[PATCH v2] lockdown: Only log restrictions once
Nicolas Bouchinet
nicolas.bouchinet at oss.cyber.gouv.fr
Tue Nov 25 10:00:00 UTC 2025
Hi,
> Currently lockdown does not support the audit function, so I believe the
> logs here serve a purpose similar to auditing. Based on this, I think
> this change will meaningfully degrade the quality of the logs, making it
> hard for users to find out what happens when lockdown is active,
> especially after a long time running.
I agree with Xiu.
I'm not sure to understand how this is a kernel issue. I mean beside
that we do not support hibernation in Lockdown for now.
Can't you just disable hibernation with systemd-logind using someting like
'AllowHibernation=no' ?
Best regards,
Nicolas
More information about the Linux-security-module-archive
mailing list