1 # 2 # Mandatory Access Control configuration 3 # 4 mainmenu_option next_comment 5 comment 'Security options' 6 7 [ -z "$CONFIG_CCSECURITY" ] && define_bool CON 8 bool 'CCSecurity support' CONFIG_CCSECURITY 9 10 if [ "$CONFIG_CCSECURITY" = "y" ]; then 11 12 [ -z "$CONFIG_CCSECURITY_LKM" ] && define_bo 13 bool 'Compile as loadable kernel module' CON 14 15 [ -z "$CONFIG_CCSECURITY_DISABLE_BY_DEFAULT" 16 bool 'Disable by default' CONFIG_CCSECURITY_ 17 18 [ -z "$CONFIG_CCSECURITY_MAX_ACCEPT_ENTRY" ] 19 [ $CONFIG_CCSECURITY_MAX_ACCEPT_ENTRY -lt 0 20 int 'Default maximal count for learning mod 21 22 [ -z "$CONFIG_CCSECURITY_MAX_AUDIT_LOG" ] && 23 [ $CONFIG_CCSECURITY_MAX_AUDIT_LOG -lt 0 ] & 24 int 'Default maximal count for audit log' C 25 26 [ -z "$CONFIG_CCSECURITY_OMIT_USERSPACE_LOAD 27 bool 'Activate without calling userspace pol 28 29 if [ "$CONFIG_CCSECURITY_OMIT_USERSPACE_LOAD 30 31 define_string CONFIG_CCSECURITY_POLICY_LOA 32 string 'Location of userspace policy loade 33 34 define_string CONFIG_CCSECURITY_ACTIVATION 35 string 'Trigger for calling userspace poli 36 37 fi 38 39 [ -z "$CONFIG_CCSECURITY_FILE_READDIR" ] && 40 bool "Enable readdir operation restriction." 41 42 [ -z "$CONFIG_CCSECURITY_FILE_GETATTR" ] && 43 bool "Enable getattr operation restriction." 44 45 if [ "$CONFIG_NET" = "y" ]; then 46 47 [ -z "$CONFIG_CCSECURITY_NETWORK" ] && de 48 bool "Enable socket operation restriction 49 50 if [ "$CONFIG_CCSECURITY_NETWORK" = "y" ] 51 52 #[ -z "$CONFIG_CCSECURITY_NETWORK_RECV 53 define_bool CONFIG_CCSECURITY_NETWORK_ 54 55 fi 56 57 fi 58 59 [ -z "$CONFIG_CCSECURITY_CAPABILITY" ] && de 60 bool "Enable non-POSIX capability operation 61 62 [ -z "$CONFIG_CCSECURITY_IPC" ] && define_bo 63 bool "Enable IPC operation restriction." CON 64 65 [ -z "$CONFIG_CCSECURITY_MISC" ] && define_b 66 bool "Enable environment variable names rest 67 68 [ -z "$CONFIG_CCSECURITY_TASK_EXECUTE_HANDLE 69 bool "Enable execute handler functionality." 70 71 [ -z "$CONFIG_CCSECURITY_TASK_DOMAIN_TRANSIT 72 bool "Enable domain transition without progr 73 74 if [ "$CONFIG_NET" = "y" ]; then 75 76 [ -z "$CONFIG_CCSECURITY_PORTRESERVE" ] & 77 bool "Enable local port reserver." CONFIG 78 79 fi 80 81 fi 82 83 endmenu
Linux® is a registered trademark of Linus Torvalds in the United States and other countries.
TOMOYO® is a registered trademark of NTT DATA CORPORATION.