[PATCH v6 1/4] security: lsm: allow LSMs to register for late_initcall_sync init

Mimi Zohar zohar at linux.ibm.com
Mon Jun 8 16:52:24 UTC 2026


On Fri, 2026-06-05 at 15:43 +0100, Yeoreum Yun wrote:
> There are situations where LSMs have dependencies that might mean they
> want to be initialised later in the boot process, to ensure those
> dependencies are available. In particular there are some TPM setups (Arm
> FF-A devices, SPI attached TPMs) required by IMA which are not
> guaranteed to be initialised for regular initcall_late.
> 
> Add an initcall_late_sync option that can be used in these situations.
> 
> Signed-off-by: Yeoreum Yun <yeoreum.yun at arm.com>

Cc: Paul Moore <paul at paul-moore.com>

Jarkko has already queued 4/4.  Paul, can we get an Ack from you?


Mimi



More information about the Linux-security-module-archive mailing list