Documentation/bpf: Document the bpf keyring and improve examples

Key generation is detailled for RSA and ML-DSA, the load example sets
keyring_id to the bpf keyring with the session keyring shown only as
the staging variant, and the LSM admission example anchors on the bpf
keyring while allowlisting staged serials rather than treating a user
keyring as ordinary trust.

Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20260828175227.1537793-12-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
1 file changed