summaryrefslogtreecommitdiff
path: root/debian.ti-omap4
diff options
context:
space:
mode:
authorSebastien Jan <s-jan@ti.com>2011-09-01 16:11:38 +0200
committerXavier Boudet <x-boudet@ti.com>2011-10-26 20:42:21 +0200
commit787786b052db2e790ca49a269c2b23be20942b9d (patch)
tree95ab66b68aeec3b6f231cf49a1190b797f819766 /debian.ti-omap4
parente6f11d1983d1feb3f8270e0bd2d702040f095c87 (diff)
UBUNTU: customize enforce file for minimal config
Signed-off-by: Sebastien Jan <s-jan@ti.com>
Diffstat (limited to 'debian.ti-omap4')
-rw-r--r--debian.ti-omap4/config/enforce28
1 files changed, 20 insertions, 8 deletions
diff --git a/debian.ti-omap4/config/enforce b/debian.ti-omap4/config/enforce
index 4e5e7f838e25..76a4b9ea6579 100644
--- a/debian.ti-omap4/config/enforce
+++ b/debian.ti-omap4/config/enforce
@@ -9,10 +9,7 @@ value CONFIG_SECURITY y
!exists CONFIG_SECURITY_FILE_CAPABILITIES | value CONFIG_SECURITY_FILE_CAPABILITIES y
value CONFIG_SECURITY_SELINUX y
value CONFIG_SECURITY_SMACK y
-value CONFIG_SECURITY_YAMA y
value CONFIG_SYN_COOKIES y
-value CONFIG_DEFAULT_SECURITY_APPARMOR y
-# For architectures which support this option ensure it is enabled.
!exists CONFIG_SECCOMP | value CONFIG_SECCOMP y
!exists CONFIG_CC_STACKPROTECTOR | value CONFIG_CC_STACKPROTECTOR y
!exists CONFIG_DEBUG_RODATA | value CONFIG_DEBUG_RODATA y
@@ -20,13 +17,16 @@ value CONFIG_DEFAULT_SECURITY_APPARMOR y
# For architectures which support this option ensure it is disabled.
!exists CONFIG_COMPAT_VDSO | value CONFIG_COMPAT_VDSO n
# Default to 32768 for armel, 65536 for everything else.
-( arch armel & value CONFIG_DEFAULT_MMAP_MIN_ADDR 32768 ) | \
- ( value CONFIG_DEFAULT_MMAP_MIN_ADDR 65536)
+( arch armel & value CONFIG_DEFAULT_MMAP_MIN_ADDR 32768 ) | ( value CONFIG_DEFAULT_MMAP_MIN_ADDR 65536)
# CONFIG_USB_DEVICE_FS breaks udev USB firmware loading and is deprecated
# ensure it is disabled.
value CONFIG_USB_DEVICEFS n
+# ARM requires some THUMB options
+(arch armel & value CONFIG_ARM_THUMB y)
+(arch armel & value CONFIG_ARM_THUMBEE y)
+
# upstart requires DEVTMPFS be enabled and mounted by default.
value CONFIG_DEVTMPFS y
value CONFIG_DEVTMPFS_MOUNT y
@@ -41,7 +41,7 @@ value CONFIG_BLK_DEV_RAM_SIZE 65536
value CONFIG_BLK_DEV_DM y
# sysfs: ensure all DEPRECATED items are off
-value CONFIG_SYSFS_DEPRECATED_V2 n
+!exists CONFIG_SYSFS_DEPRECATED_V2 | value CONFIG_SYSFS_DEPRECATED_V2 n
!exists CONFIG_SYSFS_DEPRECATED | value CONFIG_SYSFS_DEPRECATED n
# automatically add local version will cause packaging failure
@@ -53,8 +53,20 @@ value CONFIG_FRAMEBUFFER_CONSOLE y
# GRUB changes will rely on built in vesafb on x86,
# UbuntuSpec:foundations-m-grub2-boot-framebuffer
-(( arch i386 | arch amd64 ) & value CONFIG_FB_VESA y) | \
- value CONFIG_FB_VESA m | !exists CONFIG_FB_VESA
+(( arch i386 | arch amd64 ) & value CONFIG_FB_VESA y) | value CONFIG_FB_VESA m | !exists CONFIG_FB_VESA
# Build in uinput module so that it's always available (LP: 584812)
value CONFIG_INPUT_UINPUT y
+
+#prevent some Android settings:
+#value CONFIG_ANDROID_PARANOID_NETWORK n
+
+# force some convenient settings
+value CONFIG_BLK_DEV_SD y
+value CONFIG_KPROBES y
+value CONFIG_OPROFILE y
+value CONFIG_RELAY y
+value CONFIG_SCSI y
+value CONFIG_TUN y
+value CONFIG_USB_VIDEO_CLASS m
+