mirror of
https://git.yoctoproject.org/meta-security
synced 2026-05-09 17:40:32 +00:00
linux-yocto/5.0: add apparmor fragments
Signed-off-by: Armin Kuster <akuster808@gmail.com>
This commit is contained in:
@@ -0,0 +1,15 @@
|
|||||||
|
CONFIG_AUDIT=y
|
||||||
|
# CONFIG_NETFILTER_XT_TARGET_AUDIT is not set
|
||||||
|
CONFIG_SECURITY_NETWORK=y
|
||||||
|
# CONFIG_SECURITY_NETWORK_XFRM is not set
|
||||||
|
CONFIG_SECURITY_PATH=y
|
||||||
|
# CONFIG_SECURITY_SELINUX is not set
|
||||||
|
CONFIG_SECURITY_APPARMOR=y
|
||||||
|
CONFIG_SECURITY_APPARMOR_HASH=y
|
||||||
|
CONFIG_SECURITY_APPARMOR_HASH_DEFAULT=y
|
||||||
|
# CONFIG_SECURITY_APPARMOR_DEBUG is not set
|
||||||
|
CONFIG_INTEGRITY_AUDIT=y
|
||||||
|
CONFIG_DEFAULT_SECURITY_APPARMOR=y
|
||||||
|
# CONFIG_DEFAULT_SECURITY_DAC is not set
|
||||||
|
CONFIG_DEFAULT_SECURITY="apparmor"
|
||||||
|
CONFIG_AUDIT_GENERIC=y
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
CONFIG_SECURITY_APPARMOR_BOOTPARAM_VALUE=1
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
CONFIG_DEFAULT_SECURITY="smack"
|
||||||
|
CONFIG_DEFAULT_SECURITY_SMACK=y
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
CONFIG_IP_NF_SECURITY=m
|
||||||
|
CONFIG_IP6_NF_SECURITY=m
|
||||||
|
CONFIG_EXT2_FS_SECURITY=y
|
||||||
|
CONFIG_EXT3_FS_SECURITY=y
|
||||||
|
CONFIG_EXT4_FS_SECURITY=y
|
||||||
|
CONFIG_SECURITY=y
|
||||||
|
CONFIG_SECURITY_SMACK=y
|
||||||
|
CONFIG_TMPFS_XATTR=y
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
FILESEXTRAPATHS_prepend := "${THISDIR}/${PN}-5.0:"
|
||||||
|
|
||||||
|
SRC_URI += "\
|
||||||
|
${@bb.utils.contains('DISTRO_FEATURES', 'apparmor', ' file://apparmor.cfg', '', d)} \
|
||||||
|
${@bb.utils.contains('DISTRO_FEATURES', 'apparmor', ' file://apparmor_on_boot.cfg', '', d)} \
|
||||||
|
"
|
||||||
|
|
||||||
|
SRC_URI += "\
|
||||||
|
${@bb.utils.contains('DISTRO_FEATURES', 'smack', ' file://smack.cfg', '', d)} \
|
||||||
|
${@bb.utils.contains('DISTRO_FEATURES', 'smack', ' file://smack-default-lsm.cfg', '', d)} \
|
||||||
|
"
|
||||||
Reference in New Issue
Block a user