From 25f50bd5104090e849912fc1757689be32542e81 Mon Sep 17 00:00:00 2001 From: Armin Kuster Date: Sat, 1 Apr 2017 16:54:47 -0700 Subject: linux-yocto: add 4.10 kernel support Signed-off-by: Armin Kuster --- recipes-kernel/linux/linux-yocto-4.10/apparmor.cfg | 13 +++++++++++++ recipes-kernel/linux/linux-yocto-4.10/smack-default-lsm.cfg | 2 ++ recipes-kernel/linux/linux-yocto-4.10/smack.cfg | 8 ++++++++ recipes-kernel/linux/linux-yocto_4.10.bbappend | 13 +++++++++++++ 4 files changed, 36 insertions(+) create mode 100644 recipes-kernel/linux/linux-yocto-4.10/apparmor.cfg create mode 100644 recipes-kernel/linux/linux-yocto-4.10/smack-default-lsm.cfg create mode 100644 recipes-kernel/linux/linux-yocto-4.10/smack.cfg create mode 100644 recipes-kernel/linux/linux-yocto_4.10.bbappend diff --git a/recipes-kernel/linux/linux-yocto-4.10/apparmor.cfg b/recipes-kernel/linux/linux-yocto-4.10/apparmor.cfg new file mode 100644 index 0000000..1dc4168 --- /dev/null +++ b/recipes-kernel/linux/linux-yocto-4.10/apparmor.cfg @@ -0,0 +1,13 @@ +CONFIG_AUDIT=y +CONFIG_AUDITSYSCALL=y +CONFIG_AUDIT_WATCH=y +CONFIG_AUDIT_TREE=y +# CONFIG_NETFILTER_XT_TARGET_AUDIT is not set +CONFIG_SECURITY_PATH=y +# CONFIG_SECURITY_SELINUX is not set +CONFIG_SECURITY_APPARMOR=y +CONFIG_SECURITY_APPARMOR_BOOTPARAM_VALUE=1 +CONFIG_SECURITY_APPARMOR_HASH=y +CONFIG_SECURITY_APPARMOR_HASH_DEFAULT=y +CONFIG_INTEGRITY_AUDIT=y +# CONFIG_DEFAULT_SECURITY_APPARMOR is not set diff --git a/recipes-kernel/linux/linux-yocto-4.10/smack-default-lsm.cfg b/recipes-kernel/linux/linux-yocto-4.10/smack-default-lsm.cfg new file mode 100644 index 0000000..b5c4845 --- /dev/null +++ b/recipes-kernel/linux/linux-yocto-4.10/smack-default-lsm.cfg @@ -0,0 +1,2 @@ +CONFIG_DEFAULT_SECURITY="smack" +CONFIG_DEFAULT_SECURITY_SMACK=y diff --git a/recipes-kernel/linux/linux-yocto-4.10/smack.cfg b/recipes-kernel/linux/linux-yocto-4.10/smack.cfg new file mode 100644 index 0000000..62f465a --- /dev/null +++ b/recipes-kernel/linux/linux-yocto-4.10/smack.cfg @@ -0,0 +1,8 @@ +CONFIG_IP_NF_SECURITY=m +CONFIG_IP6_NF_SECURITY=m +CONFIG_EXT2_FS_SECURITY=y +CONFIG_EXT3_FS_SECURITY=y +CONFIG_EXT4_FS_SECURITY=y +CONFIG_SECURITY=y +CONFIG_SECURITY_SMACK=y +CONFIG_TMPFS_XATTR=y diff --git a/recipes-kernel/linux/linux-yocto_4.10.bbappend b/recipes-kernel/linux/linux-yocto_4.10.bbappend new file mode 100644 index 0000000..35a32b6 --- /dev/null +++ b/recipes-kernel/linux/linux-yocto_4.10.bbappend @@ -0,0 +1,13 @@ +FILESEXTRAPATHS_prepend := "${THISDIR}/${PN}-4.10:" + +# TPM kernel support +KERNEL_FEATURES_append += "${@bb.utils.contains('DISTRO_FEATURES', 'tpm', ' features/tpm/tpm.scc', '', d)}" + +SRC_URI += "\ + ${@bb.utils.contains('DISTRO_FEATURES', 'apparmor', ' file://apparmor.cfg', '', d)} \ +" + +SRC_URI += "\ + ${@bb.utils.contains('DISTRO_FEATURES', 'smack', ' file://smack.cfg', '', d)} \ + ${@bb.utils.contains('DISTRO_FEATURES', 'smack', ' file://smack-default-lsm.cfg', '', d)} \ +" -- cgit v1.2.3-54-g00ecf