• Nathan Lynch's avatar
    lockdown: ratelimit denial messages · 1e7d8bcb
    Nathan Lynch authored
    User space can flood the log with lockdown denial messages:
    
    [  662.555584] Lockdown: bash: debugfs access is restricted; see man kernel_lockdown.7
    [  662.563237] Lockdown: bash: debugfs access is restricted; see man kernel_lockdown.7
    [  662.571134] Lockdown: bash: debugfs access is restricted; see man kernel_lockdown.7
    [  662.578668] Lockdown: bash: debugfs access is restricted; see man kernel_lockdown.7
    [  662.586021] Lockdown: bash: debugfs access is restricted; see man kernel_lockdown.7
    [  662.593398] Lockdown: bash: debugfs access is restricted; see man kernel_lockdown.7
    
    Ratelimiting these shouldn't meaningfully degrade the quality of the
    information logged.
    Signed-off-by: default avatarNathan Lynch <nathanl@linux.ibm.com>
    Signed-off-by: default avatarPaul Moore <paul@paul-moore.com>
    1e7d8bcb
lockdown.c 4.11 KB