# SPDX-License-Identifier: GPL-2.0-only config [31mCONFIG_SECURITY_APPARMOR[0m bool "AppArmor support" depends on [31mCONFIG_SECURITY[0m && [31mCONFIG_NET[0m select [31mCONFIG_AUDIT[0m select [31mCONFIG_SECURITY_PATH[0m select [31mCONFIG_SECURITYFS[0m select [31mCONFIG_SECURITY_NETWORK[0m default n help This enables the AppArmor security module. Required userspace tools (if they are not included in your distribution) and further information may be found at http://apparmor.wiki.kernel.org If you are unsure how to answer this question, answer N. config [31mCONFIG_SECURITY_APPARMOR_HASH[0m bool "Enable introspection of sha1 hashes for loaded profiles" depends on [31mCONFIG_SECURITY_APPARMOR[0m select [31mCONFIG_CRYPTO[0m select [31mCONFIG_CRYPTO_SHA1[0m default y help This option selects whether introspection of loaded policy is available to userspace via the apparmor filesystem. config [31mCONFIG_SECURITY_APPARMOR_HASH_DEFAULT[0m bool "Enable policy hash introspection by default" depends on [31mCONFIG_SECURITY_APPARMOR_HASH[0m default y help This option selects whether sha1 hashing of loaded policy is enabled by default. The generation of sha1 hashes for loaded policy provide system administrators a quick way to verify that policy in the kernel matches what is expected, however it can slow down policy load on some devices. In these cases policy hashing can be disabled by default and enabled only if needed. config [31mCONFIG_SECURITY_APPARMOR_DEBUG[0m bool "Build AppArmor with debug code" depends on [31mCONFIG_SECURITY_APPARMOR[0m default n help Build apparmor with debugging logic in apparmor. Not all debugging logic will necessarily be enabled. [31mCONFIG_A[0m submenu will provide fine grained control of the debug options that are available. config [31mCONFIG_SECURITY_APPARMOR_DEBUG_ASSERTS[0m bool "Build AppArmor with debugging asserts" depends on [31mCONFIG_SECURITY_APPARMOR_DEBUG[0m default y help Enable code assertions made with AA_BUG. These are primarily function entry preconditions but also exist at other key points. If the assert is triggered it will trigger a WARN message. config [31mCONFIG_SECURITY_APPARMOR_DEBUG_MESSAGES[0m bool "Debug messages enabled by default" depends on [31mCONFIG_SECURITY_APPARMOR_DEBUG[0m default n help Set the default value of the apparmor.debug kernel parameter. When enabled, various debug messages will be logged to the kernel message buffer. |