[PATCH 2/2] doc: LSM: fix module ordering description for /sys/kernel/security/lsm

Paul Moore paul at paul-moore.com
Fri Sep 11 22:09:26 UTC 2026


On Jul 13, 2026 Lincoln Wallace <locnnil0 at gmail.com> wrote:
> 
> The LSM usage document states that the capability module will always
> be first in /sys/kernel/security/lsm, followed by any "minor" modules
> and then the one "major" module.
> 
> This does not match the current LSM infrastructure:
> 
>  - When CONFIG_SECURITY_LOCKDOWN_LSM_EARLY is enabled, lockdown is
>    initialized as an early LSM, before all other modules including
>    capability, and appears first in the list.
> 
>  - The integrity modules (e.g. IMA and EVM) register with
>    LSM_ORDER_LAST and are always placed at the end of the list,
>    regardless of the position of the major module.
> 
>  - The relative order of the remaining modules is not fixed by the
>    framework; it follows CONFIG_LSM or the "lsm=" kernel command
>    line parameter.
> 
> Rewrite the paragraph to describe the actual ordering: lockdown
> first when early lockdown is enabled, capability otherwise,
> integrity modules at the end, and the remaining modules in the
> configured order.
> 
> Signed-off-by: Lincoln Wallace <locnnil0 at gmail.com>
> ---
>  Documentation/admin-guide/LSM/index.rst | 12 +++++++++---
>  1 file changed, 9 insertions(+), 3 deletions(-)

Merged into lsm/dev, thanks!

--
paul-moore.com



More information about the Linux-security-module-archive mailing list