]> git.ipfire.org Git - people/pmueller/ipfire-3.x.git/commitdiff
kernel: update config (disable AUDIT subsys)
authorArne Fitzenreiter <arne_f@ipfire.org>
Thu, 7 Sep 2017 21:54:38 +0000 (21:54 +0000)
committerMichael Tremer <michael.tremer@ipfire.org>
Mon, 11 Sep 2017 20:11:32 +0000 (21:11 +0100)
audit support was removed from the userspace so also the kernel not need it anymore.

fixes #11465

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
kernel/config-arm-generic
kernel/config-arm64-generic
kernel/config-generic
kernel/config-x86-generic
kernel/kernel.nm

index 8f7f4641f0c444415392e146453fa8517a72f485..130c5300aaa09ede475999b5eb90277f2f8a30c4 100644 (file)
@@ -427,6 +427,11 @@ CONFIG_DRM_DW_HDMI_I2S_AUDIO=m
 CONFIG_DRM_MESON=m
 CONFIG_DRM_MESON_DW_HDMI=m
 
+#
+# Frame buffer Devices
+#
+# CONFIG_FB_BOOT_VESA_SUPPORT is not set
+
 #
 # Frame buffer hardware drivers
 #
@@ -724,11 +729,6 @@ CONFIG_RCU_CPU_STALL_TIMEOUT=21
 # CONFIG_PID_IN_CONTEXTIDR is not set
 # CONFIG_CORESIGHT is not set
 
-#
-# Security options
-#
-CONFIG_LSM_MMAP_MIN_ADDR=32768
-
 #
 # Crypto core or helper
 #
@@ -748,5 +748,4 @@ CONFIG_CRYPTO_CHACHA20_NEON=m
 #
 # Library routines
 #
-CONFIG_AUDIT_GENERIC=y
 CONFIG_LIBFDT=y
index 208c1385f0dc329105d862ae49389897bb91635b..ef5aca3b9346749ca2746c8460e3bbe46b5e0968 100644 (file)
@@ -400,7 +400,7 @@ CONFIG_HISI_KIRIN_DW_DSI=m
 #
 # Frame buffer hardware drivers
 #
-# CONFIG_FB_EFI is not set
+CONFIG_FB_EFI=y
 
 #
 # Console display driver support
@@ -709,6 +709,5 @@ CONFIG_CRYPTO_AES_ARM64_BS=m
 # Library routines
 #
 CONFIG_AUDIT_ARCH_COMPAT_GENERIC=y
-CONFIG_AUDIT_COMPAT_GENERIC=y
 CONFIG_HAS_IOPORT_MAP=y
 CONFIG_UCS2_STRING=y
index 5fac5613ae5bf6742a064c9930e0d36047b59513..c1517692291136d88716d11b8c8c97060bf7829f 100644 (file)
@@ -34,11 +34,8 @@ CONFIG_POSIX_MQUEUE_SYSCTL=y
 CONFIG_CROSS_MEMORY_ATTACH=y
 CONFIG_FHANDLE=y
 # CONFIG_USELIB is not set
-CONFIG_AUDIT=y
+# CONFIG_AUDIT is not set
 CONFIG_HAVE_ARCH_AUDITSYSCALL=y
-CONFIG_AUDITSYSCALL=y
-CONFIG_AUDIT_WATCH=y
-CONFIG_AUDIT_TREE=y
 
