]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/commitdiff
Kernel: Pin loading kernel files to one filesystem
authorPeter Müller <peter.mueller@ipfire.org>
Sun, 19 Dec 2021 17:36:32 +0000 (18:36 +0100)
committerPeter Müller <peter.mueller@ipfire.org>
Tue, 1 Mar 2022 15:29:06 +0000 (15:29 +0000)
This can be safely enabled on IPFire, as we never swap filesystems
during runtime.

Fixes: #12432
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
config/kernel/kernel.config.x86_64-ipfire

index 8b525ef894dd86859960dce657d08afb0f3a4c57..675c3ce1e15c21646b6a62140eb511ccfdc45f7a 100644 (file)
@@ -6968,7 +6968,8 @@ CONFIG_FORTIFY_SOURCE=y
 # CONFIG_SECURITY_SMACK is not set
 # CONFIG_SECURITY_TOMOYO is not set
 # CONFIG_SECURITY_APPARMOR is not set
-# CONFIG_SECURITY_LOADPIN is not set
+CONFIG_SECURITY_LOADPIN=y
+CONFIG_SECURITY_LOADPIN_ENFORCE=y
 # CONFIG_SECURITY_YAMA is not set
 # CONFIG_SECURITY_SAFESETID is not set
 # CONFIG_SECURITY_LOCKDOWN_LSM is not set