From nobody Sat Jul 25 20:48:40 2026 Received: from mail-pg1-f170.google.com (mail-pg1-f170.google.com [209.85.215.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D4BD436F42A for ; Tue, 14 Jul 2026 01:43:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783993431; cv=none; b=CziTEc6V67oYe0guuTbPfrnp0qMBRwCZ2l3JFwiCiQ1Tm1KG2daxsRSHh1qDkIjbeYVLIPN7d1Pty/wJUay4ms6fqeP3fzVIqT8AR4aSAW0zG/VjteSwx7NqRZKDm9IOX18IJ1AdR0YfWjtFQRPJZz9lkq7sqdVAJAiVTZ93+Mk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783993431; c=relaxed/simple; bh=5lO/T3tnm3QZEAd2EPJ8hvjU8Xe4okA8Q7GeLUp0bqY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=mH7mNB+UzX3ucWRqzr/ouvHN24DsOuOXeQQICX9Ac51xO0YUXsY5Ku6zm8kBI+aHhxHNRszfACXRPHAZ/i6pfQGSBpjcxTnZkTFBBzcgCoLI8/gxvGnHxHom7AB1hxiUsFW4GhXpFObf1/u2NnegH/ZFlRt+4o+bW2dhoJnKB1s= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Bly4fUQ6; arc=none smtp.client-ip=209.85.215.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Bly4fUQ6" Received: by mail-pg1-f170.google.com with SMTP id 41be03b00d2f7-c9e7391839cso406485a12.0 for ; Mon, 13 Jul 2026 18:43:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783993427; x=1784598227; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5bTdiv92W8B3yu+NVFE+yxGCJJQl+ix1X/J4ESOiB7Y=; b=Bly4fUQ6WN18DqhvrKN5f2QLG3kwVrum0T4Rw6IcemrvNbVhSayUSHAil3jeKDnKTQ xUXGPqxWSr62AjBSwkXfOHlyuJtJratHzOVZGwDO/4WeXaBp5G1z8c3BaA+pmOEYyg8P 85hLiPOpPXW0rMklWPGXYqCmJoPEhH53Azov1IGHSp6GiYkLqEgXSJ00z6w2dZ8Q9eac pFRliSeWiBBc+UvAvq6gXMCLX8uCGQCRvDvCRFauAbiHRzjrPgDlDGuZj9l2a+Vv27ia Lm5PxIKkQwGpCqPwBJYqcwH9ubE8xamMIkb+yMAJQ+5JTtGSmPtV2xUrD6NrQaYAOeFh cLEg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783993427; x=1784598227; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=5bTdiv92W8B3yu+NVFE+yxGCJJQl+ix1X/J4ESOiB7Y=; b=kZLISQhVuDQ7u4y/lqWx5+1+RtRSKFOSCyFtmLqzIL4kg/jWtP8R5sENuSmLEr+8DG +XFjIIdX+3KpYhPAC0POSTsNkuVkSWFc7FmWxY5M2hQTFfMnmzgklQ3UWaLuq8VqsAwd RGXOh3/zclBBqvUTYyH0VVGafT4wQ/DZwU4oEyv3e452ygQS0QsaE2PK6d+kd1dLCim7 EZawUQgy+Q+q7C6pJGviGWULK1Mr0DEtFPnbwx5fFIoq5MbaVEkprtfTGIulaCqT429r y1UQ36poneAM+6Kp4Kkzosf0sd6mpb4kBro3eL6x+otwVHnFK+KX7kCy2R3luzcqgcry d2vA== X-Forwarded-Encrypted: i=1; AHgh+RpBkmTWt0aT646sPS0A3NFyb6IYUxY5PeHn3wt32zO2BSnbQzv1zlLpk6eIatqLIqADsD/5Y5U+WxoH42A=@vger.kernel.org X-Gm-Message-State: AOJu0Yxu2MMTmjA9dUXT8oaqj+uB/wAJkUU8a1EfMYvRHV3KAwdo3siQ b/yGHt9fzpZ7lpAqurXYlF1H1XmBHmsYf4KM2PxkfNIfcOrenXm1vzSz X-Gm-Gg: AfdE7cmaAcWW8EHODITNcOvi8uxjy2HFTGS2bQl9kanyhs5Qbo83wjf7gImBXQ9ZcaP fei1cNoy2Ci5giq5X6rhTkhBU2t6YZA3q77GosLOuNf/+9MHTkj3PRmvcyv0nNri60qO9lVRZMG xsUnDQ6sTHchlNcwe2iO+PT2oesca4xRG534U4NIJ1kmo/8hcdr1Sy9NEzW9c5Tsp7I93L6j/b4 cqk7txXobDwFSYENEfXdWXQgtlXb/zP3OBNgRkYImsNiY5ALLfV1iPMki93moHR2EkmicdOYXMR rM9Tz6iAeD2YvcXWz24+/81KGLWj9oopgx/RcMN8hpaI/hCG8jHd3jl+RIjpSjwJ1oLZgu/TTZu uddfFvPjJG1OU8dufEgQgC95l6tIdfplSayTTH/l5l+SbP+1UX+tZhaTFCqqFMbA44ZRE+IuoRD ghNsRn/IzP2w== X-Received: by 2002:a05:6a21:50b:b0:3c0:9c1b:d0b7 with SMTP id adf61e73a8af0-3c110a1213fmr12717930637.66.1783993427065; Mon, 13 Jul 2026 18:43:47 -0700 (PDT) Received: from sleipnir ([2804:d45:3612:3b00:32a3:79f0:cdff:a04a]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13b924258a2sm59675775c88.1.2026.07.13.18.43.