mirror of
https://github.com/sheumann/hush.git
synced 2024-12-21 08:29:45 +00:00
d70e0e995e
Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
126 lines
2.5 KiB
Plaintext
126 lines
2.5 KiB
Plaintext
#
|
|
# For a description of the syntax of this configuration file,
|
|
# see scripts/kbuild/config-language.txt.
|
|
#
|
|
|
|
menu "SELinux Utilities"
|
|
depends on SELINUX
|
|
|
|
INSERT
|
|
|
|
config CHCON
|
|
bool "chcon"
|
|
default n
|
|
depends on SELINUX
|
|
help
|
|
Enable support to change the security context of file.
|
|
|
|
config FEATURE_CHCON_LONG_OPTIONS
|
|
bool "Enable long options"
|
|
default y
|
|
depends on CHCON && LONG_OPTS
|
|
help
|
|
Support long options for the chcon applet.
|
|
|
|
config GETENFORCE
|
|
bool "getenforce"
|
|
default n
|
|
depends on SELINUX
|
|
help
|
|
Enable support to get the current mode of SELinux.
|
|
|
|
config GETSEBOOL
|
|
bool "getsebool"
|
|
default n
|
|
depends on SELINUX
|
|
help
|
|
Enable support to get SELinux boolean values.
|
|
|
|
config LOAD_POLICY
|
|
bool "load_policy"
|
|
default n
|
|
depends on SELINUX
|
|
help
|
|
Enable support to load SELinux policy.
|
|
|
|
config MATCHPATHCON
|
|
bool "matchpathcon"
|
|
default n
|
|
depends on SELINUX
|
|
help
|
|
Enable support to get default security context of the
|
|
specified path from the file contexts configuration.
|
|
|
|
config RESTORECON
|
|
bool "restorecon"
|
|
default n
|
|
depends on SELINUX
|
|
help
|
|
Enable support to relabel files. The feature is almost
|
|
the same as setfiles, but usage is a little different.
|
|
|
|
config RUNCON
|
|
bool "runcon"
|
|
default n
|
|
depends on SELINUX
|
|
help
|
|
Enable support to run command in speficied security context.
|
|
|
|
config FEATURE_RUNCON_LONG_OPTIONS
|
|
bool "Enable long options"
|
|
default y
|
|
depends on RUNCON && LONG_OPTS
|
|
help
|
|
Support long options for the runcon applet.
|
|
|
|
config SELINUXENABLED
|
|
bool "selinuxenabled"
|
|
default n
|
|
depends on SELINUX
|
|
help
|
|
Enable support for this command to be used within shell scripts
|
|
to determine if selinux is enabled.
|
|
|
|
config SETENFORCE
|
|
bool "setenforce"
|
|
default n
|
|
depends on SELINUX
|
|
help
|
|
Enable support to modify the mode SELinux is running in.
|
|
|
|
config SETFILES
|
|
bool "setfiles"
|
|
default n
|
|
depends on SELINUX
|
|
help
|
|
Enable support to modify to relabel files.
|
|
Notice: If you built libselinux with -D_FILE_OFFSET_BITS=64,
|
|
(It is default in libselinux's Makefile), you _must_ enable
|
|
CONFIG_LFS.
|
|
|
|
config FEATURE_SETFILES_CHECK_OPTION
|
|
bool "Enable check option"
|
|
default n
|
|
depends on SETFILES
|
|
help
|
|
Support "-c" option (check the validity of the contexts against
|
|
the specified binary policy) for setfiles. Requires libsepol.
|
|
|
|
config SETSEBOOL
|
|
bool "setsebool"
|
|
default n
|
|
depends on SELINUX
|
|
help
|
|
Enable support for change boolean.
|
|
semanage and -P option is not supported yet.
|
|
|
|
config SESTATUS
|
|
bool "sestatus"
|
|
default n
|
|
depends on SELINUX
|
|
help
|
|
Displays the status of SELinux.
|
|
|
|
endmenu
|
|
|