summaryrefslogtreecommitdiffstats
path: root/security/Makefile
diff options
context:
space:
mode:
authorLinus Torvalds <torvalds@linux-foundation.org>2026-09-25 15:55:03 -0700
committerLinus Torvalds <torvalds@linux-foundation.org>2026-09-25 15:55:03 -0700
commit75467f60a3d14f08f86f2b353298d2826382ff23 (patch)
treeacd8a7d5b5a675042449386efa5b42ec44d8bf81 /security/Makefile
downloadlinux-stable-75467f60a3d14f08f86f2b353298d2826382ff23.tar.gz
linux-stable-75467f60a3d14f08f86f2b353298d2826382ff23.zip
Merge tag 'ipe-pr-20260925' of git://git.kernel.org/pub/scm/linux/kernel/git/wufan/ipegrafted
Pull IPE fixes from Fan Wu: "Two fixes for use-after-free issues found by recent LLM-assisted code analysis. - move successful policy load auditing under the new policy directory's inode lock, preventing a concurrent policy deletion from freeing the policy while it is still being audited - protect the dm-verity root hash with RCU, preventing policy evaluation from racing with root hash replacement during preresume" * tag 'ipe-pr-20260925' of git://git.kernel.org/pub/scm/linux/kernel/git/wufan/ipe: ipe: protect the dm-verity root hash with RCU ipe: fix use-after-free when auditing a newly loaded policy
Diffstat (limited to 'security/Makefile')
-rw-r--r--security/Makefile31
1 files changed, 31 insertions, 0 deletions
diff --git a/security/Makefile b/security/Makefile
new file mode 100644
index 000000000..4601230ba
--- /dev/null
+++ b/security/Makefile
@@ -0,0 +1,31 @@
+# SPDX-License-Identifier: GPL-2.0
+#
+# Makefile for the kernel security code
+#
+
+obj-$(CONFIG_KEYS) += keys/
+
+# always enable default capabilities
+obj-y += commoncap.o
+obj-$(CONFIG_SECURITY) += lsm_syscalls.o
+obj-$(CONFIG_MMU) += min_addr.o
+
+# Object file lists
+obj-$(CONFIG_SECURITY) += security.o lsm_notifier.o lsm_init.o
+obj-$(CONFIG_SECURITYFS) += inode.o
+obj-$(CONFIG_SECURITY_SELINUX) += selinux/
+obj-$(CONFIG_SECURITY_SMACK) += smack/
+obj-$(CONFIG_HAS_SECURITY_AUDIT) += lsm_audit.o
+obj-$(CONFIG_SECURITY_TOMOYO) += tomoyo/
+obj-$(CONFIG_SECURITY_APPARMOR) += apparmor/
+obj-$(CONFIG_SECURITY_YAMA) += yama/
+obj-$(CONFIG_SECURITY_LOADPIN) += loadpin/
+obj-$(CONFIG_SECURITY_SAFESETID) += safesetid/
+obj-$(CONFIG_SECURITY_LOCKDOWN_LSM) += lockdown/
+obj-$(CONFIG_CGROUPS) += device_cgroup.o
+obj-$(CONFIG_BPF_LSM) += bpf/
+obj-$(CONFIG_SECURITY_LANDLOCK) += landlock/
+obj-$(CONFIG_SECURITY_IPE) += ipe/
+
+# Object integrity file lists
+obj-$(CONFIG_INTEGRITY) += integrity/