finds.dev← search

// the find

MiaoHao-oops/rbac-lsm

C · GPL-3.0 · updated Apr 2024

a Role-Based Access Control LSM based on Linux 5.14.0-rc2

A toy Linux Security Module implementing role-based access control on a 5.14.0-rc2 kernel tree, built as a university OS-security coursework project (slides and a PPTX are in the repo). It targets LoongArch/QEMU and exposes a securityfs interface for adding users, roles, and permissions and binding them together. Useful for someone studying LSM internals or securityfs, not for anyone wanting actual access control on a real system.

The three-layer split (db for in-kernel object management, fs for the securityfs userspace interface, lsm for the inode_permission hook) is a clean way to understand how an LSM is structured end-to-end. The README walks through a full reproducible demo — enabling the module, adding a deny-write permission on /init, then swapping it for a deny-read permission and showing the effect — which is more verification than most student kernel projects bother to show. Permission model (accept/deny + operation + object) is simple enough to read the whole thing in one sitting.

Only one LSM hook (inode_permission) is wired up, so it can't gate exec, mount, ptrace, or network operations — calling it RBAC access control is generous. Roles cap out at 20 permissions via a fixed-size array (ROLE_MAX_PERMS) rather than a list, and users:roles is hardcoded 1:1 despite the README admitting real RBAC needs many-to-many. No tests, no CI, and it only runs on a specific LoongArch/QEMU BusyBox setup from 2024 — getting it to build against a current kernel will take real work. Zero commit activity since April 2024 and 0 stars mean this is a frozen coursework artifact, not a maintained project.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →