aboutsummaryrefslogtreecommitdiffstats
path: root/main
diff options
context:
space:
mode:
authorWilliam Pitcock <nenolod@dereferenced.org>2017-01-31 20:05:52 +0000
committerWilliam Pitcock <nenolod@dereferenced.org>2017-01-31 20:06:23 +0000
commit0debb05afca7e8933a8cf9b69929be86a92f5c22 (patch)
tree9a3d59ca41761e57e917f577c5b1bb0b533a80d6 /main
parentbfe221d6540bb18bfd95a2d0d5f7726853d0561a (diff)
downloadaports-0debb05afca7e8933a8cf9b69929be86a92f5c22.tar.bz2
aports-0debb05afca7e8933a8cf9b69929be86a92f5c22.tar.xz
main/linux-vanilla: enable Yama (provides some protections like grsecurity)
Diffstat (limited to 'main')
-rw-r--r--main/linux-vanilla/APKBUILD38
-rw-r--r--main/linux-vanilla/config-vanilla.aarch6413
-rw-r--r--main/linux-vanilla/config-vanilla.armhf13
-rw-r--r--main/linux-vanilla/config-vanilla.ppc12
-rw-r--r--main/linux-vanilla/config-vanilla.ppc64le11
-rw-r--r--main/linux-vanilla/config-vanilla.x8613
-rw-r--r--main/linux-vanilla/config-vanilla.x86_6415
7 files changed, 87 insertions, 28 deletions
diff --git a/main/linux-vanilla/APKBUILD b/main/linux-vanilla/APKBUILD
index 01f2589dec..23311aa6a2 100644
--- a/main/linux-vanilla/APKBUILD
+++ b/main/linux-vanilla/APKBUILD
@@ -7,7 +7,7 @@ case $pkgver in
*.*.*) _kernver=${pkgver%.*};;
*.*) _kernver=$pkgver;;
esac
-pkgrel=0
+pkgrel=1
pkgdesc="Linux vanilla kernel"
url="http://kernel.org"
depends="mkinitfs linux-firmware"
@@ -165,29 +165,29 @@ dev() {
}
md5sums="9a78fa2eb6c68ca5a40ed5af08142599 linux-4.4.tar.xz
-fb219ff405db2d34ab1f7d052d2d2fbb config-vanilla.aarch64
-ec4bd577f32f24143def18f66c59bb18 config-vanilla.armhf
-4497f7a7891e82cb145b0b9e9be48e99 config-vanilla.x86
-73e220a5f6d5975a7c577524e53613f0 config-vanilla.x86_64
-91b766efc7d356eacd4895cc328b7fe1 config-vanilla.ppc
-e9a904a8419976b6f4a87e32ef003fdd config-vanilla.ppc64le
+60722f3f87ee4b7e74ee6999ae810f51 config-vanilla.aarch64
+bc89928ff4a687c11d3bcc3f79d44132 config-vanilla.armhf
+32be41a1abad4eefdf491907b257737f config-vanilla.x86
+080b647a731c6013d150a370b745f158 config-vanilla.x86_64
+71cb405e6342cd1e07d5819d4b300f7d config-vanilla.ppc
+3eaa6ab780e1194cabf811d3e894ef30 config-vanilla.ppc64le
e10e580b7aadf42ba595e35d3ff3fc69 0001-Add-dts-for-GIGABYTE-X-Gene-MP30-AR0.patch
8c83b4bc6b233bd87d8f75e92086583d patch-4.4.45.xz"
sha256sums="401d7c8fef594999a460d10c72c5a94e9c2e1022f16795ec51746b0d165418b2 linux-4.4.tar.xz
-4bcde0ce497ef057006dd98915aab5797eab0a84598aad03260e3a3f4413f572 config-vanilla.aarch64
-223d31ce209e61a299ac314340cb82ebbe1c18167a09dedff317f0c4bee2d6a9 config-vanilla.armhf
-005a169fbe77e9e0e35bb9783d6f526dc43335846c2cf97c94e68a20c6e76bca config-vanilla.x86
-0dff4ba5f486ecb573ffaa2088e323d6a494d096ebda3b58db7ab954038c0e4f config-vanilla.x86_64
-a8e465d96c743621273f77eddefa476b21947194bc174290671e2a8165557e61 config-vanilla.ppc
-178c467d8a0fb85491fc4fc966375a712398e753ebd8b020d05368049a8a35e6 config-vanilla.ppc64le
+2bde88a9393d93b3bff368706aeb467b8fa8e1459877c3ba9db7f90cba96e824 config-vanilla.aarch64
+83cfbe20ba8c5d8b9a540c6bd55a26c31fe6928abf08881131901a47152dd2aa config-vanilla.armhf
+16c33fa4b2f41f76c42610c46271ab9ab09618cc70720b5bc33ed9e1611122c8 config-vanilla.x86
+530a9bfbfae90e103de41bf77e5897eda50687dcef286b2465d3f90b74151208 config-vanilla.x86_64
+9a3a0019de416dad7c487ba7c022609baf4fd65599c73a0ea370ff12f8f5df8d config-vanilla.ppc
+be575bd67f224df227319a511814a1cbd2db9c7cc8f80532ec844d786527652d config-vanilla.ppc64le
b9bcbe11c017764075179fb61fb13f6d0eca2c5495402d8f4ace2331cfe0c0b4 0001-Add-dts-for-GIGABYTE-X-Gene-MP30-AR0.patch
8d359628e1b6918308998510f6f5724b7f5f27016bcaee3760f4ad1f4a8a93fb patch-4.4.45.xz"
sha512sums="13c8459933a8b80608e226a1398e3d1848352ace84bcfb7e6a4a33cb230bbe1ab719d4b58e067283df91ce5311be6d2d595fc8c19e2ae6ecc652499415614b3e linux-4.4.tar.xz
-897b4b7d4dc2b5a72f4497283d5b90336e6097e79872325255296c01498389c883f1a266f8732833ab492936fbdb1d32606b0c8e67136c7b90268352b56e8cad config-vanilla.aarch64
-2e8711861f7765cb35f70b905dc40189b1436afca11b35b3000a426d4c1afed2d9028ef71589e37340ed0c0e5e12abe45375d122712dec47d2edc0df7ea73faf config-vanilla.armhf
-74f1fe3bb14800688fca27c5dd7943d357af4f1f9703b04553d7479fcf6aabd0304a2df4b6f7fff65d6c7fecf86dae3199814d6516d30b7688b6f5f78b354070 config-vanilla.x86
-bcf576c45626236928d987feaab3a3be0852a7cc33ede71f4148548a1146955df56bef82816f3285c2d4b1a44d26f99e35adb5bbeada0cf5d7a3db5b1939e804 config-vanilla.x86_64
-8e28e997eb8847b395f2f3accf675c7fd6ba0c3dda71c7caf9d5429ca1be227ce417ff04b7696cde01ce24e8c5cc26d4ae879feaf514d2f63b3eb7702698efed config-vanilla.ppc
-59474c6a5d96abb081430d88aec500f1e4d0ddf6ae006d06c1db069c680c509306ded0234a27ce07d8fcfd32481e6dd7402f4e6fc198833c0ed65b3887559683 config-vanilla.ppc64le
+5fb62b82d23566fe0d0ce6cfff258a4a044ce0d968d81ccd10da6073dc7c30ad21e18b3be14fe36635a7e46793c5ce4c6184847917706fec733c584a2c14ac54 config-vanilla.aarch64
+0ed4e87ef8ff5f38ed36bfe19faa7c4b0c45c6abb55e943fa1dd18798028bd545527c7b6e04e3c3ae89160e9567975cec9f9c5fb50c5f73b39cf347005cf4650 config-vanilla.armhf
+191307370b90fdbefd8182fe7bb5f2e2e21db74efeb560672cc4088b51bf9542ec4ca7d7556a14e34219183bdb36ebb9fa324dddda4ad5cc3cca347d073ecdb7 config-vanilla.x86
+b3146ef4a16aa3caf79cc3bef57144a718afc644718eaecd02e72c028a8831efc5cbd87afe1bd3056a4f8788abd8ddffc15265b848146b198719015fb93e649d config-vanilla.x86_64
+ee565e219530bcfaf5cade2622432cfb83743bdbbfc388781901461f19ca553b7fdee3c81ce6b34225ef78a209eb60088630284fcbb0430947aad77a5d8a0865 config-vanilla.ppc
+47699009e208e8dec52a3fd77471f85a24d0c30a663a56e17c3063113e3c3dd32e46e17fd99b4f4b6e1e6202ce48747c60700c0c9ae097a46167bdacfa3e330b config-vanilla.ppc64le
ebc1b89ff0985246889f68c32fb0bd326eb0f015a97b913bf8e2b92855c75809d114c57aff8f3f74d120694f1c5891d7a11ebe4aadaadd1954a947e762bf121d 0001-Add-dts-for-GIGABYTE-X-Gene-MP30-AR0.patch
37c8fb23b9456e67f515ac3baf03a5eecd1fcbf534d222564579ba47db19c2ccff92275fc977279c49d1e8df3c7e51e64552446f1789cd08c7d994b8367bfe2b patch-4.4.45.xz"
diff --git a/main/linux-vanilla/config-vanilla.aarch64 b/main/linux-vanilla/config-vanilla.aarch64
index b4f8338ca3..1b40f47be8 100644
--- a/main/linux-vanilla/config-vanilla.aarch64
+++ b/main/linux-vanilla/config-vanilla.aarch64
@@ -668,6 +668,7 @@ CONFIG_IPV6_SUBTREES=y
CONFIG_IPV6_MROUTE=y
CONFIG_IPV6_MROUTE_MULTIPLE_TABLES=y
CONFIG_IPV6_PIMSM_V2=y
+# CONFIG_NETLABEL is not set
CONFIG_NETWORK_SECMARK=y
CONFIG_NET_PTP_CLASSIFY=y
CONFIG_NETWORK_PHY_TIMESTAMPING=y
@@ -931,6 +932,7 @@ CONFIG_IP_NF_TARGET_CLUSTERIP=m
CONFIG_IP_NF_TARGET_ECN=m
CONFIG_IP_NF_TARGET_TTL=m
CONFIG_IP_NF_RAW=m
+# CONFIG_IP_NF_SECURITY is not set
CONFIG_IP_NF_ARPTABLES=m
CONFIG_IP_NF_ARPFILTER=m
CONFIG_IP_NF_ARP_MANGLE=m
@@ -968,6 +970,7 @@ CONFIG_IP6_NF_TARGET_REJECT=m
CONFIG_IP6_NF_TARGET_SYNPROXY=m
CONFIG_IP6_NF_MANGLE=m
CONFIG_IP6_NF_RAW=m
+# CONFIG_IP6_NF_SECURITY is not set
CONFIG_IP6_NF_NAT=m
CONFIG_IP6_NF_TARGET_MASQUERADE=m
CONFIG_IP6_NF_TARGET_NPT=m
@@ -5883,6 +5886,7 @@ CONFIG_NFSD_V3=y
# CONFIG_NFSD_V3_ACL is not set
CONFIG_NFSD_V4=y
CONFIG_NFSD_PNFS=y
+# CONFIG_NFSD_V4_SECURITY_LABEL is not set
# CONFIG_NFSD_FAULT_INJECTION is not set
CONFIG_GRACE_PERIOD=m
CONFIG_LOCKD=m
@@ -6170,8 +6174,15 @@ CONFIG_KEYS=y
CONFIG_TRUSTED_KEYS=m
CONFIG_ENCRYPTED_KEYS=m
# CONFIG_SECURITY_DMESG_RESTRICT is not set
-# CONFIG_SECURITY is not set
+CONFIG_SECURITY=y
CONFIG_SECURITYFS=y
+# CONFIG_SECURITY_NETWORK is not set
+# CONFIG_SECURITY_PATH is not set
+# CONFIG_SECURITY_SMACK is not set
+# CONFIG_SECURITY_TOMOYO is not set
+# CONFIG_SECURITY_APPARMOR is not set
+CONFIG_SECURITY_YAMA=y
+# CONFIG_INTEGRITY is not set
CONFIG_DEFAULT_SECURITY_DAC=y
CONFIG_DEFAULT_SECURITY=""
CONFIG_XOR_BLOCKS=m
diff --git a/main/linux-vanilla/config-vanilla.armhf b/main/linux-vanilla/config-vanilla.armhf
index d357a519e8..d56f0c1448 100644
--- a/main/linux-vanilla/config-vanilla.armhf
+++ b/main/linux-vanilla/config-vanilla.armhf
@@ -793,6 +793,7 @@ CONFIG_IPV6_SUBTREES=y
CONFIG_IPV6_MROUTE=y
CONFIG_IPV6_MROUTE_MULTIPLE_TABLES=y
CONFIG_IPV6_PIMSM_V2=y
+# CONFIG_NETLABEL is not set
CONFIG_NETWORK_SECMARK=y
CONFIG_NET_PTP_CLASSIFY=y
CONFIG_NETWORK_PHY_TIMESTAMPING=y
@@ -1055,6 +1056,7 @@ CONFIG_IP_NF_TARGET_CLUSTERIP=m
CONFIG_IP_NF_TARGET_ECN=m
CONFIG_IP_NF_TARGET_TTL=m
CONFIG_IP_NF_RAW=m
+# CONFIG_IP_NF_SECURITY is not set
CONFIG_IP_NF_ARPTABLES=m
CONFIG_IP_NF_ARPFILTER=m
CONFIG_IP_NF_ARP_MANGLE=m
@@ -1092,6 +1094,7 @@ CONFIG_IP6_NF_TARGET_REJECT=m
# CONFIG_IP6_NF_TARGET_SYNPROXY is not set
CONFIG_IP6_NF_MANGLE=m
CONFIG_IP6_NF_RAW=m
+# CONFIG_IP6_NF_SECURITY is not set
CONFIG_IP6_NF_NAT=m
CONFIG_IP6_NF_TARGET_MASQUERADE=m
CONFIG_IP6_NF_TARGET_NPT=m
@@ -4900,6 +4903,7 @@ CONFIG_NFSD_V3=y
# CONFIG_NFSD_V3_ACL is not set
CONFIG_NFSD_V4=y
CONFIG_NFSD_PNFS=y
+# CONFIG_NFSD_V4_SECURITY_LABEL is not set
# CONFIG_NFSD_FAULT_INJECTION is not set
CONFIG_GRACE_PERIOD=m
CONFIG_LOCKD=m
@@ -5180,8 +5184,15 @@ CONFIG_KEYS=y
CONFIG_TRUSTED_KEYS=m
CONFIG_ENCRYPTED_KEYS=m
# CONFIG_SECURITY_DMESG_RESTRICT is not set
-# CONFIG_SECURITY is not set
+CONFIG_SECURITY=y
CONFIG_SECURITYFS=y
+# CONFIG_SECURITY_NETWORK is not set
+# CONFIG_SECURITY_PATH is not set
+# CONFIG_SECURITY_SMACK is not set
+# CONFIG_SECURITY_TOMOYO is not set
+# CONFIG_SECURITY_APPARMOR is not set
+CONFIG_SECURITY_YAMA=y
+# CONFIG_INTEGRITY is not set
CONFIG_DEFAULT_SECURITY_DAC=y
CONFIG_DEFAULT_SECURITY=""
CONFIG_XOR_BLOCKS=m
diff --git a/main/linux-vanilla/config-vanilla.ppc b/main/linux-vanilla/config-vanilla.ppc
index 78f9d2e290..172a8c1665 100644
--- a/main/linux-vanilla/config-vanilla.ppc
+++ b/main/linux-vanilla/config-vanilla.ppc
@@ -688,6 +688,7 @@ CONFIG_IP_NF_MANGLE=m
CONFIG_IP_NF_TARGET_ECN=m
CONFIG_IP_NF_TARGET_TTL=m
CONFIG_IP_NF_RAW=m
+# CONFIG_IP_NF_SECURITY is not set
CONFIG_IP_NF_ARPTABLES=m
CONFIG_IP_NF_ARPFILTER=m
CONFIG_IP_NF_ARP_MANGLE=m
@@ -3229,8 +3230,15 @@ CONFIG_KEYS=y
# CONFIG_BIG_KEYS is not set
# CONFIG_ENCRYPTED_KEYS is not set
# CONFIG_SECURITY_DMESG_RESTRICT is not set
-# CONFIG_SECURITY is not set
-# CONFIG_SECURITYFS is not set
+CONFIG_SECURITY=y
+CONFIG_SECURITYFS=y
+# CONFIG_SECURITY_NETWORK is not set
+# CONFIG_SECURITY_PATH is not set
+# CONFIG_SECURITY_SMACK is not set
+# CONFIG_SECURITY_TOMOYO is not set
+# CONFIG_SECURITY_APPARMOR is not set
+CONFIG_SECURITY_YAMA=y
+# CONFIG_INTEGRITY is not set
CONFIG_DEFAULT_SECURITY_DAC=y
CONFIG_DEFAULT_SECURITY=""
CONFIG_CRYPTO=y
