On Thursday, January 21, 2016 08:12:12 AM Mimi Zohar wrote: > Paul, Casey, Kees, Jon, Tetsuo does it make sense to consolidate the > module, firmware, and kexec pre and post security hooks and have just > one set of pre and post security kernel_read_file hook instead? Does > it make sense for this patch set to define the new hooks to allow the > LSMs to migrate to it independently of each other? Well, as usual, the easiest way to both get solid feedback and actually get a change accepted is to post patches to the affected LSMs. Probably not what you wanted to hear, but at least I'm honest :) -- paul moore security @ redhat