// the find
guomo233/LSM-based-RBAC
基于角色访问控制的Linux安全模块
A toy Linux Security Module (LSM) that bolts role-based access control onto two syscalls — file creation and file rename — plus a CLI tool (role_manager) to manage roles and user assignments at runtime. It's a student/coursework-style demo of writing and compiling a custom LSM into the kernel, not a usable access-control product.
It's a real in-tree LSM, not a userspace simulation — it registers actual LSM hooks and requires compiling into the kernel, which is more than most 'security module' toy projects attempt. The role_manager CLI lets you add/update/delete roles and reassign users without recompiling. The README walks through the full out-of-tree build process (copying .config, Kconfig, menuconfig, selecting it as the default security module), which is a decent reference if you've never built a custom LSM before.
Policy coverage is two operations — file creation and rename — everything else falls through to default DAC, so calling this RBAC is a stretch; it enforces almost nothing. Last commit is from 2019, targeting a pre-LSM-stacking kernel ABI, so it likely won't even compile against a modern kernel without rework. No license file, no tests, no CI, and the entire enforcement logic lives in one C file with no separation between policy storage and hook logic, which is a bad sign for anything touching access control where correctness actually matters.