On 7/6/20 6:57 PM, Lorenzo Fontana wrote:
This option adds a kernel parameter 'bpf_lsm', which allows the BPF LSM to be disabled at boot. The purpose of this option is to allow a single kernel image to be distributed with the BPF LSM built in, but not necessarily enabled. Signed-off-by: Lorenzo Fontana <fontanalorenz@xxxxxxxxx>
Well, this explains what the patch is doing but not *why* you need it exactly. Please explain your concrete use-case for this patch. Thanks, Daniel