Files
Centos-kernel-stream-10/security/Makefile
T
Ondrej Mosnacek 7aa3fb5951 lsm: split the init code out into lsm_init.c
JIRA: https://issues.redhat.com/browse/RHEL-179440
CVE: CVE-2026-46054
Conflicts:
  - security/security.c:
    - conflict due to 5816bf4273ed ("lsm,selinux: Add LSM blob support
      for BPF objects"), which is not backported
    - need to also carry over bits from RHEL-only commit 1e3e3bce93
      ("CVE-2025-1272: security: Re-enable lockdown LSM in some
      setup_arch()")

commit 67a4b6a89b99aff0883114e4ecba4b11aedc29a5
Author: Paul Moore <paul@paul-moore.com>
Date:   Thu Feb 6 16:44:10 2025 -0500

    lsm: split the init code out into lsm_init.c

    Continue to pull code out of security/security.c to help improve
    readability by pulling all of the LSM framework initialization
    code out into a new file.

    No code changes.

    Reviewed-by: Kees Cook <kees@kernel.org>
    Reviewed-by: John Johansen <john.johansen@canonical.com>
    Reviewed-by: Casey Schaufler <casey@schaufler-ca.com>
    Reviewed-by: Mimi Zohar <zohar@linux.ibm.com>
    Signed-off-by: Paul Moore <paul@paul-moore.com>

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
2026-06-02 20:13:57 +02:00

32 lines
998 B
Makefile

# SPDX-License-Identifier: GPL-2.0
#
# Makefile for the kernel security code
#
obj-$(CONFIG_KEYS) += keys/
# always enable default capabilities
obj-y += commoncap.o
obj-$(CONFIG_SECURITY) += lsm_syscalls.o
obj-$(CONFIG_MMU) += min_addr.o
# Object file lists
obj-$(CONFIG_SECURITY) += security.o lsm_notifier.o lsm_init.o
obj-$(CONFIG_SECURITYFS) += inode.o
obj-$(CONFIG_SECURITY_SELINUX) += selinux/
obj-$(CONFIG_SECURITY_SMACK) += smack/
obj-$(CONFIG_SECURITY) += lsm_audit.o
obj-$(CONFIG_SECURITY_TOMOYO) += tomoyo/
obj-$(CONFIG_SECURITY_APPARMOR) += apparmor/
obj-$(CONFIG_SECURITY_YAMA) += yama/
obj-$(CONFIG_SECURITY_LOADPIN) += loadpin/
obj-$(CONFIG_SECURITY_SAFESETID) += safesetid/
obj-$(CONFIG_SECURITY_LOCKDOWN_LSM) += lockdown/
obj-$(CONFIG_CGROUPS) += device_cgroup.o
obj-$(CONFIG_BPF_LSM) += bpf/
obj-$(CONFIG_SECURITY_LANDLOCK) += landlock/
obj-$(CONFIG_SECURITY_IPE) += ipe/
# Object integrity file lists
obj-$(CONFIG_INTEGRITY) += integrity/