Re: [PATCH kernel/goldfish] enable secmark labeling for SE Android network access controls

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sat, 2012-06-16 at 14:56 -0400, Joshua Brindle wrote:
> Signed-off-by: Joshua Brindle <jbrindle@xxxxxxxxxx>
> ---
>  arch/x86/configs/i386_defconfig |    4 ++++
>  1 file changed, 4 insertions(+)

I would have expected these changes to go into
arch/x86/configs/goldfish_defconfig,
arch/arm/configs/goldfish_defconfig, and
arch/arm/configs/goldfish_armv7_defconfig.

> 
> diff --git a/arch/x86/configs/i386_defconfig b/arch/x86/configs/i386_defconfig
> index edba00d..09db997 100644
> --- a/arch/x86/configs/i386_defconfig
> +++ b/arch/x86/configs/i386_defconfig
> @@ -2128,6 +2128,10 @@ CONFIG_SECURITY_NETWORK=y
>  CONFIG_SECURITY_FILE_CAPABILITIES=y
>  # CONFIG_SECURITY_ROOTPLUG is not set
>  CONFIG_SECURITY_DEFAULT_MMAP_MIN_ADDR=65536
> +CONFIG_NETWORK_SECMARK=y
> +CONFIG_NF_CONNTRACK_SECMARK=y
> +CONFIG_NETFILTER_XT_TARGET_CONNSECMARK=y
> +CONFIG_NETFILTER_XT_TARGET_SECMARK=y
>  CONFIG_SECURITY_SELINUX=y
>  CONFIG_SECURITY_SELINUX_BOOTPARAM=y
>  CONFIG_SECURITY_SELINUX_BOOTPARAM_VALUE=1

-- 
Stephen Smalley
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.


[Index of Archives]     [Selinux Refpolicy]     [Linux SGX]     [Fedora Users]     [Fedora Desktop]     [Yosemite Photos]     [Yosemite Camping]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux