From dc38e853b5e5a2ec05ce084361c1ab003a18fac0 Mon Sep 17 00:00:00 2001 From: Bruce Leidl Date: Sat, 6 Apr 2019 16:14:23 -0400 Subject: [PATCH] removed grsec sysctl --- .../citadel-initramfs/citadel-initramfs.bb | 4 ---- .../recipes-initrd/citadel-initramfs/files/99-grsec.conf | 9 --------- 2 files changed, 13 deletions(-) delete mode 100644 meta-citadel/recipes-initrd/citadel-initramfs/files/99-grsec.conf diff --git a/meta-citadel/recipes-initrd/citadel-initramfs/citadel-initramfs.bb b/meta-citadel/recipes-initrd/citadel-initramfs/citadel-initramfs.bb index 3788467..201a2a5 100644 --- a/meta-citadel/recipes-initrd/citadel-initramfs/citadel-initramfs.bb +++ b/meta-citadel/recipes-initrd/citadel-initramfs/citadel-initramfs.bb @@ -13,7 +13,6 @@ SRC_URI = "\ file://citadel-rootfs-mount.service \ file://citadel-rootfs-setup.service \ file://citadel-install-rootfs-mount.service \ - file://99-grsec.conf \ " S = "${WORKDIR}" @@ -38,9 +37,6 @@ do_install() { ln -s ../citadel-rootfs-setup.service ${D}${systemd_system_unitdir}/sysinit.target.wants/citadel-rootfs-setup.service ln -s ../citadel-install-rootfs-mount.service ${D}${systemd_system_unitdir}/sysinit.target.wants/citadel-install-rootfs-mount.service - install -d ${D}${libdir}/sysctl.d/ - install -m 0644 ${WORKDIR}/99-grsec.conf ${D}${libdir}/sysctl.d/ - install -d ${D}${sysconfdir} install -m 644 ${WORKDIR}/initrd-release ${D}${sysconfdir} install -m 644 ${WORKDIR}/crypttab ${D}${sysconfdir} diff --git a/meta-citadel/recipes-initrd/citadel-initramfs/files/99-grsec.conf b/meta-citadel/recipes-initrd/citadel-initramfs/files/99-grsec.conf deleted file mode 100644 index 8d5131e..0000000 --- a/meta-citadel/recipes-initrd/citadel-initramfs/files/99-grsec.conf +++ /dev/null @@ -1,9 +0,0 @@ - -# disable some pax and grsecurity features so that debootstrap will work -# this should be removed later - -kernel.grsecurity.chroot_caps = 0 -kernel.grsecurity.chroot_deny_chmod = 0 -kernel.grsecurity.chroot_deny_mknod = 0 -kernel.grsecurity.chroot_deny_mount = 0 -kernel.pax.softmode = 1