Skip to content

kernel: strike the BPF_LSM note the guard replaced - #102

Merged
aledbf merged 1 commit into
mainfrom
f2b/stale-bpf-lsm-note
Oct 5, 2026
Merged

aledbf merged 1 commit into
mainfrom
f2b/stale-bpf-lsm-note

Conversation

@aledbf

@aledbf aledbf commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

F2b's lockdown commit (1400f6a) enabled CONFIG_SECURITY and CONFIG_BPF_LSM and guards both above the BPF section, with the reason beside the guard. The note in the BPF section still records the opposite decision — that BPF_LSM is deliberately off and somebody would have to switch it on "deliberately, with a measurement" (it even says CONFIG_SECURITY is off, which is no longer true of the config in the same build).

A build reads the guard. The note now only disagrees, so it goes. One line of build-script prose, no behaviour.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

The lockdown commit enabled CONFIG_SECURITY and CONFIG_BPF_LSM and
guarded both above the BPF section, with the reason beside the guard.
The note here still says BPF_LSM is off and why somebody would switch
it on: the decision it records has been made, by the guard, and the
two now disagree in one file. A build cannot read either; the build
reads the guard.
@aledbf
aledbf force-pushed the f2b/stale-bpf-lsm-note branch from 15771a4 to 8c1bd44 Compare October 5, 2026 04:46
@aledbf
aledbf merged commit ebe2a6e into main Oct 5, 2026
4 checks passed
@aledbf
aledbf deleted the f2b/stale-bpf-lsm-note branch October 5, 2026 11:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant