~ [ source navigation ] ~ [ diff markup ] ~ [ identifier search ] ~

TOMOYO Linux Cross Reference
Linux/security/ccsecurity/Config.in

Version: ~ [ linux-6.12-rc7 ] ~ [ linux-6.11.7 ] ~ [ linux-6.10.14 ] ~ [ linux-6.9.12 ] ~ [ linux-6.8.12 ] ~ [ linux-6.7.12 ] ~ [ linux-6.6.60 ] ~ [ linux-6.5.13 ] ~ [ linux-6.4.16 ] ~ [ linux-6.3.13 ] ~ [ linux-6.2.16 ] ~ [ linux-6.1.116 ] ~ [ linux-6.0.19 ] ~ [ linux-5.19.17 ] ~ [ linux-5.18.19 ] ~ [ linux-5.17.15 ] ~ [ linux-5.16.20 ] ~ [ linux-5.15.171 ] ~ [ linux-5.14.21 ] ~ [ linux-5.13.19 ] ~ [ linux-5.12.19 ] ~ [ linux-5.11.22 ] ~ [ linux-5.10.229 ] ~ [ linux-5.9.16 ] ~ [ linux-5.8.18 ] ~ [ linux-5.7.19 ] ~ [ linux-5.6.19 ] ~ [ linux-5.5.19 ] ~ [ linux-5.4.285 ] ~ [ linux-5.3.18 ] ~ [ linux-5.2.21 ] ~ [ linux-5.1.21 ] ~ [ linux-5.0.21 ] ~ [ linux-4.20.17 ] ~ [ linux-4.19.323 ] ~ [ linux-4.18.20 ] ~ [ linux-4.17.19 ] ~ [ linux-4.16.18 ] ~ [ linux-4.15.18 ] ~ [ linux-4.14.336 ] ~ [ linux-4.13.16 ] ~ [ linux-4.12.14 ] ~ [ linux-4.11.12 ] ~ [ linux-4.10.17 ] ~ [ linux-4.9.337 ] ~ [ linux-4.4.302 ] ~ [ linux-3.10.108 ] ~ [ linux-2.6.32.71 ] ~ [ linux-2.6.0 ] ~ [ linux-2.4.37.11 ] ~ [ unix-v6-master ] ~ [ ccs-tools-1.8.12 ] ~ [ policy-sample ] ~
Architecture: ~ [ i386 ] ~ [ alpha ] ~ [ m68k ] ~ [ mips ] ~ [ ppc ] ~ [ sparc ] ~ [ sparc64 ] ~

Diff markup

Differences between /security/ccsecurity/Config.in (Version linux-6.12-rc7) and /security/ccsecurity/Config.in (Version unix-v6-master)


  1 #                                                 
  2 # Mandatory Access Control configuration          
  3 #                                                 
  4 mainmenu_option next_comment                      
  5 comment 'Security options'                        
  6                                                   
  7 [ -z "$CONFIG_CCSECURITY" ] && define_bool CON    
  8 bool 'CCSecurity support' CONFIG_CCSECURITY       
  9                                                   
 10 if [ "$CONFIG_CCSECURITY" = "y" ]; then           
 11                                                   
 12   [ -z "$CONFIG_CCSECURITY_LKM" ] && define_bo    
 13   bool 'Compile as loadable kernel module' CON    
 14                                                   
 15   [ -z "$CONFIG_CCSECURITY_DISABLE_BY_DEFAULT"    
 16   bool 'Disable by default' CONFIG_CCSECURITY_    
 17                                                   
 18   [ -z "$CONFIG_CCSECURITY_MAX_ACCEPT_ENTRY" ]    
 19   [ $CONFIG_CCSECURITY_MAX_ACCEPT_ENTRY -lt 0     
 20   int  'Default maximal count for learning mod    
 21                                                   
 22   [ -z "$CONFIG_CCSECURITY_MAX_AUDIT_LOG" ] &&    
 23   [ $CONFIG_CCSECURITY_MAX_AUDIT_LOG -lt 0 ] &    
 24   int  'Default maximal count for audit log' C    
 25                                                   
 26   [ -z "$CONFIG_CCSECURITY_OMIT_USERSPACE_LOAD    
 27   bool 'Activate without calling userspace pol    
 28                                                   
 29   if [ "$CONFIG_CCSECURITY_OMIT_USERSPACE_LOAD    
 30                                                   
 31     define_string CONFIG_CCSECURITY_POLICY_LOA    
 32     string 'Location of userspace policy loade    
 33                                                   
 34     define_string CONFIG_CCSECURITY_ACTIVATION    
 35     string 'Trigger for calling userspace poli    
 36                                                   
 37   fi                                              
 38                                                   
 39   [ -z "$CONFIG_CCSECURITY_FILE_READDIR" ] &&     
 40   bool "Enable readdir operation restriction."    
 41                                                   
 42   [ -z "$CONFIG_CCSECURITY_FILE_GETATTR" ] &&     
 43   bool "Enable getattr operation restriction."    
 44                                                   
 45   if [ "$CONFIG_NET" = "y" ]; then                
 46                                                   
 47      [ -z "$CONFIG_CCSECURITY_NETWORK" ] && de    
 48      bool "Enable socket operation restriction    
 49                                                   
 50      if [ "$CONFIG_CCSECURITY_NETWORK" = "y" ]    
 51                                                   
 52         #[ -z "$CONFIG_CCSECURITY_NETWORK_RECV    
 53         define_bool CONFIG_CCSECURITY_NETWORK_    
 54                                                   
 55      fi                                           
 56                                                   
 57   fi                                              
 58                                                   
 59   [ -z "$CONFIG_CCSECURITY_CAPABILITY" ] && de    
 60   bool "Enable non-POSIX capability operation     
 61                                                   
 62   [ -z "$CONFIG_CCSECURITY_IPC" ] && define_bo    
 63   bool "Enable IPC operation restriction." CON    
 64                                                   
 65   [ -z "$CONFIG_CCSECURITY_MISC" ] && define_b    
 66   bool "Enable environment variable names rest    
 67                                                   
 68   [ -z "$CONFIG_CCSECURITY_TASK_EXECUTE_HANDLE    
 69   bool "Enable execute handler functionality."    
 70                                                   
 71   [ -z "$CONFIG_CCSECURITY_TASK_DOMAIN_TRANSIT    
 72   bool "Enable domain transition without progr    
 73                                                   
 74   if [ "$CONFIG_NET" = "y" ]; then                
 75                                                   
 76      [ -z "$CONFIG_CCSECURITY_PORTRESERVE" ] &    
 77      bool "Enable local port reserver." CONFIG    
 78                                                   
 79   fi                                              
 80                                                   
 81 fi                                                
 82                                                   
 83 endmenu                                           
                                                      

~ [ source navigation ] ~ [ diff markup ] ~ [ identifier search ] ~

kernel.org | git.kernel.org | LWN.net | Project Home | SVN repository | Mail admin

Linux® is a registered trademark of Linus Torvalds in the United States and other countries.
TOMOYO® is a registered trademark of NTT DATA CORPORATION.

sflogo.php