Files
Centos-kernel-stream-9/kernel
Prarit Bhargava 3156b093af hardening: Provide Kconfig fragments for basic options
JIRA: https://issues.redhat.com/browse/RHEL-25415

Conflicts: The MAINTAINERS entry doesn't exist in RHEL9.

commit 215199e3d9f3dc01a6d10b8229891e6f7f1085e7
Author: Kees Cook <keescook@chromium.org>
Date:   Thu Aug 24 21:25:55 2023 -0700

    hardening: Provide Kconfig fragments for basic options

    Inspired by Salvatore Mesoraca's earlier[1] efforts to provide some
    in-tree guidance for kernel hardening Kconfig options, add a new fragment
    named "hardening-basic.config" (along with some arch-specific fragments)
    that enable a basic set of kernel hardening options that have the least
    (or no) performance impact and remove a reasonable set of legacy APIs.

    Using this fragment is as simple as running "make hardening.config".

    More extreme fragments can be added[2] in the future to cover all the
    recognized hardening options, and more per-architecture files can be
    added too.

    For now, document the fragments directly via comments. Perhaps .rst
    documentation can be generated from them in the future (rather than the
    other way around).

    [1] https://lore.kernel.org/kernel-hardening/1536516257-30871-1-git-send-email-s.mesoraca16@gmail.com/
    [2] https://github.com/KSPP/linux/issues/14

    Cc: Salvatore Mesoraca <s.mesoraca16@gmail.com>
    Cc: x86@kernel.org
    Cc: linux-arm-kernel@lists.infradead.org
    Cc: linux-doc@vger.kernel.org
    Cc: linux-kbuild@vger.kernel.org
    Signed-off-by: Kees Cook <keescook@chromium.org>

Signed-off-by: Prarit Bhargava <prarit@redhat.com>
2024-03-20 09:43:30 -04:00
..
2024-03-20 09:42:38 -04:00
2024-03-20 09:42:40 -04:00