Signed-off-by: Armin Kuster <[email protected]>
---
 recipes-kernel/linux/linux-yocto-4.10/apparmor.cfg          | 13 +++++++++++++
 recipes-kernel/linux/linux-yocto-4.10/smack-default-lsm.cfg |  2 ++
 recipes-kernel/linux/linux-yocto-4.10/smack.cfg             |  8 ++++++++
 recipes-kernel/linux/linux-yocto_4.10.bbappend              | 13 +++++++++++++
 4 files changed, 36 insertions(+)
 create mode 100644 recipes-kernel/linux/linux-yocto-4.10/apparmor.cfg
 create mode 100644 recipes-kernel/linux/linux-yocto-4.10/smack-default-lsm.cfg
 create mode 100644 recipes-kernel/linux/linux-yocto-4.10/smack.cfg
 create mode 100644 recipes-kernel/linux/linux-yocto_4.10.bbappend

diff --git a/recipes-kernel/linux/linux-yocto-4.10/apparmor.cfg 
b/recipes-kernel/linux/linux-yocto-4.10/apparmor.cfg
new file mode 100644
index 0000000..1dc4168
--- /dev/null
+++ b/recipes-kernel/linux/linux-yocto-4.10/apparmor.cfg
@@ -0,0 +1,13 @@
+CONFIG_AUDIT=y
+CONFIG_AUDITSYSCALL=y
+CONFIG_AUDIT_WATCH=y
+CONFIG_AUDIT_TREE=y
+# CONFIG_NETFILTER_XT_TARGET_AUDIT is not set
+CONFIG_SECURITY_PATH=y
+# CONFIG_SECURITY_SELINUX is not set
+CONFIG_SECURITY_APPARMOR=y
+CONFIG_SECURITY_APPARMOR_BOOTPARAM_VALUE=1
+CONFIG_SECURITY_APPARMOR_HASH=y
+CONFIG_SECURITY_APPARMOR_HASH_DEFAULT=y
+CONFIG_INTEGRITY_AUDIT=y
+# CONFIG_DEFAULT_SECURITY_APPARMOR is not set
diff --git a/recipes-kernel/linux/linux-yocto-4.10/smack-default-lsm.cfg 
b/recipes-kernel/linux/linux-yocto-4.10/smack-default-lsm.cfg
new file mode 100644
index 0000000..b5c4845
--- /dev/null
+++ b/recipes-kernel/linux/linux-yocto-4.10/smack-default-lsm.cfg
@@ -0,0 +1,2 @@
+CONFIG_DEFAULT_SECURITY="smack"
+CONFIG_DEFAULT_SECURITY_SMACK=y
diff --git a/recipes-kernel/linux/linux-yocto-4.10/smack.cfg 
b/recipes-kernel/linux/linux-yocto-4.10/smack.cfg
new file mode 100644
index 0000000..62f465a
--- /dev/null
+++ b/recipes-kernel/linux/linux-yocto-4.10/smack.cfg
@@ -0,0 +1,8 @@
+CONFIG_IP_NF_SECURITY=m
+CONFIG_IP6_NF_SECURITY=m
+CONFIG_EXT2_FS_SECURITY=y
+CONFIG_EXT3_FS_SECURITY=y
+CONFIG_EXT4_FS_SECURITY=y
+CONFIG_SECURITY=y
+CONFIG_SECURITY_SMACK=y
+CONFIG_TMPFS_XATTR=y
diff --git a/recipes-kernel/linux/linux-yocto_4.10.bbappend 
b/recipes-kernel/linux/linux-yocto_4.10.bbappend
new file mode 100644
index 0000000..35a32b6
--- /dev/null
+++ b/recipes-kernel/linux/linux-yocto_4.10.bbappend
@@ -0,0 +1,13 @@
+FILESEXTRAPATHS_prepend := "${THISDIR}/${PN}-4.10:"
+
+# TPM kernel support
+KERNEL_FEATURES_append += "${@bb.utils.contains('DISTRO_FEATURES', 'tpm', ' 
features/tpm/tpm.scc', '', d)}"
+
+SRC_URI += "\
+        ${@bb.utils.contains('DISTRO_FEATURES', 'apparmor', ' 
file://apparmor.cfg', '', d)} \
+"
+
+SRC_URI += "\
+        ${@bb.utils.contains('DISTRO_FEATURES', 'smack', ' file://smack.cfg', 
'', d)} \
+        ${@bb.utils.contains('DISTRO_FEATURES', 'smack', ' 
file://smack-default-lsm.cfg', '', d)} \
+"
-- 
2.7.4

-- 
_______________________________________________
yocto mailing list
[email protected]
https://lists.yoctoproject.org/listinfo/yocto

Reply via email to