4b5e4234be
3 Commits
Author | SHA1 | Message | Date | |
---|---|---|---|---|
Jeremy Cline
|
4b5e4234be |
Rebase the kernel lockdown patch set
Use the latest version of the kernel lockdown patch set. This includes a few configuration renames: CONFIG_KEXEC_VERIFY_SIG became CONFIG_KEXEC_SIG and CONFIG_KEXEC_SIG_FORCE was added. CONFIG_KEXEC_SIG_FORCE=n because the "kexec_file: Restrict at runtime if the kernel is locked down" patch enforces the signature requirement when the kernel is locked down. CONFIG_LOCK_DOWN_MANDATORY got renamed to CONFIG_LOCK_DOWN_KERNEL_FORCE and remains false as LOCK_DOWN_IN_EFI_SECURE_BOOT covers enabling it for EFI Secure Boot users. Finally, the SysRq patches got dropped for the present. |
||
Paul Bolle
|
da848d916b |
Remove all references to unknown Kconfig symbols
There are 244 Kconfig symbols referenced in the files used for configuration generation and in the shipped .config files that are unknown in v4.20-rc1. Neither are these symbols added in the patches that Fedora applies. The references to these symbols can be safely removed. These symbols are: CONFIG_8723AU_AP_MODE CONFIG_8723AU_BT_COEXIST CONFIG_ACPI_NFIT_DEBUG CONFIG_ACPI_PROCFS CONFIG_ADE7753 CONFIG_ADE7754 CONFIG_ADE7758 CONFIG_ADE7759 CONFIG_ADIS16060 CONFIG_ALTERNATIVES CONFIG_ARM64_PTDUMP CONFIG_ARM_ASM_UNIFIED CONFIG_ARM_PTDUMP CONFIG_ATH9K_DEBUG CONFIG_AVERAGE CONFIG_AXON_RAM CONFIG_BACKLIGHT_LM3630 CONFIG_BLK_DEV_NVME_SCSI CONFIG_BLK_DEV_OSD CONFIG_BLK_DEV_RAM_DAX CONFIG_BOOTPARAM_LOCKDEP_CROSSRELEASE_FULLSTACK CONFIG_BT_HCIBTUART CONFIG_BUILD_DOCSRC CONFIG_BUILD_ID_SALT CONFIG_CC_STACKPROTECTOR_AUTO CONFIG_CC_STACKPROTECTOR_NONE CONFIG_CC_STACKPROTECTOR_REGULAR CONFIG_CIFS_SMB2 CONFIG_CIFS_SMB311 CONFIG_CIFS_STATS CONFIG_CPU_FREQ_STAT_DETAILS CONFIG_CPU_NOTIFIER_ERROR_INJECT CONFIG_CROS_EC_CHARDEV CONFIG_CROSS_COMPILE CONFIG_CRYPTO_CRC32_ARM64 CONFIG_CRYPTO_CRC32_ARM64_CE CONFIG_CRYPTO_MCRYPTD CONFIG_CRYPTO_SALSA20_586 CONFIG_CRYPTO_SALSA20_X86_64 CONFIG_CRYPTO_SHA1_MB CONFIG_CRYPTO_SHA256_MB CONFIG_CRYPTO_SHA512_MB CONFIG_CRYPTO_SKEIN CONFIG_CTC CONFIG_DEBUG_NX_TEST CONFIG_DEBUG_REFCOUNT CONFIG_DEBUG_SET_MODULE_RONX CONFIG_DGAP CONFIG_DGNC CONFIG_DIRECT_GBPAGES CONFIG_DISABLE_MPROFILE_KERNEL CONFIG_DM_CACHE_CLEANER CONFIG_DM_MQ_DEFAULT CONFIG_DRM_AMD_DC_FBC CONFIG_DRM_AMD_DC_PRE_VEGA CONFIG_DRM_AMD_POWERPLAY CONFIG_DRM_DEBUG_MM_SELFTEST CONFIG_DRM_ETNAVIV_REGISTER_LOGGING CONFIG_DRM_IMX_IPUV3 CONFIG_DRM_OMAP_NUM_CRTCS CONFIG_DRM_TILCDC_SLAVE_COMPAT CONFIG_DT3155 CONFIG_DVB_USB_FRIIO CONFIG_DW_DMAC_BIG_ENDIAN_IO CONFIG_EFI_ALLOW_SECURE_BOOT_EXIT CONFIG_EFI_SECURE_BOOT_LOCK_DOWN CONFIG_EFI_SECURE_BOOT_SIG_ENFORCE CONFIG_ENABLE_WARN_DEPRECATED CONFIG_FB_AUO_K190X CONFIG_FUJITSU_LAPTOP_DEBUG CONFIG_GPIO_AXP209 CONFIG_GPIO_DEVRES CONFIG_GPIO_MCP23S08 CONFIG_GPIO_SX150X