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 13 Jul 2026 18:43:46 -0700 (PDT) From: Lincoln Wallace To: paul@paul-moore.com, corbet@lwn.net Cc: skhan@linuxfoundation.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, penguin-kernel@I-love.SAKURA.ne.jp, rdunlap@infradead.org, Lincoln Wallace Subject: [PATCH 1/2] doc: LSM: describe CONFIG_LSM and lsm= as the selection mechanism Date: Mon, 13 Jul 2026 22:38:31 -0300 Message-ID: <20260714013832.977443-2-locnnil0@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260714013832.977443-1-locnnil0@gmail.com> References: <20260714013832.977443-1-locnnil0@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The LSM usage document states that security modules are selectable at build time via CONFIG_DEFAULT_SECURITY and can be overridden at boot time via the "security=3D..." kernel command line argument. CONFIG_DEFAULT_SECURITY no longer exists: LSMs are enabled via CONFIG_LSM, an ordered list of the LSMs to initialize, which can be overridden at boot time with the "lsm=3D" parameter. The "security=3D" parameter remains as a deprecated way to choose a legacy "major" security module, and is ignored when "lsm=3D" is specified; see commit 89a9684ea158 ("LSM: Ignore "security=3D" when "lsm=3D" is specified"). A previous attempt replaced "security=3D" with "lsm=3D" in place [1], which was rejected because the parameters are not equivalent: "security=3D" selects a single major module while the built-in CONFIG_LSM list otherwise remains active, whereas "lsm=3D" must list every LSM to enable. Update the paragraph to describe CONFIG_LSM and "lsm=3D" as the current selection mechanism, keeping "security=3D" documented as the deprecated legacy option, matching the wording in kernel-parameters.txt. Link: https://lore.kernel.org/r/20250114225156.10458-1-rdunlap@infradead.or= g [1] Signed-off-by: Lincoln Wallace --- Documentation/admin-guide/LSM/index.rst | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/Documentation/admin-guide/LSM/index.rst b/Documentation/admin-= guide/LSM/index.rst index b44ef68f6e4d..c24310c709dc 100644 --- a/Documentation/admin-guide/LSM/index.rst +++ b/Documentation/admin-guide/LSM/index.rst @@ -6,9 +6,11 @@ The Linux Security Module (LSM) framework provides a mecha= nism for various security checks to be hooked by new kernel extensions. The name "module" is a bit of a misnomer since these extensions are not actually loadable kernel modules. Instead, they are selectable at build-time via -CONFIG_DEFAULT_SECURITY and can be overridden at boot-time via the -``"security=3D..."`` kernel command line argument, in the case where multi= ple -LSMs were built into a given kernel. +CONFIG_LSM, an ordered list of the LSMs to enable, and can be +overridden at boot-time via the ``"lsm=3D..."`` kernel command line +argument. The ``"security=3D..."`` kernel command line argument remains +available to choose a legacy "major" security module, but has been +deprecated by the ``"lsm=3D..."