On Thu, 5 Nov 2020, Olga Kornievskaia wrote: > From: Olga Kornievskaia <kolga@xxxxxxxxxx> > > Add a new hook func_query_vfs to query an LSM module (such as > SELinux) with the intention of finding whether or not it is enabled > or perhaps supports some functionality. > > NFS stores security labels for file system objects and SElinux > or any other LSM module can query those objects. But it's > wasteful to do so when no security enforcement is taking place. > Using a new API call of security_func_query_vfs() and asking if Seems we lost something here. -- James Morris <jmorris@xxxxxxxxx>