|
Message-Id: <201702132029.HJD35443.HFQFVOJOFLtOMS@I-love.SAKURA.ne.jp> Date: Mon, 13 Feb 2017 20:29:24 +0900 From: Tetsuo Handa <penguin-kernel@...ove.SAKURA.ne.jp> To: jmorris@...ei.org, linux-security-module@...r.kernel.org Cc: kernel-hardening@...ts.openwall.com Subject: Re: [RFC PATCH 2/4] security: mark nf ops in SELinux and Smack as __ro_after_init James Morris wrote: > Both SELinux and Smack register Netfilter operations during init, > which then don't change. Mark these ops as __ro_after_init. > > Signed-off-by: James Morris <james.l.morris@...cle.com> This patch breaks CONFIG_SECURITY_SELINUX_DISABLE=y + SELINUX=disabled in /etc/selinux/config case, doesn't it? Although I heard that SELinux is planning to remove CONFIG_SECURITY_SELINUX_DISABLE, CONFIG_SECURITY_SELINUX_DISABLE is valid as of current linux-security.git#next .
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.