Kernel lockdown on track for 5.4
The kernel lockdown patches, meant to prevent even root from corrupting a
running kernel, have been under development
since 2012. In the seven years since then, this work has inspired numerous
heated discussions and has been through many changes as a result. The latest incarnation implements lockdown as a
Linux security module. On August 19, security subsystem maintainer
James Morris applied
the lockdown patches to his repository, indicating that they will
almost certainly be part of the security pull request in the 5.4 merge
window. After 40 iterations, the lockdown work looks set to finally make
it into the mainline kernel.