fix #2814: config: disable lockdown
since it prevents boot with our current way of building ZFS modules in case a system is booted with secureboot enabled. Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
This commit is contained in:
parent
3507a8ec4c
commit
f6d3198e5d
3
debian/rules
vendored
3
debian/rules
vendored
@ -73,6 +73,9 @@ PVE_CONFIG_OPTS= \
|
|||||||
-d CONFIG_UNWINDER_ORC \
|
-d CONFIG_UNWINDER_ORC \
|
||||||
-d CONFIG_UNWINDER_GUESS \
|
-d CONFIG_UNWINDER_GUESS \
|
||||||
-e CONFIG_UNWINDER_FRAME_POINTER \
|
-e CONFIG_UNWINDER_FRAME_POINTER \
|
||||||
|
-d CONFIG_SECURITY_LOCKDOWN_LSM \
|
||||||
|
-d CONFIG_SECURITY_LOCKDOWN_LSM_EARLY \
|
||||||
|
--set-str CONFIG_LSM yama,integrity,apparmor \
|
||||||
-e CONFIG_PAGE_TABLE_ISOLATION
|
-e CONFIG_PAGE_TABLE_ISOLATION
|
||||||
|
|
||||||
debian/control: $(wildcard debian/*.in)
|
debian/control: $(wildcard debian/*.in)
|
||||||
|
Loading…
Reference in New Issue
Block a user