summaryrefslogtreecommitdiffstats
path: root/arch
diff options
context:
space:
mode:
authorKees Cook2012-10-15 23:02:07 +0200
committerRusty Russell2012-12-14 03:35:24 +0100
commit2e72d51b4ac32989496870cd8171b3682fea1839 (patch)
treeb8190d17aa5d59508f8c979ce0160f21bef89500 /arch
parentmodule: add flags arg to sys_finit_module() (diff)
downloadkernel-qcow2-linux-2e72d51b4ac32989496870cd8171b3682fea1839.tar.gz
kernel-qcow2-linux-2e72d51b4ac32989496870cd8171b3682fea1839.tar.xz
kernel-qcow2-linux-2e72d51b4ac32989496870cd8171b3682fea1839.zip
security: introduce kernel_module_from_file hook
Now that kernel module origins can be reasoned about, provide a hook to the LSMs to make policy decisions about the module file. This will let Chrome OS enforce that loadable kernel modules can only come from its read-only hash-verified root filesystem. Other LSMs can, for example, read extended attributes for signatures, etc. Signed-off-by: Kees Cook <keescook@chromium.org> Acked-by: Serge E. Hallyn <serge.hallyn@canonical.com> Acked-by: Eric Paris <eparis@redhat.com> Acked-by: Mimi Zohar <zohar@us.ibm.com> Acked-by: James Morris <james.l.morris@oracle.com> Signed-off-by: Rusty Russell <rusty@rustcorp.com.au>
Diffstat (limited to 'arch')
0 files changed, 0 insertions, 0 deletions