diff --git a/main/linux-vanilla/config-vanilla.ppc64le b/main/linux-vanilla/config-vanilla.ppc64le
index 57a1f61264..b296863613 100644
--- a/main/linux-vanilla/config-vanilla.ppc64le
+++ b/main/linux-vanilla/config-vanilla.ppc64le
@@ -3087,8 +3087,15 @@ CONFIG_KEYS=y
# CONFIG_BIG_KEYS is not set
# CONFIG_ENCRYPTED_KEYS is not set
# CONFIG_SECURITY_DMESG_RESTRICT is not set
-# CONFIG_SECURITY is not set
-# CONFIG_SECURITYFS is not set
+CONFIG_SECURITY=y
+CONFIG_SECURITYFS=y
+# CONFIG_SECURITY_NETWORK is not set
+# CONFIG_SECURITY_PATH is not set
+# CONFIG_SECURITY_SMACK is not set
+# CONFIG_SECURITY_TOMOYO is not set
+# CONFIG_SECURITY_APPARMOR is not set
+CONFIG_SECURITY_YAMA=y
+# CONFIG_INTEGRITY is not set
CONFIG_DEFAULT_SECURITY_DAC=y
CONFIG_DEFAULT_SECURITY=""
CONFIG_KEYS_COMPAT=y
diff --git a/main/linux-vanilla/config-vanilla.x86 b/main/linux-vanilla/config-vanilla.x86
index 8d33725459..e321089a67 100644
--- a/main/linux-vanilla/config-vanilla.x86
+++ b/main/linux-vanilla/config-vanilla.x86
@@ -832,6 +832,7 @@ CONFIG_IPV6_SUBTREES=y
CONFIG_IPV6_MROUTE=y
CONFIG_IPV6_MROUTE_MULTIPLE_TABLES=y
CONFIG_IPV6_PIMSM_V2=y
+# CONFIG_NETLABEL is not set
CONFIG_NETWORK_SECMARK=y
CONFIG_NET_PTP_CLASSIFY=y
CONFIG_NETWORK_PHY_TIMESTAMPING=y
@@ -1095,6 +1096,7 @@ CONFIG_IP_NF_TARGET_CLUSTERIP=m
CONFIG_IP_NF_TARGET_ECN=m
CONFIG_IP_NF_TARGET_TTL=m
CONFIG_IP_NF_RAW=m
+# CONFIG_IP_NF_SECURITY is not set
CONFIG_IP_NF_ARPTABLES=m
CONFIG_IP_NF_ARPFILTER=m
CONFIG_IP_NF_ARP_MANGLE=m
@@ -1132,6 +1134,7 @@ CONFIG_IP6_NF_TARGET_REJECT=m
CONFIG_IP6_NF_TARGET_SYNPROXY=m
CONFIG_IP6_NF_MANGLE=m
CONFIG_IP6_NF_RAW=m
+# CONFIG_IP6_NF_SECURITY is not set
CONFIG_IP6_NF_NAT=m
CONFIG_IP6_NF_TARGET_MASQUERADE=m
CONFIG_IP6_NF_TARGET_NPT=m
@@ -6007,6 +6010,7 @@ CONFIG_NFSD_V3=y
# CONFIG_NFSD_V3_ACL is not set
CONFIG_NFSD_V4=y
CONFIG_NFSD_PNFS=y
+# CONFIG_NFSD_V4_SECURITY_LABEL is not set
# CONFIG_NFSD_FAULT_INJECTION is not set
CONFIG_GRACE_PERIOD=m
CONFIG_LOCKD=m
@@ -6327,9 +6331,16 @@ CONFIG_KEYS=y
CONFIG_TRUSTED_KEYS=m
CONFIG_ENCRYPTED_KEYS=m
# CONFIG_SECURITY_DMESG_RESTRICT is not set
-# CONFIG_SECURITY is not set
+CONFIG_SECURITY=y
CONFIG_SECURITYFS=y
+# CONFIG_SECURITY_NETWORK is not set
+# CONFIG_SECURITY_PATH is not set
# CONFIG_INTEL_TXT is not set
+# CONFIG_SECURITY_SMACK is not set
+# CONFIG_SECURITY_TOMOYO is not set
+# CONFIG_SECURITY_APPARMOR is not set
+CONFIG_SECURITY_YAMA=y
+# CONFIG_INTEGRITY is not set
CONFIG_DEFAULT_SECURITY_DAC=y
CONFIG_DEFAULT_SECURITY=""
CONFIG_XOR_BLOCKS=m
diff --git a/main/linux-vanilla/config-vanilla.x86_64 b/main/linux-vanilla/config-vanilla.x86_64
