meta-hardening: Convert to new override syntax

Signed-off-by: Armin Kuster <akuster808@gmail.com>
This commit is contained in:
Armin Kuster
2021-07-29 16:32:30 -07:00
parent b8554aae23
commit 352e6498a4
8 changed files with 11 additions and 11 deletions

View File

@@ -6,6 +6,6 @@ DISTRO_FEATURES = " acl xattr pci ext2 pam ipv4 ipv6 ipsec largefile usbhost"
VIRTUAL-RUNTIME_base-utils-syslog ?= "rsyslog"
IMAGE_ROOTFS_EXTRA_SPACE = "524288"
EXTRA_IMAGE_FEATURES_remove = "debug-tweaks"
EXTRA_IMAGE_FEATURES:remove = "debug-tweaks"
DISABLE_ROOT ?= "True"

View File

@@ -1,4 +1,4 @@
do_install_append_harden () {
do_install:append_harden () {
# to hardend
sed -i -e 's:#AllowTcpForwarding yes:AllowTcpForwarding no:' ${D}${sysconfdir}/ssh/sshd_config
sed -i -e 's:ClientAliveCountMax 4:ClientAliveCountMax 2:' ${D}${sysconfdir}/ssh/sshd_config

View File

@@ -1,4 +1,4 @@
do_install_append_harden () {
do_install:append_harden () {
sed -i 's/umask.*/umask 027/g' ${D}/${sysconfdir}/profile
}

View File

@@ -1,7 +1,7 @@
SUMMARY = "A small image for an example hardening OE."
IMAGE_INSTALL = "packagegroup-core-boot packagegroup-hardening"
IMAGE_INSTALL_append = " os-release"
IMAGE_INSTALL:append = " os-release"
IMAGE_FEATURES = ""
IMAGE_LINGUAS = " "

View File

@@ -1,8 +1,8 @@
FILESEXTRAPATHS_prepend_harden := "${THISDIR}/files:"
FILESEXTRAPATHS:prepend_harden := "${THISDIR}/files:"
SRC_URI_append_harden = " file://mountall.sh"
SRC_URI:append_harden = " file://mountall.sh"
do_install_append_harden() {
do_install:append_harden() {
install -d ${D}${sysconfdir}/init.d
install -m 0755 ${WORKDIR}/mountall.sh ${D}${sysconfdir}/init.d
}

View File

@@ -11,7 +11,7 @@ PACKAGES = "${PN} \
packagegroup-${PN} \
"
RDEPENDS_${PN} = "\
RDEPENDS:${PN} = "\
init-ifupdown \
${VIRTUAL-RUNTIME_base-utils-syslog} \
sudo \

View File

@@ -1,4 +1,4 @@
do_install_append_harden () {
do_install:append_harden () {
# to hardend
sed -i -e 's:UMASK.*:UMASK 027:' ${D}${sysconfdir}/login.defs
sed -i -e 's:PASS_MAX_DAYS.*:PASS_MAX_DAYS 365:' ${D}${sysconfdir}/login.defs

View File

@@ -1,6 +1,6 @@
PACKAGECONFIG_append_harden = " pam-wheel"
do_install_append_harden () {
PACKAGECONFIG:append_harden = " pam-wheel"
do_install:append_harden () {
if [ "${@bb.utils.contains('DISABLE_ROOT', 'True', 'yes', 'no', d)}" = "yes" ]; then
sed -i -e 's:root ALL=(ALL) ALL:#root ALL=(ALL) ALL:' ${D}${sysconfdir}/sudoers
fi