diff options
author | antman666 | 2021-06-27 11:43:00 +0800 |
---|---|---|
committer | antman666 | 2021-06-27 11:43:00 +0800 |
commit | dd4c93d029a4ebe22d46cb057f21c1476e626d1d (patch) | |
tree | 73482127e3d4424e8ab0c4e70110a029c3134337 | |
parent | 6797d09ada57c2cb0455a0b9ae7c10ca3406c293 (diff) | |
download | aur-dd4c93d029a4ebe22d46cb057f21c1476e626d1d.tar.gz |
update linux-ck-uksm
-rw-r--r-- | config | 17 |
1 files changed, 8 insertions, 9 deletions
@@ -379,7 +379,7 @@ CONFIG_ACRN_GUEST=y # CONFIG_MPSC is not set # CONFIG_MCORE2 is not set # CONFIG_MATOM is not set -# CONFIG_MNEHALEM is not set +CONFIG_MNEHALEM=y # CONFIG_MWESTMERE is not set # CONFIG_MSILVERMONT is not set # CONFIG_MGOLDMONT is not set @@ -398,7 +398,7 @@ CONFIG_ACRN_GUEST=y # CONFIG_MSAPPHIRERAPIDS is not set # CONFIG_MROCKETLAKE is not set # CONFIG_MALDERLAKE is not set -CONFIG_GENERIC_CPU=y +# CONFIG_GENERIC_CPU is not set # CONFIG_GENERIC_CPU2 is not set # CONFIG_GENERIC_CPU3 is not set # CONFIG_GENERIC_CPU4 is not set @@ -406,6 +406,9 @@ CONFIG_GENERIC_CPU=y # CONFIG_MNATIVE_AMD is not set CONFIG_X86_INTERNODE_CACHE_SHIFT=6 CONFIG_X86_L1_CACHE_SHIFT=6 +CONFIG_X86_INTEL_USERCOPY=y +CONFIG_X86_USE_PPRO_CHECKSUM=y +CONFIG_X86_P6_NOP=y CONFIG_X86_TSC=y CONFIG_X86_CMPXCHG64=y CONFIG_X86_CMOV=y @@ -9252,13 +9255,10 @@ CONFIG_SECURITY_TOMOYO_MAX_AUDIT_LOG=1024 CONFIG_SECURITY_TOMOYO_POLICY_LOADER="/usr/bin/tomoyo-init" CONFIG_SECURITY_TOMOYO_ACTIVATION_TRIGGER="/usr/lib/systemd/systemd" # CONFIG_SECURITY_TOMOYO_INSECURE_BUILTIN_SETTING is not set -CONFIG_SECURITY_APPARMOR=y -CONFIG_SECURITY_APPARMOR_HASH=y -CONFIG_SECURITY_APPARMOR_HASH_DEFAULT=y -# CONFIG_SECURITY_APPARMOR_DEBUG is not set +# CONFIG_SECURITY_APPARMOR is not set CONFIG_SECURITY_LOADPIN=y CONFIG_SECURITY_LOADPIN_ENFORCE=y -CONFIG_SECURITY_YAMA=y +# CONFIG_SECURITY_YAMA is not set CONFIG_SECURITY_SAFESETID=y CONFIG_SECURITY_LOCKDOWN_LSM=y # CONFIG_SECURITY_LOCKDOWN_LSM_EARLY is not set @@ -9269,9 +9269,8 @@ CONFIG_LOCK_DOWN_KERNEL_FORCE_NONE=y # CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT is not set # CONFIG_DEFAULT_SECURITY_SMACK is not set # CONFIG_DEFAULT_SECURITY_TOMOYO is not set -# CONFIG_DEFAULT_SECURITY_APPARMOR is not set CONFIG_DEFAULT_SECURITY_DAC=y -CONFIG_LSM="lockdown,yama,bpf" +CONFIG_LSM="lockdown,bpf" # # Kernel hardening options |