index ebe36c88ca..53ea0ccec0 100644
--- a/main/linux-vanilla/config-vanilla.x86_64
+++ b/main/linux-vanilla/config-vanilla.x86_64
@@ -1,6 +1,6 @@
#
# Automatically generated file; DO NOT EDIT.
-# Linux/x86 4.4.34 Kernel Configuration
+# Linux/x86_64 4.4.45 Kernel Configuration
#
CONFIG_64BIT=y
CONFIG_X86_64=y
@@ -834,6 +834,7 @@ CONFIG_IPV6_SUBTREES=y
CONFIG_IPV6_MROUTE=y
CONFIG_IPV6_MROUTE_MULTIPLE_TABLES=y
CONFIG_IPV6_PIMSM_V2=y
+# CONFIG_NETLABEL is not set
CONFIG_NETWORK_SECMARK=y
CONFIG_NET_PTP_CLASSIFY=y
CONFIG_NETWORK_PHY_TIMESTAMPING=y
@@ -1097,6 +1098,7 @@ CONFIG_IP_NF_TARGET_CLUSTERIP=m
CONFIG_IP_NF_TARGET_ECN=m
CONFIG_IP_NF_TARGET_TTL=m
CONFIG_IP_NF_RAW=m
+# CONFIG_IP_NF_SECURITY is not set
CONFIG_IP_NF_ARPTABLES=m
CONFIG_IP_NF_ARPFILTER=m
CONFIG_IP_NF_ARP_MANGLE=m
@@ -1134,6 +1136,7 @@ CONFIG_IP6_NF_TARGET_REJECT=m
CONFIG_IP6_NF_TARGET_SYNPROXY=m
CONFIG_IP6_NF_MANGLE=m
CONFIG_IP6_NF_RAW=m
+# CONFIG_IP6_NF_SECURITY is not set
CONFIG_IP6_NF_NAT=m
CONFIG_IP6_NF_TARGET_MASQUERADE=m
CONFIG_IP6_NF_TARGET_NPT=m
@@ -6026,6 +6029,7 @@ CONFIG_NFSD_V3=y
# CONFIG_NFSD_V3_ACL is not set
CONFIG_NFSD_V4=y
CONFIG_NFSD_PNFS=y
+# CONFIG_NFSD_V4_SECURITY_LABEL is not set
# CONFIG_NFSD_FAULT_INJECTION is not set
CONFIG_GRACE_PERIOD=m
CONFIG_LOCKD=m
@@ -6349,9 +6353,16 @@ CONFIG_KEYS=y
CONFIG_TRUSTED_KEYS=m
CONFIG_ENCRYPTED_KEYS=m
# CONFIG_SECURITY_DMESG_RESTRICT is not set
-# CONFIG_SECURITY is not set
+CONFIG_SECURITY=y
CONFIG_SECURITYFS=y
+# CONFIG_SECURITY_NETWORK is not set
+# CONFIG_SECURITY_PATH is not set
# CONFIG_INTEL_TXT is not set
+# CONFIG_SECURITY_SMACK is not set
+# CONFIG_SECURITY_TOMOYO is not set
+# CONFIG_SECURITY_APPARMOR is not set
+CONFIG_SECURITY_YAMA=y
+# CONFIG_INTEGRITY is not set
CONFIG_DEFAULT_SECURITY_DAC=y
CONFIG_DEFAULT_SECURITY=""
CONFIG_XOR_BLOCKS=m