[PATCH 2/2] doc: LSM: fix module ordering description for /sys/kernel/security/lsm
Paul Moore
paul at paul-moore.com
Fri Sep 11 22:09:26 UTC 2026
On Jul 13, 2026 Lincoln Wallace <locnnil0 at gmail.com> wrote:
>
> The LSM usage document states that the capability module will always
> be first in /sys/kernel/security/lsm, followed by any "minor" modules
> and then the one "major" module.
>
> This does not match the current LSM infrastructure:
>
> - When CONFIG_SECURITY_LOCKDOWN_LSM_EARLY is enabled, lockdown is
> initialized as an early LSM, before all other modules including
> capability, and appears first in the list.
>
> - The integrity modules (e.g. IMA and EVM) register with
> LSM_ORDER_LAST and are always placed at the end of the list,
> regardless of the position of the major module.
>
> - The relative order of the remaining modules is not fixed by the
> framework; it follows CONFIG_LSM or the "lsm=" kernel command
> line parameter.
>
> Rewrite the paragraph to describe the actual ordering: lockdown
> first when early lockdown is enabled, capability otherwise,
> integrity modules at the end, and the remaining modules in the
> configured order.
>
> Signed-off-by: Lincoln Wallace <locnnil0 at gmail.com>
> ---
> Documentation/admin-guide/LSM/index.rst | 12 +++++++++---
> 1 file changed, 9 insertions(+), 3 deletions(-)
Merged into lsm/dev, thanks!
--
paul-moore.com
More information about the Linux-security-module-archive
mailing list