Skip to content

Conversation

@EricccTaiwan
Copy link
Collaborator

Close #2911

Copy link
Contributor

@arighi arighi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it really true? I just recompiled a kernel with CONFIG_SECURITY=y and CONFIG_BPF_LSM not set and I don't get any permission error. However, I tested it inside virtme-ng, so maybe other components are involved to trigger the issue (likely systemd).

So, I'm ok to recommend this option, but it'd be nice to understand exactly what is happening.

@etsal
Copy link
Contributor

etsal commented Oct 19, 2025

Is it really true? I just recompiled a kernel with CONFIG_SECURITY=y and CONFIG_BPF_LSM not set and I don't get any permission error. However, I tested it inside virtme-ng, so maybe other components are involved to trigger the issue (likely systemd).

So, I'm ok to recommend this option, but it'd be nice to understand exactly what is happening.

Second that, looking at the logs in the original issue (Frogging-Family/linux-tkg#1156) The problem seems lavd-specific and related to ftrace support.

Should we wait till the problem gets triaged a bit better before merging? The original problem (lavd not finding some pretty basic kfuncs) is not that obviously related to CONFIG_BPF_LSM.

@multics69
Copy link
Contributor

Let me reproduce the original issue (Frogging-Family/linux-tkg#1156) with your changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

missing kernel option

5 participants