diff options
author | Sebastien Jan <s-jan@ti.com> | 2011-09-01 16:11:38 +0200 |
---|---|---|
committer | Xavier Boudet <x-boudet@ti.com> | 2011-10-26 20:42:21 +0200 |
commit | 787786b052db2e790ca49a269c2b23be20942b9d (patch) | |
tree | 95ab66b68aeec3b6f231cf49a1190b797f819766 /debian.ti-omap4 | |
parent | e6f11d1983d1feb3f8270e0bd2d702040f095c87 (diff) |
UBUNTU: customize enforce file for minimal config
Signed-off-by: Sebastien Jan <s-jan@ti.com>
Diffstat (limited to 'debian.ti-omap4')
-rw-r--r-- | debian.ti-omap4/config/enforce | 28 |
1 files changed, 20 insertions, 8 deletions
diff --git a/debian.ti-omap4/config/enforce b/debian.ti-omap4/config/enforce index 4e5e7f838e25..76a4b9ea6579 100644 --- a/debian.ti-omap4/config/enforce +++ b/debian.ti-omap4/config/enforce @@ -9,10 +9,7 @@ value CONFIG_SECURITY y !exists CONFIG_SECURITY_FILE_CAPABILITIES | value CONFIG_SECURITY_FILE_CAPABILITIES y value CONFIG_SECURITY_SELINUX y value CONFIG_SECURITY_SMACK y -value CONFIG_SECURITY_YAMA y value CONFIG_SYN_COOKIES y -value CONFIG_DEFAULT_SECURITY_APPARMOR y -# For architectures which support this option ensure it is enabled. !exists CONFIG_SECCOMP | value CONFIG_SECCOMP y !exists CONFIG_CC_STACKPROTECTOR | value CONFIG_CC_STACKPROTECTOR y !exists CONFIG_DEBUG_RODATA | value CONFIG_DEBUG_RODATA y @@ -20,13 +17,16 @@ value CONFIG_DEFAULT_SECURITY_APPARMOR y # For architectures which support this option ensure it is disabled. !exists CONFIG_COMPAT_VDSO | value CONFIG_COMPAT_VDSO n # Default to 32768 for armel, 65536 for everything else. -( arch armel & value CONFIG_DEFAULT_MMAP_MIN_ADDR 32768 ) | \ - ( value CONFIG_DEFAULT_MMAP_MIN_ADDR 65536) +( arch armel & value CONFIG_DEFAULT_MMAP_MIN_ADDR 32768 ) | ( value CONFIG_DEFAULT_MMAP_MIN_ADDR 65536) # CONFIG_USB_DEVICE_FS breaks udev USB firmware loading and is deprecated # ensure it is disabled. value CONFIG_USB_DEVICEFS n +# ARM requires some THUMB options +(arch armel & value CONFIG_ARM_THUMB y) +(arch armel & value CONFIG_ARM_THUMBEE y) + # upstart requires DEVTMPFS be enabled and mounted by default. value CONFIG_DEVTMPFS y value CONFIG_DEVTMPFS_MOUNT y @@ -41,7 +41,7 @@ value CONFIG_BLK_DEV_RAM_SIZE 65536 value CONFIG_BLK_DEV_DM y # sysfs: ensure all DEPRECATED items are off -value CONFIG_SYSFS_DEPRECATED_V2 n +!exists CONFIG_SYSFS_DEPRECATED_V2 | value CONFIG_SYSFS_DEPRECATED_V2 n !exists CONFIG_SYSFS_DEPRECATED | value CONFIG_SYSFS_DEPRECATED n # automatically add local version will cause packaging failure @@ -53,8 +53,20 @@ value CONFIG_FRAMEBUFFER_CONSOLE y # GRUB changes will rely on built in vesafb on x86, # UbuntuSpec:foundations-m-grub2-boot-framebuffer -(( arch i386 | arch amd64 ) & value CONFIG_FB_VESA y) | \ - value CONFIG_FB_VESA m | !exists CONFIG_FB_VESA +(( arch i386 | arch amd64 ) & value CONFIG_FB_VESA y) | value CONFIG_FB_VESA m | !exists CONFIG_FB_VESA # Build in uinput module so that it's always available (LP: 584812) value CONFIG_INPUT_UINPUT y + +#prevent some Android settings: +#value CONFIG_ANDROID_PARANOID_NETWORK n + +# force some convenient settings +value CONFIG_BLK_DEV_SD y +value CONFIG_KPROBES y +value CONFIG_OPROFILE y +value CONFIG_RELAY y +value CONFIG_SCSI y +value CONFIG_TUN y +value CONFIG_USB_VIDEO_CLASS m + |