Yama: Initialize as ordered LSM
authorKees Cook <keescook@chromium.org>
Fri, 14 Sep 2018 22:37:20 +0000 (15:37 -0700)
committerKees Cook <keescook@chromium.org>
Tue, 8 Jan 2019 21:18:43 +0000 (13:18 -0800)
This converts Yama from being a direct "minor" LSM into an ordered LSM.

Signed-off-by: Kees Cook <keescook@chromium.org>
Reviewed-by: Casey Schaufler <casey@schaufler-ca.com>
include/linux/lsm_hooks.h
security/Kconfig
security/security.c
security/yama/yama_lsm.c

index fb1a653..2849e9b 100644 (file)
@@ -2090,10 +2090,5 @@ static inline void security_delete_hooks(struct security_hook_list *hooks,
 #endif /* CONFIG_SECURITY_WRITABLE_HOOKS */
 
 extern void __init capability_add_hooks(void);
-#ifdef CONFIG_SECURITY_YAMA
-extern void __init yama_add_hooks(void);
-#else
-static inline void __init yama_add_hooks(void) { }
-#endif
 
 #endif /* ! __LINUX_LSM_HOOKS_H */
index 2cd737b..78dc12b 100644 (file)
@@ -241,7 +241,7 @@ source "security/integrity/Kconfig"
 
 config LSM
        string "Ordered list of enabled LSMs"
-       default "loadpin,integrity,selinux,smack,tomoyo,apparmor"
+       default "yama,loadpin,integrity,selinux,smack,tomoyo,apparmor"
        help
          A comma-separated list of LSMs, in initialization order.
          Any LSMs left off this list will be ignored. This can be
index b8d75f5..35f93b7 100644 (file)
@@ -274,7 +274,6 @@ int __init security_init(void)
         * Load minor LSMs, with the capability module always first.
         */
        capability_add_hooks();
-       yama_add_hooks();
 
        /* Load LSMs in specified order. */
        ordered_lsm_init();
index ffda91a..eb1da13 100644 (file)
@@ -477,9 +477,15 @@ static void __init yama_init_sysctl(void)
 static inline void yama_init_sysctl(void) { }
 #endif /* CONFIG_SYSCTL */
 
-void __init yama_add_hooks(void)
+static int __init yama_init(void)
 {
        pr_info("Yama: becoming mindful.\n");
        security_add_hooks(yama_hooks, ARRAY_SIZE(yama_hooks), "yama");
        yama_init_sysctl();
+       return 0;
 }
+
+DEFINE_LSM(yama) = {
+       .name = "yama",
+       .init = yama_init,
+};