UBUNTU: [Config] SECCOMP_FILTER=y
authorKees Cook <kees@ubuntu.com>
Wed, 21 Mar 2012 15:40:39 +0000 (08:40 -0700)
committerLeann Ogasawara <leann.ogasawara@canonical.com>
Mon, 2 Apr 2012 20:23:10 +0000 (13:23 -0700)
Enable SECCOMP_FILTER for x86 builds, update enforce check.

Signed-off-by: Kees Cook <kees@ubuntu.com>

debian.master/config/config.common.ubuntu
debian.master/config/enforce

index 6c44d65..0e37af7 100644 (file)
@@ -1879,6 +1879,7 @@ CONFIG_HAVE_ARCH_JUMP_LABEL=y
 CONFIG_HAVE_ARCH_KGDB=y
 CONFIG_HAVE_ARCH_KMEMCHECK=y
 CONFIG_HAVE_ARCH_PFN_VALID=y
+CONFIG_HAVE_ARCH_SECCOMP_FILTER=y
 CONFIG_HAVE_ARCH_TRACEHOOK=y
 CONFIG_HAVE_ATOMIC_IOMAP=y
 CONFIG_HAVE_BPF_JIT=y
@@ -4580,6 +4581,7 @@ CONFIG_SDIO_UART=m
 CONFIG_SDLA=m
 CONFIG_SEALEVEL_4021=m
 CONFIG_SECCOMP=y
+CONFIG_SECCOMP_FILTER=y
 CONFIG_SECURITY=y
 CONFIG_SECURITYFS=y
 CONFIG_SECURITY_APPARMOR=y
index f728597..4da41d5 100644 (file)
@@ -14,7 +14,7 @@ value CONFIG_SYN_COOKIES y
 value CONFIG_DEFAULT_SECURITY_APPARMOR y
 # For architectures which support this option ensure it is enabled.
 !exists CONFIG_SECCOMP | value CONFIG_SECCOMP y
-!exists CONFIG_HAVE_SECCOMP_FILTER | value CONFIG_SECCOMP_FILTER y
+!exists CONFIG_HAVE_ARCH_SECCOMP_FILTER | value CONFIG_SECCOMP_FILTER y
 !exists CONFIG_CC_STACKPROTECTOR | value CONFIG_CC_STACKPROTECTOR y
 !exists CONFIG_DEBUG_RODATA | value CONFIG_DEBUG_RODATA y
 !exists CONFIG_DEBUG_SET_MODULE_RONX | value CONFIG_DEBUG_SET_MODULE_RONX y