[$] Unprivileged BPF and authoritative security hooks

When the developers of the Linux security module (LSM) subsystem find
themselves disagreeing with other kernel developers, it tends to be because
those other developers don’t think to — or don’t want to — add security
hooks to their shiny new subsystems. Sometimes, though, the addition of
new hooks by non-LSM developers can also create some friction. Andrii
Nakryiko’s posting of a pair of
BPF-related security hooks
raised a couple of interesting questions,
one of which spurred a fair amount of discussion, and one that did not.

Source: LWN.net – [$] Unprivileged BPF and authoritative security hooks