linux5.15+: Add landlock to CONFIG_LSM
This commit is contained in:
parent
f389e5416d
commit
661f17ea74
18 changed files with 18 additions and 18 deletions
|
@ -11226,7 +11226,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_EVM is not set
|
||||
CONFIG_DEFAULT_SECURITY_APPARMOR=y
|
||||
# CONFIG_DEFAULT_SECURITY_DAC is not set
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -9544,7 +9544,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
|
||||
# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
|
||||
CONFIG_DEFAULT_SECURITY_DAC=y
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -7674,7 +7674,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
|
||||
CONFIG_DEFAULT_SECURITY_APPARMOR=y
|
||||
# CONFIG_DEFAULT_SECURITY_DAC is not set
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity,apparmor,selinux,smack,tomoyo"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity,apparmor,selinux,smack,tomoyo"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -9658,7 +9658,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
|
||||
# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
|
||||
CONFIG_DEFAULT_SECURITY_DAC=y
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -9380,7 +9380,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
|
||||
# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
|
||||
CONFIG_DEFAULT_SECURITY_DAC=y
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -9728,7 +9728,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_EVM is not set
|
||||
# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
|
||||
CONFIG_DEFAULT_SECURITY_DAC=y
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -11759,7 +11759,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_EVM is not set
|
||||
CONFIG_DEFAULT_SECURITY_APPARMOR=y
|
||||
# CONFIG_DEFAULT_SECURITY_DAC is not set
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -9964,7 +9964,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
|
||||
# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
|
||||
CONFIG_DEFAULT_SECURITY_DAC=y
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -8005,7 +8005,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
|
||||
CONFIG_DEFAULT_SECURITY_APPARMOR=y
|
||||
# CONFIG_DEFAULT_SECURITY_DAC is not set
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity,apparmor,selinux,smack,tomoyo"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity,apparmor,selinux,smack,tomoyo"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -10030,7 +10030,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
|
||||
# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
|
||||
CONFIG_DEFAULT_SECURITY_DAC=y
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -9750,7 +9750,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
|
||||
# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
|
||||
CONFIG_DEFAULT_SECURITY_DAC=y
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -10188,7 +10188,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_EVM is not set
|
||||
# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
|
||||
CONFIG_DEFAULT_SECURITY_DAC=y
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -11785,7 +11785,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_EVM is not set
|
||||
CONFIG_DEFAULT_SECURITY_APPARMOR=y
|
||||
# CONFIG_DEFAULT_SECURITY_DAC is not set
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -9981,7 +9981,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
|
||||
# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
|
||||
CONFIG_DEFAULT_SECURITY_DAC=y
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -8009,7 +8009,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
|
||||
CONFIG_DEFAULT_SECURITY_APPARMOR=y
|
||||
# CONFIG_DEFAULT_SECURITY_DAC is not set
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity,apparmor,selinux,smack,tomoyo"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity,apparmor,selinux,smack,tomoyo"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -10050,7 +10050,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
|
||||
# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
|
||||
CONFIG_DEFAULT_SECURITY_DAC=y
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -9771,7 +9771,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_DEFAULT_SECURITY_SELINUX is not set
|
||||
# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
|
||||
CONFIG_DEFAULT_SECURITY_DAC=y
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
|
@ -10219,7 +10219,7 @@ CONFIG_INTEGRITY_AUDIT=y
|
|||
# CONFIG_EVM is not set
|
||||
# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
|
||||
CONFIG_DEFAULT_SECURITY_DAC=y
|
||||
CONFIG_LSM="yama,loadpin,safesetid,integrity"
|
||||
CONFIG_LSM="landlock,yama,loadpin,safesetid,integrity"
|
||||
|
||||
#
|
||||
# Kernel hardening options
|
||||
|
|
Loading…
Add table
Reference in a new issue