From facced23f1e3561b236bc2ce5d7ac8961e1f4ec1 Mon Sep 17 00:00:00 2001 From: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> Date: Tue, 17 Feb 2026 23:03:47 +0100 Subject: [PATCH 1/8] refactor(kernel): added audit.cfg kernel config snippet for settings uniform on all platforms Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> --- conf/distro/include/omnect-os-kernel.conf | 1 + recipes-kernel/linux/files/audit.cfg | 5 +++++ 2 files changed, 6 insertions(+) create mode 100644 recipes-kernel/linux/files/audit.cfg diff --git a/conf/distro/include/omnect-os-kernel.conf b/conf/distro/include/omnect-os-kernel.conf index 5a713e705..7824c116b 100644 --- a/conf/distro/include/omnect-os-kernel.conf +++ b/conf/distro/include/omnect-os-kernel.conf @@ -7,6 +7,7 @@ OMNECT_KERNEL_SRC_URI_LTE = " \ " OMNECT_KERNEL_SRC_URI = " \ + file://audit.cfg \ file://cpu_freq_default_gov_schedutil.cfg \ file://enable-overlayfs.cfg \ file://enable-cifs.cfg \ diff --git a/recipes-kernel/linux/files/audit.cfg b/recipes-kernel/linux/files/audit.cfg new file mode 100644 index 000000000..cfb546e55 --- /dev/null +++ b/recipes-kernel/linux/files/audit.cfg @@ -0,0 +1,5 @@ +CONFIG_AUDIT=y +CONFIG_AUDITSYSCALL=y +CONFIG_SECURITY_NETWORK=y +# next one is for ARM only but won't hurt for other platforms +CONFIG_HAVE_ARCH_AUDITSYSCALL=y From c7b5462f95ddf4745c46a4c1f37cb83243456d8d Mon Sep 17 00:00:00 2001 From: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> Date: Mon, 2 Mar 2026 11:11:39 +0100 Subject: [PATCH 2/8] refactor(kernel-config): audit configuration can depend on option CONFIG_SECURITY_APPARMOR, so add it, too Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> --- recipes-kernel/linux/files/audit.cfg | 1 + 1 file changed, 1 insertion(+) diff --git a/recipes-kernel/linux/files/audit.cfg b/recipes-kernel/linux/files/audit.cfg index cfb546e55..fca4191d4 100644 --- a/recipes-kernel/linux/files/audit.cfg +++ b/recipes-kernel/linux/files/audit.cfg @@ -1,5 +1,6 @@ CONFIG_AUDIT=y CONFIG_AUDITSYSCALL=y CONFIG_SECURITY_NETWORK=y +CONFIG_SECURITY_APPARMOR=y # next one is for ARM only but won't hurt for other platforms CONFIG_HAVE_ARCH_AUDITSYSCALL=y From 9b0ccc6573397ac5fe38359a557ea4d1950916f5 Mon Sep 17 00:00:00 2001 From: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> Date: Mon, 2 Mar 2026 18:43:03 +0100 Subject: [PATCH 3/8] refactor(kernel-config): in audit config snippet set SECURITY_DAC as default (as it was w/o audit) Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> --- recipes-kernel/linux/files/audit.cfg | 2 ++ 1 file changed, 2 insertions(+) diff --git a/recipes-kernel/linux/files/audit.cfg b/recipes-kernel/linux/files/audit.cfg index fca4191d4..0e8765506 100644 --- a/recipes-kernel/linux/files/audit.cfg +++ b/recipes-kernel/linux/files/audit.cfg @@ -1,6 +1,8 @@ CONFIG_AUDIT=y CONFIG_AUDITSYSCALL=y CONFIG_SECURITY_NETWORK=y +# audit might depend on APPARMOR so enable it; but keep DAC as default CONFIG_SECURITY_APPARMOR=y +CONFIG_DEFAULT_SECURITY_DAC=y # next one is for ARM only but won't hurt for other platforms CONFIG_HAVE_ARCH_AUDITSYSCALL=y From 8641102554ce7c112db12429de73b7d39ba5ecf7 Mon Sep 17 00:00:00 2001 From: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> Date: Mon, 9 Mar 2026 16:59:38 +0100 Subject: [PATCH 4/8] refactor(kernel-config): make config snippet audit.cfg dependent on audit distro feature Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> --- conf/distro/include/omnect-os-kernel.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/conf/distro/include/omnect-os-kernel.conf b/conf/distro/include/omnect-os-kernel.conf index 7824c116b..613202478 100644 --- a/conf/distro/include/omnect-os-kernel.conf +++ b/conf/distro/include/omnect-os-kernel.conf @@ -7,7 +7,7 @@ OMNECT_KERNEL_SRC_URI_LTE = " \ " OMNECT_KERNEL_SRC_URI = " \ - file://audit.cfg \ + ${@bb.utils.contains('DISTRO_FEATURES', 'audit', 'file://audit.cfg', '', d)} \ file://cpu_freq_default_gov_schedutil.cfg \ file://enable-overlayfs.cfg \ file://enable-cifs.cfg \ From 3e38bc26fd9a8f0f034ae7c6418109bbef6e4895 Mon Sep 17 00:00:00 2001 From: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> Date: Mon, 9 Mar 2026 17:00:24 +0100 Subject: [PATCH 5/8] Revert "refactor(kernel-config): make config snippet audit.cfg dependent on audit distro feature" This reverts commit 8641102554ce7c112db12429de73b7d39ba5ecf7. --- conf/distro/include/omnect-os-kernel.