mirror of
https://github.com/openwrt/openwrt.git
synced 2024-12-23 15:32:33 +00:00
109 lines
2.7 KiB
Plaintext
109 lines
2.7 KiB
Plaintext
|
#
|
||
|
# For a description of the syntax of this configuration file,
|
||
|
# see scripts/kbuild/config-language.txt.
|
||
|
#
|
||
|
|
||
|
menu "Selinux Utilities"
|
||
|
depends on BUSYBOX_CONFIG_SELINUX
|
||
|
|
||
|
config BUSYBOX_CONFIG_CHCON
|
||
|
bool "chcon"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_SELINUX
|
||
|
help
|
||
|
Enable support to change the security context of file.
|
||
|
|
||
|
config BUSYBOX_CONFIG_FEATURE_CHCON_LONG_OPTIONS
|
||
|
bool "Enable long options"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_CHCON && BUSYBOX_CONFIG_GETOPT_LONG
|
||
|
help
|
||
|
Support long options for the chcon applet.
|
||
|
|
||
|
config BUSYBOX_CONFIG_GETENFORCE
|
||
|
bool "getenforce"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_SELINUX
|
||
|
help
|
||
|
Enable support to get the current mode of SELinux.
|
||
|
|
||
|
config BUSYBOX_CONFIG_GETSEBOOL
|
||
|
bool "getsebool"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_SELINUX
|
||
|
help
|
||
|
Enable support to get SELinux boolean values.
|
||
|
|
||
|
config BUSYBOX_CONFIG_LOAD_POLICY
|
||
|
bool "load_policy"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_SELINUX
|
||
|
help
|
||
|
Enable support to load SELinux policy.
|
||
|
|
||
|
config BUSYBOX_CONFIG_MATCHPATHCON
|
||
|
bool "matchpathcon"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_SELINUX
|
||
|
help
|
||
|
Enable support to get default security context of the
|
||
|
specified path from the file contexts configuration.
|
||
|
|
||
|
config BUSYBOX_CONFIG_RESTORECON
|
||
|
bool "restorecon"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_SELINUX
|
||
|
help
|
||
|
Enable support to relabel files. The feature is almost
|
||
|
the same as setfiles, but usage is a little different.
|
||
|
|
||
|
config BUSYBOX_CONFIG_RUNCON
|
||
|
bool "runcon"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_SELINUX
|
||
|
help
|
||
|
Enable support to run command in speficied security context.
|
||
|
|
||
|
config BUSYBOX_CONFIG_FEATURE_RUNCON_LONG_OPTIONS
|
||
|
bool "Enable long options"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_RUNCON && BUSYBOX_CONFIG_GETOPT_LONG
|
||
|
help
|
||
|
Support long options for the runcon applet.
|
||
|
|
||
|
config BUSYBOX_CONFIG_SELINUXENABLED
|
||
|
bool "selinuxenabled"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_SELINUX
|
||
|
help
|
||
|
Enable support for this command to be used within shell scripts
|
||
|
to determine if selinux is enabled.
|
||
|
|
||
|
config BUSYBOX_CONFIG_SETENFORCE
|
||
|
bool "setenforce"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_SELINUX
|
||
|
help
|
||
|
Enable support to modify the mode SELinux is running in.
|
||
|
|
||
|
config BUSYBOX_CONFIG_SETFILES
|
||
|
bool "setfiles"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_SELINUX
|
||
|
help
|
||
|
Enable support to modify to relabel files.
|
||
|
Notice: If you built libselinux with -D_FILE_OFFSET_BITS=64,
|
||
|
(It is default in libselinux's Makefile), you _must_ enable
|
||
|
CONFIG_LFS.
|
||
|
|
||
|
config BUSYBOX_CONFIG_FEATURE_SETFILES_CHECK_OPTION
|
||
|
bool "Enable check option"
|
||
|
default n
|
||
|
depends on BUSYBOX_CONFIG_SETFILES
|
||
|
help
|
||
|
Support "-c" option (check the validity of the contexts against
|
||
|
the specified binary policy) for setfiles. Requires libsepol.
|
||
|
|
||
|
endmenu
|
||
|
|