// the find
MiaoHao-oops/rbac-lsm
a Role-Based Access Control LSM based on Linux 5.14.0-rc2
A toy Linux Security Module implementing role-based access control on a 5.14.0-rc2 kernel tree, built as a university OS-security coursework project (slides and a PPTX are in the repo). It targets LoongArch/QEMU and exposes a securityfs interface for adding users, roles, and permissions and binding them together. Useful for someone studying LSM internals or securityfs, not for anyone wanting actual access control on a real system.
The three-layer split (db for in-kernel object management, fs for the securityfs userspace interface, lsm for the inode_permission hook) is a clean way to understand how an LSM is structured end-to-end. The README walks through a full reproducible demo — enabling the module, adding a deny-write permission on /init, then swapping it for a deny-read permission and showing the effect — which is more verification than most student kernel projects bother to show. Permission model (accept/deny + operation + object) is simple enough to read the whole thing in one sitting.
Only one LSM hook (inode_permission) is wired up, so it can't gate exec, mount, ptrace, or network operations — calling it RBAC access control is generous. Roles cap out at 20 permissions via a fixed-size array (ROLE_MAX_PERMS) rather than a list, and users:roles is hardcoded 1:1 despite the README admitting real RBAC needs many-to-many. No tests, no CI, and it only runs on a specific LoongArch/QEMU BusyBox setup from 2024 — getting it to build against a current kernel will take real work. Zero commit activity since April 2024 and 0 stars mean this is a frozen coursework artifact, not a maintained project.