`` parameter. =20 The primary users of the LSM interface are Mandatory Access Control (MAC) extensions which provide a comprehensive security policy. Examples --=20 2.53.0 From nobody Sat Jul 25 20:48:40 2026 Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4378C36C9C0 for ; Tue, 14 Jul 2026 01:43:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783993433; cv=none; b=e65mks4pYLspWYHv9eJAv4GewJIwt6pzpcmmn+WtwDXbNvz0Z2aSKV7zgrf1cfXBcFu5B+ZpDoeKfqoKKPvB3AdycCLZnz+zkm7Iri6+1GjjJwI5si7bVEZiOErBnjeh67O8GTeZ8frqRBXC0LFlaaNznM5c7XPqJzBM/RnXgPU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783993433; c=relaxed/simple; bh=PVs+gHTDyYChhu+7rRJSjmFR790Mb8zOYoVJnPhHsQE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=HWv0AxjB/K1F3em6c38QcHrkFoS5rP2/BbMFrXbkPxSmviC9viUFSHUNGunlHS7+PUwVXQgk7pxaD+QbNc5zb3wFXRAj+JNJgW/ki7a2EsGTf6ZzFIMwkyZ8nQQhH5nn89vIMu/UWuTByh2CHQ6oTaB/obMzgIMqSXHIgAYGEX4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=WlaO0CRb; arc=none smtp.client-ip=209.85.216.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="WlaO0CRb" Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-381018b9375so4232779a91.0 for ; Mon, 13 Jul 2026 18:43:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783993430; x=1784598230; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=yLYnguE796013GUUX5AfLaBgg2bMMPqf3FcC8kN1cc0=; b=WlaO0CRb7KrIB/XrVnc1Dmc0UqbtDoG3BelkYEOx55pq640zozcmjQ06wciqCDuD4m EihGqQf486ZkXBPIYQJ/DuULtVXIn2Zao9IGlt3kS3QxxFNnEGnwsItetocmCK3j95nR p5AwSGvhWl/ZxboXSIuqklKmI9g9wDv0qMGK13JB6duvjpXpczqV2l8DJZFsd3rjJc7+ L1vM3A5oZNP9rt+pAOO4So5UKxj/qXeJJjq+jizVIY+HoZzFHZTEVTNh5UmvxjS7/mxT sm8bktBnG21uIkqvCQPABtijbfmPWMyGbzSm6RBZTfxX+28xbvNHBRrouRZIWwCLX2Do R2jQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783993430; x=1784598230; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=yLYnguE796013GUUX5AfLaBgg2bMMPqf3FcC8kN1cc0=; b=Qp1xOjuZXhaB8uXEbClpj15r6LJJz1VVaCKUy4vbYHkMoI0H3EKqtd0eJGwbMvEoHV nMKkx70qaLxaZIpquB8hP/TI4cjIW55Tn104OKBRgxVIDBrY1vCRf5ZK94UgGTn5uXSn C6+LKRKwFskF2FOHTuHi3elwuLbLPypVf7bS5ODsVYojdEprZ6HGwTQDbshXPx7lWCFb zTDLJyGANPf3FFkO4ExIAFWH7QqIJ5ZV/ccYyUH1pbRyTdA7Fli6Tht1QdTzwwjZuEUx JpemVxHFj7rObCSBwxfYqmiijlkvay29EI1o/C+wISYOnZ3XTmbm4n+3u+NgL1G6k89O 8K5g== X-Forwarded-Encrypted: i=1; AHgh+Rq5BF3Ae4j4jGvtCQg28YAX2iTmdvVQMGJtdE8+eUpnyNKm0UoTjcdSD6kLhSCB2YIYiQMZJ5D8r0eISrQ=@vger.kernel.org X-Gm-Message-State: AOJu0YzGYJMttmLaAokQRXzJBBXjM6NmHDdRCom9ymk1iklYsmTvncOL QpdNpV4T2hSKvZO8i4A1YqwF9ACS3cWf3SzByCQDkuZxiO9FLlIk/dLh X-Gm-Gg: AfdE7clBbJ1ZVTi4SbhiVMGHGbTw2ZHNGwAh9QaPCTP0L0GVLmXE7QS6HhuGCt1AOjO SDS+qCK+LOsUqMzK9ksr87F7XyTTHMdTX4vBGx7itJZ9sGVPcURh/55FnOLzgxv5UyVqCXNxKvn /H+TpwOb/yu2YxefA62GD8J1wP/xSchjzL+zuxvrqKfsFF73UWVenLRw7feUyLTWWRAvQVT+1MY qPyZ+GSX1D7jZKX/WZS9nuOKo+3KT1CN5oL+mgYneq5myQ6Fz2nHW/r4Zr/EENPBKkmqAHrMs1m bUqlzYtSRNLiL8lZB87REEioHcHKNJKuFaZQXYKI+I1Wp17eFV2lQPmmZeej0o7sfjfNdcCkzoX X6++JnylklYiUjPvOl4krDZXu65sRu9DAaK4sCqj0xKKwv4vhuNDiHkm63JV1Yjzg3zv5ub552+ Xr/zHRSdKirA== X-Received: by 2002:a05:6a21:9d48:b0:3c1:85d:fa2f with SMTP id adf61e73a8af0-3c1108c2d4fmr11352039637.36.1783993429962; Mon, 13 Jul 2026 18:43:49 -0700 (PDT) Received: from sleipnir ([2804:d45:3612:3b00:32a3:79f0:cdff:a04a]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13b924258a2sm59675775c88.1.2026.07.13.18.43.