Skip to content

refactor(kernel): added audit.cfg kernel config snippet for settings uniform on all platforms#635

Open
HarryWaschkeit wants to merge 9 commits intoomnect:mainfrom
HarryWaschkeit:hwt-2026-02-17-refactor-kernel-uniform-audit-settings
Open

refactor(kernel): added audit.cfg kernel config snippet for settings uniform on all platforms#635
HarryWaschkeit wants to merge 9 commits intoomnect:mainfrom
HarryWaschkeit:hwt-2026-02-17-refactor-kernel-uniform-audit-settings

Conversation

@HarryWaschkeit
Copy link
Contributor

@HarryWaschkeit HarryWaschkeit commented Feb 17, 2026

Note that audit is not used by omnect Secure OS (yet), but potentially allow for an application to take advantage of that.

…uniform on all platforms

Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com>
…FIG_SECURITY_APPARMOR, so add it, too

Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com>
…default (as it was w/o audit)

Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com>
@HarryWaschkeit HarryWaschkeit requested a review from mlilien March 9, 2026 08:27
@HarryWaschkeit
Copy link
Contributor Author

@JanZachmann @JoergZeidler jfyi

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a kernel config fragment to enable Linux audit-related options across omnect Secure OS kernel builds, making audit settings consistent across platforms (even if audit isn’t currently used by the OS itself).

Changes:

  • Introduces a new kernel config snippet audit.cfg enabling audit/audit-syscall options (and related security options).
  • Includes the new config fragment in the common kernel SRC_URI list so it is applied to all supported kernel recipes.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
recipes-kernel/linux/files/audit.cfg New kernel config fragment enabling audit-related configuration.
conf/distro/include/omnect-os-kernel.conf Adds audit.cfg to the shared kernel config fragment list applied to all kernels.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

…udit distro feature

Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com>
…ent on audit distro feature"

This reverts commit 8641102.
…AUDITSYSCALL in audit snippet

Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com>
…ore consistent)

Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com>
…udit.cfg

Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com>
@HarryWaschkeit HarryWaschkeit requested a review from mlilien March 10, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants