Thread (101 messages) 101 messages, 7 authors, 2024-02-15

Re: [PATCH v9 25/25] integrity: Remove LSM

From: Paul Moore <paul@paul-moore.com>
Date: 2024-02-08 03:18:59
Also in: keyrings, linux-fsdevel, linux-integrity, linux-kselftest, linux-nfs, lkml, selinux

On Jan 15, 2024 Roberto Sassu [off-list ref] wrote:
Since now IMA and EVM use their own integrity metadata, it is safe to
remove the 'integrity' LSM, with its management of integrity metadata.

Keep the iint.c file only for loading IMA and EVM keys at boot, and for
creating the integrity directory in securityfs (we need to keep it for
retrocompatibility reasons).

Signed-off-by: Roberto Sassu <roberto.sassu@huawei.com>
Reviewed-by: Casey Schaufler <casey@schaufler-ca.com>
---
 include/linux/integrity.h      |  14 ---
 security/integrity/iint.c      | 197 +--------------------------------
 security/integrity/integrity.h |  25 -----
 security/security.c            |   2 -
 4 files changed, 2 insertions(+), 236 deletions(-)
Acked-by: Paul Moore <paul@paul-moore.com>

--
paul-moore.com
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help