[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#876437: linux: Please enable CONFIG_SECURITY_SELINUX_DISABLE



Control: tag -1 wontfix

On Fri, 2017-09-22 at 18:08 +0800, Yanhao Mo wrote:
> Source: linux
> Severity: wishlist
> 
> Dear Maintaners,
> 
> CONFIG_SECURITY_WRITABLE_HOOKS is nessesarry for write linux security
> modules which doesn't compile into vmlinuz. Writing a "linux security
> module" as a kernel module is impossible without enable this config.

I don't think that's possible anyway.

> Please enable this. It is very appreciated.

This is not a user-configurable Kconfig option, so we can't directly
enable it.  The help text for SECURITY_SELINUX_DISABLE, which selects
it, notes that this is bad for security.

So no, we won't do this.

Ben.

-- 
Ben Hutchings
Horngren's Observation:
              Among economists, the real world is often a special case.

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: