summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
* Update to KSPP patchHEADmasterMike Pagano2024-05-051-12/+21
| | | | | | Bug: https://bugs.gentoo.org/930733 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Add UBSAN_BOUNDS and UBSAN_SHIFT and dependenciesMike Pagano2024-04-271-7/+7
| | | | | | Bug: https://bugs.gentoo.org/930733 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* select BLK_DEV_BSG if SCSI as it depends on it.Mike Pagano2023-10-051-1/+1
| | | | | | Thanks, Ancient. Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Remove patch on security/selinux/KconfigMike Pagano2023-05-091-12/+0
| | | | | | | As CONFIG_SECURITY_SELINUX_DISABLE was removed upstream, remove our corresponding patch on it Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Fix config change from X86_X32 to X86_X32_ABIMike Pagano2023-03-211-1/+1
| | | | | | | | Thanks to Frank Limpert Bug: https://bugs.gentoo.org/902443 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Add CONFIG_LANDLOCK to KSPP and RANDSTRUCT fixMike Pagano2022-08-251-10/+11
| | | | | | Bug: https://bugs.gentoo.org/865685 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Remove references to HARDENED_USERCOPY_PAGESPANMike Pagano2022-06-271-10/+0
| | | | | | Removed from upstream Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Update Gentoo Hardened patchset based on KSPP thanks to Peter BoMike Pagano2022-05-111-6/+11
| | | | | | | | | | | | | | Bug: https://bugs.gentoo.org/841488 Added: CONFIG_HARDENED_USERCOPY=y CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT=y CONFIG_KFENCE=y CONFIG_IOMMU_DEFAULT_DMA_STRICT=y CONFIG_SCHED_CORE=y CONFIG_ZERO_CALL_USED_REGS=y Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Update distro patch in security Kconfig for 5.18Mike Pagano2022-04-251-3/+3
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Remove deprecated select AUTOFS4_FSMike Pagano2022-04-121-2/+1
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Select AUTOFS_FS when GENTOO_LINUX_INIT_SYSTEMD selectedMike Pagano2022-04-121-5/+6
| | | | | | Bug: https://bugs.gentoo.org/838082 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Select CONFIG_CPU_FREQ_DEFAULT_GOV_SCHEDUTIL=y as defaultMike Pagano2022-01-291-3/+5
| | | | | | Bug: https://bugs.gentoo.org/832224 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Revert "Update Gentoo Distro patch, thanks to gyakovlev"Mike Pagano2022-01-091-149/+102
| | | | | | This reverts commit 632cc59cc8462f3f01085d1b76cc304488a06394. Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Update Gentoo Distro patch, thanks to gyakovlevMike Pagano2022-01-041-102/+149
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Move X86 and ARM only config settings to their respective sectionsMike Pagano2021-12-211-5/+7
| | | | | | Thanks to gyakovlev Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Remove KSPP setting for HARDENED_USERCOPY_FALLBACKMike Pagano2021-12-051-13/+3
| | | | | | This config option has been removed in 5.16. Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* For systemd, select CONFIG_KCMP as systemd uses the kcmp() callMike Pagano2021-10-181-1/+1
| | | | | | | | | | Originally tied to CHECKPOINT_RESTORE. Thanks to Mike Gilbert for reporting. Bug: https://bugs.gentoo.org/818832 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Move USER_NS to GENTOO_LINUX_PORTAGEMike Pagano2021-09-201-1/+1
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Change CONFIG_GENTOO_PRINT_FIRMWARE_INFO to yMike Pagano2021-08-251-1/+1
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Add CONFIG option to print firmware infoMike Pagano2021-08-241-3/+17
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Fix GCC_PLUGINS dependsMike Pagano2021-08-091-6/+5
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Add CONFIG_RELOCATABLE when selecting RANDOMIZE_BASEMike Pagano2021-08-031-23/+28
| | | | | | | | Redo menu's to make more user-friendly Bug: https://bugs.gentoo.org/806300 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Fix SECCOMP PatchMike Pagano2021-08-031-2/+2
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Select SECCOMP options only if supportedMike Pagano2021-08-021-4/+4
| | | | | | | | | | | | | | | | | | | | Thanks to Matt Turner for this patch Some architectures (e.g., alpha, sparc) do not support SECCOMP. Without this kernel builds will show: WARNING: unmet direct dependencies detected for SECCOMP Depends on [n]: HAVE_ARCH_SECCOMP [=n] Selected by [y]: - GENTOO_LINUX_INIT_SYSTEMD [=y] && GENTOO_LINUX [=y] && GENTOO_LINUX_UDEV [=y] WARNING: unmet direct dependencies detected for SECCOMP_FILTER Depends on [n]: HAVE_ARCH_SECCOMP_FILTER [=n] && SECCOMP [=y] && NET [=y] Selected by [y]: - GENTOO_LINUX_INIT_SYSTEMD [=y] && GENTOO_LINUX [=y] && GENTOO_LINUX_UDEV [=y] Signed-off-by: Matt Turner <mattst88@gentoo.org> Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Fix DEVMEM Select and move help textMike Pagano2021-07-041-13/+13
| | | | | | | | Thanks to Peter for reporting Bug: https://bugs.gentoo.org/798315 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Update KSP Patch, minor typo and formattingMike Pagano2021-06-111-9/+9
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Updates from gyakovlevMike Pagano2021-06-081-8/+64
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Updates from gyakovlevMike Pagano2021-06-081-10/+10
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Remove !IA32_EMULATION in KSSP to avoid disabling multilib.Thanks gyakovlevMike Pagano2021-06-081-1/+1
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* CONFIG opt to enable a subset of Kernel Self Protection Project settingsMike Pagano2021-06-081-6/+115
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Add missing endmenuMike Pagano2020-09-241-2/+3
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Fix formattingMike Pagano2020-09-241-1/+1
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Add CONFIG_USER_NS to GENTOO_LINUX_INIT_SYSTEMDMike Pagano2020-09-241-3/+3
| | | | | | Required for PrivateUsers= in service units Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Add UTS_NS to GENTOO_LINUX_PORTAGE as required by portage since 2.3.99Mike Pagano2020-05-131-3/+4
| | | | | | Bug: https://bugs.gentoo.org/722772 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Update distro Kconfig to support needed options for elogindMike Pagano2020-04-151-5/+10
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Add CONFIG selections for GENTOO_LINUX_INIT_SYSTEMDMike Pagano2019-12-301-5/+7
| | | | | | | | Adding CGROUP_BPF and it's dependency BPF_SYSCALL Bug: https://bugs.gentoo.org/704284 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* select FILE_LOCKING for both non-systemd and systemd configMike Pagano2019-09-181-3/+5
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Update Gentoo Kernel Linux distro patchMike Pagano2019-08-071-5/+5
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* proj/linux-patches: Select PID_NS to support FEATURES=pid-sandboxMike Pagano2018-12-281-3/+5
| | | | | | | For portage: >=sys-apps/portage-2.3.53 See bug #673896 Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Update of Gentoo distro patch for 4.19Mike Pagano2018-09-281-7/+6
| | | | Signed-off-by: Mike Pagano <mpagano@gentoo.org>
* Enable crypto API for systemd as its required for systemd versions >= 233. ↵Mike Pagano2017-03-021-3/+6
| | | | See bug #611368.
* For GENTOO_LINUX_INIT_SYSTEMD don't add DMIID for non X86 architectures. See ↵Mike Pagano2017-02-181-3/+3
| | | | bug #609590.
* Update gentoo kconfig patch adding CHECKPOINT_RESTORE for ↵Mike Pagano2016-11-161-3/+4
| | | | GENTOO_LINUX_INIT_SYSTEMD. See bug #598623
* Update gentoo kconfig patch. See bug #598623Mike Pagano2016-11-061-8/+17
|
* Update gentoo kconfig patch to remove DEVPTS_MULTIPLE_INSTANCES. See kernel ↵Mike Pagano2016-08-301-10/+8
| | | | upstream commit: eedf265aa003b4781de24cfed40a655a664457e6. Thanks to Ralf Ramsauer.
* Select SYSVIPC when GENTOO_LINUX_PORTAGE is selected. Dependency of IPC_NS. ↵Mike Pagano2016-07-011-5/+8
| | | | See bug #587736.
* Fix readmeMike Pagano2015-06-231-72/+0
|
* Clean up masterMike Pagano2015-06-2318-30940/+0
|
* Add check to saved_root_name for supported filesystem path naming.Mike Pagano2015-06-201-1/+1
|
* Linux patch 4.0.54.0-7Mike Pagano2015-06-062-0/+4941
|