android_kernel_motorola_sm6375/security
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Paul Moore 1903a616ae
UPSTREAM: selinux: deprecate disabling SELinux and runtime
Deprecate the CONFIG_SECURITY_SELINUX_DISABLE functionality.  The
code was originally developed to make it easier for Linux
distributions to support architectures where adding parameters to the
kernel command line was difficult.  Unfortunately, supporting runtime
disable meant we had to make some security trade-offs when it came to
the LSM hooks, as documented in the Kconfig help text:

  NOTE: selecting this option will disable the '__ro_after_init'
  kernel hardening feature for security hooks.   Please consider
  using the selinux=0 boot parameter instead of enabling this
  option.

Fortunately it looks as if that the original motivation for the
runtime disable functionality is gone, and Fedora/RHEL appears to be
the only major distribution enabling this capability at build time
so we are now taking steps to remove it entirely from the kernel.
The first step is to mark the functionality as deprecated and print
an error when it is used (what this patch is doing).  As Fedora/RHEL
makes progress in transitioning the distribution away from runtime
disable, we will introduce follow-up patches over several kernel
releases which will block for increasing periods of time when the
runtime disable is used.  Finally we will remove the option entirely
once we believe all users have moved to the kernel cmdline approach.

Acked-by: Casey Schaufler <casey@schaufler-ca.com>
Acked-by: Ondrej Mosnacek <omosnace@redhat.com>
Acked-by: Stephen Smalley <sds@tycho.nsa.gov>
Change-Id: I22ac297dbef6ec149bc29240f0b802f5c27d93dc
Signed-off-by: Paul Moore <paul@paul-moore.com>
2026-01-14 18:13:15 -08:00
..
apparmor BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
bpf UPSTREAM: bpf: Implement bpf_local_storage for inodes 2026-01-14 18:12:21 -08:00
integrity This is the 5.4.291 stable release 2025-03-13 14:53:52 +00:00
keys KEYS: trusted_tpm1: Compare HMAC values in constant time 2025-10-29 14:00:01 +01:00
loadpin
lockdown
safesetid
selinux UPSTREAM: selinux: deprecate disabling SELinux and runtime 2026-01-14 18:13:15 -08:00
smack This is the 5.4.294 stable release 2025-06-05 07:11:21 +00:00
tomoyo tomoyo: don't emit warning in tomoyo_write_control() 2025-03-13 12:43:03 +01:00
yama BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
commoncap.c
device_cgroup.c
inode.c securityfs: don't pin dentries twice, once is enough... 2025-08-28 16:21:24 +02:00
Kconfig UPSTREAM: bpf: lsm: Initialize the BPF LSM hooks 2026-01-14 18:12:20 -08:00
Kconfig.hardening ANDROID: kernelci build-break for 64-bit riscv clang builds (5.4 only) 2025-01-31 16:42:47 -08:00
lsm_audit.c
Makefile UPSTREAM: bpf: lsm: Initialize the BPF LSM hooks 2026-01-14 18:12:20 -08:00
min_addr.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
security.c BACKPORT: security: Refactor declaration of LSM hooks 2025-12-23 13:36:10 -08:00