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/conf/distro/include/omnect-os-kernel.conf b/conf/distro/include/omnect-os-kernel.conf index 613202478..7824c116b 100644 --- a/conf/distro/include/omnect-os-kernel.conf +++ b/conf/distro/include/omnect-os-kernel.conf @@ -7,7 +7,7 @@ OMNECT_KERNEL_SRC_URI_LTE = " \ " OMNECT_KERNEL_SRC_URI = " \ - ${@bb.utils.contains('DISTRO_FEATURES', 'audit', 'file://audit.cfg', '', d)} \ + file://audit.cfg \ file://cpu_freq_default_gov_schedutil.cfg \ file://enable-overlayfs.cfg \ file://enable-cifs.cfg \ From f53e9c1b1720b20bdcf12a0fe466c875f88d9d63 Mon Sep 17 00:00:00 2001 From: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> Date: Tue, 10 Mar 2026 16:38:59 +0100 Subject: [PATCH 6/8] refactor(kernel-config): removed unnecessary option CONFIG_HAVE_ARCH_AUDITSYSCALL in audit snippet Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> --- recipes-kernel/linux/files/audit.cfg | 2 -- 1 file changed, 2 deletions(-) diff --git a/recipes-kernel/linux/files/audit.cfg b/recipes-kernel/linux/files/audit.cfg index 0e8765506..7676fa9b2 100644 --- a/recipes-kernel/linux/files/audit.cfg +++ b/recipes-kernel/linux/files/audit.cfg @@ -4,5 +4,3 @@ CONFIG_SECURITY_NETWORK=y # audit might depend on APPARMOR so enable it; but keep DAC as default CONFIG_SECURITY_APPARMOR=y CONFIG_DEFAULT_SECURITY_DAC=y -# next one is for ARM only but won't hurt for other platforms -CONFIG_HAVE_ARCH_AUDITSYSCALL=y From a209100f6ef1e97ab3661aca1c24f4297216925f Mon Sep 17 00:00:00 2001 From: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> Date: Tue, 10 Mar 2026 16:41:11 +0100 Subject: [PATCH 7/8] refactor(systemd): now remove audit socket targets unconditionally (more consistent) Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> --- recipes-core/systemd/systemd_%.bbappend | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/recipes-core/systemd/systemd_%.bbappend b/recipes-core/systemd/systemd_%.bbappend index 2ddb95504..5bcf196e5 100644 --- a/recipes-core/systemd/systemd_%.bbappend +++ b/recipes-core/systemd/systemd_%.bbappend @@ -56,11 +56,9 @@ do_install:append() { [ -n "${JOURNALD_RuntimeMaxFiles}" ] && sed -i 's/^#RuntimeMaxFiles=/RuntimeMaxFiles=${JOURNALD_RuntimeMaxFiles} /' ${D}${sysconfdir}/systemd/journald.conf [ -n "${JOURNALD_ForwardToSyslog}" ] && sed -i -E 's/^#ForwardToSyslog=(.*)/ForwardToSyslog=${JOURNALD_ForwardToSyslog} /' ${D}${sysconfdir}/systemd/journald.conf - # delete systemd-journald-audit.socket if audit is not in DISTRO_FEATURES - if ${@bb.utils.contains('DISTRO_FEATURES', 'audit', 'false', 'true', d)}; then - rm -f ${D}${systemd_system_unitdir}/sockets.target.wants/systemd-journald-audit.socket - rm -f ${D}${systemd_system_unitdir}/systemd-journald-audit.socket - fi + # delete systemd-journald-audit.socket - we don't use this feature (yet) + rm -f ${D}${systemd_system_unitdir}/sockets.target.wants/systemd-journald-audit.socket + rm -f ${D}${systemd_system_unitdir}/systemd-journald-audit.socket # sync time on sysinit install -d ${D}${sysconfdir}/systemd/system/sysinit.target.wants From 445d1e782946aa27a3f7470c00535fd04714f2c3 Mon Sep 17 00:00:00 2001 From: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> Date: Tue, 10 Mar 2026 18:44:15 +0100 Subject: [PATCH 8/8] refactor(kernel-config): improved comment for enablinng APPARMOR in audit.cfg Signed-off-by: Harry Waschkeit <44188360+HarryWaschkeit@users.noreply.github.com> --- recipes-kernel/linux/files/audit.cfg | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/recipes-kernel/linux/files/audit.cfg b/recipes-kernel/linux/files/audit.cfg index 7676fa9b2..a51f86552 100644 --- a/recipes-kernel/linux/files/audit.cfg +++ b/recipes-kernel/linux/files/audit.cfg @@ -1,6 +1,7 @@ CONFIG_AUDIT=y CONFIG_AUDITSYSCALL=y CONFIG_SECURITY_NETWORK=y -# audit might depend on APPARMOR so enable it; but keep DAC as default +# AUDIT option might depend on APPARMOR option so enable it; but keep DAC as +# default CONFIG_SECURITY_APPARMOR=y CONFIG_DEFAULT_SECURITY_DAC=y