blob: 41c60bd7e424330b455292ad0829ab0f27b07eb2 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
|
#
# For a description of the syntax of this configuration file,
# see scripts/kbuild/config-language.txt.
#
menu "SELinux Utilities"
depends on BUSYBOX_SELINUX
config BUSYBOX_CHCON
bool "chcon"
default n
depends on BUSYBOX_SELINUX
help
Enable support to change the security context of file.
config BUSYBOX_FEATURE_CHCON_LONG_OPTIONS
bool "Enable long options"
default y
depends on BUSYBOX_CHCON && BUSYBOX_LONG_OPTS
help
Support long options for the chcon applet.
config BUSYBOX_GETENFORCE
bool "getenforce"
default n
depends on BUSYBOX_SELINUX
help
Enable support to get the current mode of SELinux.
config BUSYBOX_GETSEBOOL
bool "getsebool"
default n
depends on BUSYBOX_SELINUX
help
Enable support to get SELinux boolean values.
config BUSYBOX_LOAD_POLICY
bool "load_policy"
default n
depends on BUSYBOX_SELINUX
help
Enable support to load SELinux policy.
config BUSYBOX_MATCHPATHCON
bool "matchpathcon"
default n
depends on BUSYBOX_SELINUX
help
Enable support to get default security context of the
specified path from the file contexts configuration.
config BUSYBOX_RESTORECON
bool "restorecon"
default n
depends on BUSYBOX_SELINUX
help
Enable support to relabel files. The feature is almost
the same as setfiles, but usage is a little different.
config BUSYBOX_RUNCON
bool "runcon"
default n
depends on BUSYBOX_SELINUX
help
Enable support to run command in speficied security context.
config BUSYBOX_FEATURE_RUNCON_LONG_OPTIONS
bool "Enable long options"
default y
depends on BUSYBOX_RUNCON && BUSYBOX_LONG_OPTS
help
Support long options for the runcon applet.
config BUSYBOX_SELINUXENABLED
bool "selinuxenabled"
default n
depends on BUSYBOX_SELINUX
help
Enable support for this command to be used within shell scripts
to determine if selinux is enabled.
config BUSYBOX_SETENFORCE
bool "setenforce"
default n
depends on BUSYBOX_SELINUX
help
Enable support to modify the mode SELinux is running in.
config BUSYBOX_SETFILES
bool "setfiles"
default n
depends on BUSYBOX_SELINUX
help
Enable support to modify to relabel files.
Notice: If you built libselinux with -D_FILE_OFFSET_BITS=64,
(It is default in libselinux's Makefile), you _must_ enable
CONFIG_LFS.
config BUSYBOX_FEATURE_SETFILES_CHECK_OPTION
bool "Enable check option"
default n
depends on BUSYBOX_SETFILES
help
Support "-c" option (check the validity of the contexts against
the specified binary policy) for setfiles. Requires libsepol.
config BUSYBOX_SETSEBOOL
bool "setsebool"
default n
depends on BUSYBOX_SELINUX
help
Enable support for change boolean.
semanage and -P option is not supported yet.
config BUSYBOX_SESTATUS
bool "sestatus"
default n
depends on BUSYBOX_SELINUX
help
Displays the status of SELinux.
endmenu
|