 #
 # IRQ subsystem
@@ -697,7 +694,6 @@ CONFIG_NETFILTER_XT_SET=m
 #
 # Xtables targets
 #
-CONFIG_NETFILTER_XT_TARGET_AUDIT=m
 CONFIG_NETFILTER_XT_TARGET_CLASSIFY=m
 CONFIG_NETFILTER_XT_TARGET_CONNMARK=m
 CONFIG_NETFILTER_XT_TARGET_CONNSECMARK=m
@@ -3795,10 +3791,9 @@ CONFIG_FIRMWARE_EDID=y
 CONFIG_FB_CMDLINE=y
 CONFIG_FB_NOTIFY=y
 # CONFIG_FB_DDC is not set
-CONFIG_FB_BOOT_VESA_SUPPORT=y
-CONFIG_FB_CFB_FILLRECT=m
-CONFIG_FB_CFB_COPYAREA=m
-CONFIG_FB_CFB_IMAGEBLIT=m
+CONFIG_FB_CFB_FILLRECT=y
+CONFIG_FB_CFB_COPYAREA=y
+CONFIG_FB_CFB_IMAGEBLIT=y
 # CONFIG_FB_CFB_REV_PIXELS_IN_BYTE is not set
 CONFIG_FB_SYS_FILLRECT=m
 CONFIG_FB_SYS_COPYAREA=m
@@ -5578,7 +5573,7 @@ CONFIG_ENCRYPTED_KEYS=m
 # CONFIG_KEY_DH_OPERATIONS is not set
 CONFIG_SECURITY_DMESG_RESTRICT=y
 CONFIG_SECURITY=y
-CONFIG_SECURITY_WRITABLE_HOOKS=y
+# CONFIG_SECURITY_WRITABLE_HOOKS is not set
 CONFIG_SECURITYFS=y
 CONFIG_SECURITY_NETWORK=y
 CONFIG_SECURITY_NETWORK_XFRM=y
@@ -5587,13 +5582,6 @@ CONFIG_HAVE_HARDENED_USERCOPY_ALLOCATOR=y
 CONFIG_HARDENED_USERCOPY=y
 CONFIG_HARDENED_USERCOPY_PAGESPAN=y
 # CONFIG_STATIC_USERMODEHELPER is not set
-CONFIG_SECURITY_SELINUX=y
-CONFIG_SECURITY_SELINUX_BOOTPARAM=y
-CONFIG_SECURITY_SELINUX_BOOTPARAM_VALUE=0
-CONFIG_SECURITY_SELINUX_DISABLE=y
-CONFIG_SECURITY_SELINUX_DEVELOP=y
-CONFIG_SECURITY_SELINUX_AVC_STATS=y
-CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE=1
 # CONFIG_SECURITY_SMACK is not set
 # CONFIG_SECURITY_TOMOYO is not set
 # CONFIG_SECURITY_APPARMOR is not set
@@ -5603,12 +5591,10 @@ CONFIG_INTEGRITY=y
 CONFIG_INTEGRITY_SIGNATURE=y
 CONFIG_INTEGRITY_ASYMMETRIC_KEYS=y
 CONFIG_INTEGRITY_TRUSTED_KEYRING=y
-CONFIG_INTEGRITY_AUDIT=y
 # CONFIG_IMA is not set
 # CONFIG_EVM is not set
-CONFIG_DEFAULT_SECURITY_SELINUX=y
-# CONFIG_DEFAULT_SECURITY_DAC is not set
-CONFIG_DEFAULT_SECURITY="selinux"
+CONFIG_DEFAULT_SECURITY_DAC=y
+CONFIG_DEFAULT_SECURITY=""
 CONFIG_XOR_BLOCKS=m
 CONFIG_ASYNC_CORE=m
 CONFIG_ASYNC_MEMCPY=m
index 50318e3a700dbfd14531826f303a71369bd10b2a..1ed2ee29a98b859ba953abc601f7515f6631cf26 100644 (file)
@@ -1105,6 +1105,11 @@ CONFIG_DRM_VMWGFX=m
 #
 CONFIG_HSA_AMD=m
 
+#
+# Frame buffer Devices
+#
+CONFIG_FB_BOOT_VESA_SUPPORT=y
+
 #
 # Frame buffer hardware drivers
 #
@@ -1482,6 +1487,7 @@ CONFIG_EFIVAR_FS=m
 #
 # Compile-time checks and compiler options
 #
+CONFIG_HARDLOCKUP_CHECK_TIMESTAMP=y
 CONFIG_ARCH_WANT_FRAME_POINTERS=y
 CONFIG_FRAME_POINTER=y
 CONFIG_STACK_VALIDATION=y
@@ -1553,7 +1559,6 @@ CONFIG_OPTIMIZE_INLINING=y
 #
 CONFIG_KEYS_COMPAT=y
 CONFIG_INTEL_TXT=y
-CONFIG_LSM_MMAP_MIN_ADDR=65536
 
 #
 # Crypto core or helper
index 0724d4dcf8e24109afa221d047519a70d626ddb7..4936b6a122521897806aeb9ad8ae64046dc3653c 100644 (file)
@@ -33,7 +33,6 @@ build
 
        requires
                asciidoc
-               audit-devel
                bc
                binutils >= 2.25
                binutils-devel