// the find
abhishekgupta8/Role-Based-Access-Controlled-Security-Model-for-linux
RBAC
A Linux Security Module implementing role-based access control on top of the standard LSM hooks, built against kernel 3.14.17 as a course project (Stony Brook, 2014). It's for someone who wants to see a minimal, working RBAC LSM example rather than run it on anything real.
Maps roles to inode numbers instead of file paths, which avoids the obvious TOCTOU/symlink-swap problems a path-based scheme would have. It hooks the full set of inode operations you'd actually need for a coherent model (create, link, unlink, symlink, mkdir, rmdir, rename, readlink, permission, init_security), not just a couple of them. Layering on top of the existing ACL/DAC checks rather than replacing them is the right call for an academic implementation — it only adds restrictions, it can't accidentally loosen anything the kernel already enforces.
The fail-open default — 'if RBAC can't map the user or file, it grants access' — is a genuinely bad security posture, not just a rough edge; any file created before RBAC was enabled, or by an unregistered user, is silently unprotected. Access is binary (full or none) with no read/write split, which rules out most real policies. The install instructions have you chmod 777 the policy store files as a setup step, which is the kind of thing that gets forgotten and left that way. It's hard-pinned to kernel 3.14.17 (EOL for over a decade), hasn't been touched since 2014, has no tests, and the whole thing is really a single-semester assignment rather than something meant to be adopted.