Re: [PATCH v6 1/4] security: lsm: allow LSMs to register for late_initcall_sync init

Mimi Zohar <[email protected]> Mon, 08 Jun 2026 12:52:24 -0400
Newsgroups org.kernel.vger.linux-integrity,org.kernel.vger.linux-kernel,org.kernel.vger.linux-security-module
Message-ID <[email protected]>
On Fri, 2026-06-05 at 15:43 +0100, Yeoreum Yun wrote:
> There are situations where LSMs have dependencies that might mean they
> want to be initialised later in the boot process, to ensure those
> dependencies are available. In particular there are some TPM setups (Arm
> FF-A devices, SPI attached TPMs) required by IMA which are not
> guaranteed to be initialised for regular initcall_late.
> 
> Add an initcall_late_sync option that can be used in these situations.
> 
> Signed-off-by: Yeoreum Yun <[email protected]>

Cc: Paul Moore <[email protected]>

Jarkko has already queued 4/4.  Paul, can we get an Ack from you?


Mimi