]> asedeno.scripts.mit.edu Git - linux.git/commitdiff
security: only build lsm_audit if CONFIG_SECURITY=y
authorStephen Smalley <sds@tycho.nsa.gov>
Tue, 10 Dec 2019 16:55:41 +0000 (11:55 -0500)
committerPaul Moore <paul@paul-moore.com>
Tue, 10 Dec 2019 18:51:42 +0000 (13:51 -0500)
The lsm_audit code is only required when CONFIG_SECURITY is enabled.
It does not have a build dependency on CONFIG_AUDIT since audit.h
provides trivial static inlines for audit_log*() when CONFIG_AUDIT
is disabled.  Hence, the Makefile should only add lsm_audit to the
obj lists based on CONFIG_SECURITY, not CONFIG_AUDIT.

Fixes: 59438b46471a ("security,lockdown,selinux: implement SELinux lockdown")
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: Paul Moore <paul@paul-moore.com>
security/Makefile

index be1dd9d2cb2fb90d3969902e456144b6ecc3ea89..74643849902950fd7c0dd286aec84e2b57ce4be3 100644 (file)
@@ -22,7 +22,7 @@ obj-$(CONFIG_SECURITY)                        += security.o
 obj-$(CONFIG_SECURITYFS)               += inode.o
 obj-$(CONFIG_SECURITY_SELINUX)         += selinux/
 obj-$(CONFIG_SECURITY_SMACK)           += smack/
-obj-$(CONFIG_AUDIT)                    += lsm_audit.o
+obj-$(CONFIG_SECURITY)                 += lsm_audit.o
 obj-$(CONFIG_SECURITY_TOMOYO)          += tomoyo/
 obj-$(CONFIG_SECURITY_APPARMOR)                += apparmor/
 obj-$(CONFIG_SECURITY_YAMA)            += yama/