AppArmor: Enable configuring and building of the AppArmor security module
Kconfig and Makefiles to enable configuration and building of AppArmor. Signed-off-by: John Johansen <john.johansen@canonical.com> Signed-off-by: James Morris <jmorris@namei.org>
This commit is contained in:
parent
c1c124e91e
commit
f9ad1af53d
|
@ -140,6 +140,7 @@ config LSM_MMAP_MIN_ADDR
|
||||||
source security/selinux/Kconfig
|
source security/selinux/Kconfig
|
||||||
source security/smack/Kconfig
|
source security/smack/Kconfig
|
||||||
source security/tomoyo/Kconfig
|
source security/tomoyo/Kconfig
|
||||||
|
source security/apparmor/Kconfig
|
||||||
|
|
||||||
source security/integrity/ima/Kconfig
|
source security/integrity/ima/Kconfig
|
||||||
|
|
||||||
|
@ -148,6 +149,7 @@ choice
|
||||||
default DEFAULT_SECURITY_SELINUX if SECURITY_SELINUX
|
default DEFAULT_SECURITY_SELINUX if SECURITY_SELINUX
|
||||||
default DEFAULT_SECURITY_SMACK if SECURITY_SMACK
|
default DEFAULT_SECURITY_SMACK if SECURITY_SMACK
|
||||||
default DEFAULT_SECURITY_TOMOYO if SECURITY_TOMOYO
|
default DEFAULT_SECURITY_TOMOYO if SECURITY_TOMOYO
|
||||||
|
default DEFAULT_SECURITY_APPARMOR if SECURITY_APPARMOR
|
||||||
default DEFAULT_SECURITY_DAC
|
default DEFAULT_SECURITY_DAC
|
||||||
|
|
||||||
help
|
help
|
||||||
|
@ -163,6 +165,9 @@ choice
|
||||||
config DEFAULT_SECURITY_TOMOYO
|
config DEFAULT_SECURITY_TOMOYO
|
||||||
bool "TOMOYO" if SECURITY_TOMOYO=y
|
bool "TOMOYO" if SECURITY_TOMOYO=y
|
||||||
|
|
||||||
|
config DEFAULT_SECURITY_APPARMOR
|
||||||
|
bool "AppArmor" if SECURITY_APPARMOR=y
|
||||||
|
|
||||||
config DEFAULT_SECURITY_DAC
|
config DEFAULT_SECURITY_DAC
|
||||||
bool "Unix Discretionary Access Controls"
|
bool "Unix Discretionary Access Controls"
|
||||||
|
|
||||||
|
@ -173,6 +178,7 @@ config DEFAULT_SECURITY
|
||||||
default "selinux" if DEFAULT_SECURITY_SELINUX
|
default "selinux" if DEFAULT_SECURITY_SELINUX
|
||||||
default "smack" if DEFAULT_SECURITY_SMACK
|
default "smack" if DEFAULT_SECURITY_SMACK
|
||||||
default "tomoyo" if DEFAULT_SECURITY_TOMOYO
|
default "tomoyo" if DEFAULT_SECURITY_TOMOYO
|
||||||
|
default "apparmor" if DEFAULT_SECURITY_APPARMOR
|
||||||
default "" if DEFAULT_SECURITY_DAC
|
default "" if DEFAULT_SECURITY_DAC
|
||||||
|
|
||||||
endmenu
|
endmenu
|
||||||
|
|
|
@ -6,6 +6,7 @@ obj-$(CONFIG_KEYS) += keys/
|
||||||
subdir-$(CONFIG_SECURITY_SELINUX) += selinux
|
subdir-$(CONFIG_SECURITY_SELINUX) += selinux
|
||||||
subdir-$(CONFIG_SECURITY_SMACK) += smack
|
subdir-$(CONFIG_SECURITY_SMACK) += smack
|
||||||
subdir-$(CONFIG_SECURITY_TOMOYO) += tomoyo
|
subdir-$(CONFIG_SECURITY_TOMOYO) += tomoyo
|
||||||
|
subdir-$(CONFIG_SECURITY_APPARMOR) += apparmor
|
||||||
|
|
||||||
# always enable default capabilities
|
# always enable default capabilities
|
||||||
obj-y += commoncap.o
|
obj-y += commoncap.o
|
||||||
|
@ -19,6 +20,7 @@ obj-$(CONFIG_SECURITY_SELINUX) += selinux/built-in.o
|
||||||
obj-$(CONFIG_SECURITY_SMACK) += smack/built-in.o
|
obj-$(CONFIG_SECURITY_SMACK) += smack/built-in.o
|
||||||
obj-$(CONFIG_AUDIT) += lsm_audit.o
|
obj-$(CONFIG_AUDIT) += lsm_audit.o
|
||||||
obj-$(CONFIG_SECURITY_TOMOYO) += tomoyo/built-in.o
|
obj-$(CONFIG_SECURITY_TOMOYO) += tomoyo/built-in.o
|
||||||
|
obj-$(CONFIG_SECURITY_APPARMOR) += apparmor/built-in.o
|
||||||
obj-$(CONFIG_CGROUP_DEVICE) += device_cgroup.o
|
obj-$(CONFIG_CGROUP_DEVICE) += device_cgroup.o
|
||||||
|
|
||||||
# Object integrity file lists
|
# Object integrity file lists
|
||||||
|
|
Loading…
Reference in New Issue