Re: [PATCH V40 03/29] security: Add a static lockdown policy LSM
From: Matthew Garrett <hidden>
Date: 2019-09-04 16:51:31
Also in:
linux-api, lkml
From: Matthew Garrett <hidden>
Date: 2019-09-04 16:51:31
Also in:
linux-api, lkml
On Fri, Aug 30, 2019 at 9:28 AM David Howells [off-list ref] wrote:
Matthew Garrett [off-list ref] wrote:quoted
+static char *lockdown_reasons[LOCKDOWN_CONFIDENTIALITY_MAX+1] = {const char *const maybe?
Seems reasonable.
quoted
+static enum lockdown_reason lockdown_levels[] = {LOCKDOWN_NONE, + LOCKDOWN_INTEGRITY_MAX, + LOCKDOWN_CONFIDENTIALITY_MAX}; +const? Isn't this also a 1:1 mapping?
Sorry, a 1:1 mapping to what?
quoted
+static int lock_kernel_down(const char *where, enum lockdown_reason level)Is the last parameter the reason or the level? You're mixing the terms.
Fair.