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 13 Jul 2026 18:43:49 -0700 (PDT) From: Lincoln Wallace To: paul@paul-moore.com, corbet@lwn.net Cc: skhan@linuxfoundation.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, penguin-kernel@I-love.SAKURA.ne.jp, rdunlap@infradead.org, Lincoln Wallace Subject: [PATCH 2/2] doc: LSM: fix module ordering description for /sys/kernel/security/lsm Date: Mon, 13 Jul 2026 22:38:32 -0300 Message-ID: <20260714013832.977443-3-locnnil0@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260714013832.977443-1-locnnil0@gmail.com> References: <20260714013832.977443-1-locnnil0@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The LSM usage document states that the capability module will always be first in /sys/kernel/security/lsm, followed by any "minor" modules and then the one "major" module. This does not match the current LSM infrastructure: - When CONFIG_SECURITY_LOCKDOWN_LSM_EARLY is enabled, lockdown is initialized as an early LSM, before all other modules including capability, and appears first in the list. - The integrity modules (e.g. IMA and EVM) register with LSM_ORDER_LAST and are always placed at the end of the list, regardless of the position of the major module. - The relative order of the remaining modules is not fixed by the framework; it follows CONFIG_LSM or the "lsm=3D" kernel command line parameter. Rewrite the paragraph to describe the actual ordering: lockdown first when early lockdown is enabled, capability otherwise, integrity modules at the end, and the remaining modules in the configured order. Signed-off-by: Lincoln Wallace --- Documentation/admin-guide/LSM/index.rst | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/Documentation/admin-guide/LSM/index.rst b/Documentation/admin-= guide/LSM/index.rst index c24310c709dc..9518495edfbc 100644 --- a/Documentation/admin-guide/LSM/index.rst +++ b/Documentation/admin-guide/LSM/index.rst @@ -27,9 +27,15 @@ man-pages project. A list of the active security modules can be found by reading ``/sys/kernel/security/lsm``. This is a comma separated list, and will always include the capability module. The list reflects the -order in which checks are made. The capability module will always -be first, followed by any "minor" modules (e.g. Yama) and then -the one "major" module (e.g. SELinux) if there is one configured. +order in which checks are made. The capability module will be +first, unless CONFIG_SECURITY_LOCKDOWN_LSM_EARLY is enabled, in +which case the lockdown module will precede it. The integrity +modules (e.g. IMA and EVM), if enabled in the kernel +configuration, are always placed at the end of the list. Any +other "minor" modules (e.g. Yama) and the one "major" module +(e.g. SELinux), if there is one configured, appear in between, +in the order given by CONFIG_LSM or the ``"lsm=3D..."`` kernel +command line parameter. =20 Process attributes associated with "major" security modules should be accessed and maintained using the special files in ``/proc/.../attr``. --=20 2.53.0