[PATCH 0/2] Allow individual features to be locked down
Nikolay Borisov
nik.borisov at suse.com
Fri Mar 21 10:24:19 UTC 2025
This simple change allows usecases where someone might want to lock only specific
feature at a finer granularity than integrity/confidentiality levels allows.
The first likely user of this is the CoCo subsystem where certain features will be
disabled.
Nikolay Borisov (2):
lockdown: Switch implementation to using bitmap
lockdown/kunit: Introduce kunit tests
security/lockdown/Kconfig | 5 +++
security/lockdown/Makefile | 1 +
security/lockdown/lockdown.c | 24 +++++++++-----
security/lockdown/lockdown_test.c | 55 +++++++++++++++++++++++++++++++
4 files changed, 77 insertions(+), 8 deletions(-)
create mode 100644 security/lockdown/lockdown_test.c
--
2.43.0
More information about the Linux-security-module-archive
mailing list