On Wed, 2022-11-23 at 13:57 -0500, Nayna wrote:
Given there are no other exploiters for fwsecurityfs and there should
be
no platform-specific fs, would modifying sysfs now to let userspace
create files cleanly be the way forward? Or, if we should strongly
consider securityfs, which would result in updating securityfs to
allow
userspace creation of files and then expose variables via a more
platform-specific directory /sys/kernel/security/pks? We want to pick
the best available option and would find some hints on direction
helpful
before we develop the next patch.
Ping - it would be helpful for us to know your thoughts on this.
Andrew
--
Andrew Donnellan OzLabs, ADL Canberra
ajd@linux.ibm.com IBM Australia Limited