• Kees Cook's avatar
    LSM: Revive CONFIG_DEFAULT_SECURITY_* for "make oldconfig" · 2623c4fb
    Kees Cook authored
    Commit 70b62c25
    
     ("LoadPin: Initialize as ordered LSM") removed
    CONFIG_DEFAULT_SECURITY_{SELINUX,SMACK,TOMOYO,APPARMOR,DAC} from
    security/Kconfig and changed CONFIG_LSM to provide a fixed ordering as a
    default value. That commit expected that existing users (upgrading from
    Linux 5.0 and earlier) will edit CONFIG_LSM value in accordance with
    their CONFIG_DEFAULT_SECURITY_* choice in their old kernel configs. But
    since users might forget to edit CONFIG_LSM value, this patch revives
    the choice (only for providing the default value for CONFIG_LSM) in order
    to make sure that CONFIG_LSM reflects CONFIG_DEFAULT_SECURITY_* from their
    old kernel configs.
    
    Note that since TOMOYO can be fully stacked against the other legacy
    major LSMs, when it is selected, it explicitly disables the other LSMs
    to avoid them also initializing since TOMOYO does not expect this
    currently.
    Reported-by: default avatarJakub Kicinski <jakub.kicinski@netronome.com>
    Reported-by: Randy Dun...
    2623c4fb
Kconfig 10.5 KB