CONFIG_HFI1_VERBS_31BIT_PSN CONFIG_HFSPLUS_FS_POSIX_ACL CONFIG_HOTPLUG CONFIG_HT_IRQ CONFIG_I2C_DESIGNWARE CONFIG_I2O CONFIG_I40E_FCOE CONFIG_I7300_IDLE CONFIG_IDMA64 CONFIG_INFINIBAND_CXGB3_DEBUG CONFIG_INFINIBAND_EXP_USER_ACCESS CONFIG_INPUT_GPIO CONFIG_INPUT_GPIO_TILT_POLLED CONFIG_INTEL_RDT_A CONFIG_IOMMU_STRESS CONFIG_IP1000 CONFIG_IP_DCCP_CCID2 CONFIG_IPL CONFIG_IPV6_SEG6_INLINE CONFIG_IRDA CONFIG_IR_LIRC_CODEC CONFIG_IRQ_DOMAIN_DEBUG CONFIG_IWM CONFIG_KEXEC_SIG CONFIG_KEXEC_SIG_FORCE CONFIG_KVM_DEVICE_ASSIGNMENT CONFIG_LGUEST CONFIG_LGUEST_GUEST CONFIG_LIRC_BT829 CONFIG_LIRC_IMON CONFIG_LIRC_PARALLEL CONFIG_LIRC_SERIAL CONFIG_LIRC_SERIAL_TRANSMITTER CONFIG_LIRC_STAGING CONFIG_LIRC_ZILOG CONFIG_LNET CONFIG_LOGFS CONFIG_LPFC_NVME_INITIATOR CONFIG_LPFC_NVME_TARGET CONFIG_MACH_MESON8B CONFIG_MCE_AMD_INJ CONFIG_MEDIA_CEC_DEBUG CONFIG_MEDIA_RC_SUPPORT CONFIG_MFD_CROS_EC_I2C CONFIG_MFD_CROS_EC_SPI CONFIG_MG_DISK CONFIG_MLX_CPLD_PLATFORM CONFIG_MOVABLE_NODE CONFIG_MTD_NAND_DOCG4 CONFIG_MTD_NAND_PXA3xx CONFIG_MVEBU_CLK_CORE CONFIG_NET_CADENCE CONFIG_NET_CLS_ROUTE CONFIG_NET_DCCPPROBE CONFIG_NET_DSA_HWMON CONFIG_NETFILTER_DEBUG CONFIG_NET_PACKET_ENGINE CONFIG_NET_SCTPPROBE CONFIG_NET_TCPPROBE CONFIG_NET_VENDOR_EXAR CONFIG_NET_VENDOR_SNI CONFIG_NF_CONNTRACK_IPV4 CONFIG_NF_CONNTRACK_IPV6 CONFIG_NF_CONNTRACK_PROC_COMPAT CONFIG_NFC_WILINK CONFIG_NFP_NET_DEBUG CONFIG_NFP_NETVF CONFIG_NFT_BRIDGE_META CONFIG_NFT_EXTHDR CONFIG_NFT_META CONFIG_NFT_RBTREE CONFIG_NFT_RT CONFIG_NFT_SET_BITMAP CONFIG_NFT_SET_HASH CONFIG_NFT_SET_RBTREE CONFIG_NL80211 CONFIG_NMI_LOG_BUF_SHIFT CONFIG_NO_BOOTMEM CONFIG_NO_HZ_FULL_ALL CONFIG_NO_HZ_FULL_SYSIDLE CONFIG_NR_DEV_DAX CONFIG_OLPC_XO1 CONFIG_OMAP2_DSS_RFBI CONFIG_OMAP_PM_NOOP CONFIG_PHONE CONFIG_PHY_MIPHY365X CONFIG_PHY_STIH41X_USB CONFIG_PNFS_OBJLAYOUT CONFIG_PPC_CPUFEATURES_ENABLE_UNKNOWN CONFIG_PPC_ICSWX CONFIG_PPC_ICSWX_PID CONFIG_PPC_ICSWX_USE_SIGILL CONFIG_PROVE_RCU_REPEATEDLY CONFIG_QETH_IPV6 CONFIG_R8723AU CONFIG_RCU_KTHREAD_PRIO CONFIG_RCU_NOCB_CPU_ALL CONFIG_RCU_TORTURE_TEST_SLOW_CLEANUP CONFIG_RCU_TORTURE_TEST_SLOW_INIT CONFIG_RCU_TORTURE_TEST_SLOW_INIT_DELAY CONFIG_RCU_TORTURE_TEST_SLOW_PREINIT CONFIG_RESET_GPIO CONFIG_RESET_HSDK_V1 CONFIG_RIO CONFIG_RTC_DRV_DS1307_HWMON CONFIG_RTC_DRV_ISL12057 CONFIG_RTC_DS1685_PROC_REGS CONFIG_RTC_DS1685_SYSFS_REGS CONFIG_S390_GUEST_OLD_TRANSPORT CONFIG_SAMSUNG_USBPHY CONFIG_SCM_BLOCK_CLUSTER_WRITE CONFIG_SCSI_EATA CONFIG_SCSI_EATA_PIO CONFIG_SCSI_FUTURE_DOMAIN CONFIG_SCSI_IN2000 CONFIG_SCSI_SRP CONFIG_SECURITY_SELINUX_POLICYDB_VERSION_MAX CONFIG_SENSORS_TWL4030_MADC CONFIG_SHARED_KERNEL CONFIG_SIGMA CONFIG_SILEAD_DMI CONFIG_SND_HDA_POWER_SAVE CONFIG_SND_SOC_DIO2125 CONFIG_SOC_EXYNOS4212 CONFIG_SOC_EXYNOS4415 CONFIG_SOC_EXYNOS5440 CONFIG_SOLO6X10 CONFIG_SPARSE_RCU_POINTER CONFIG_SSB_DEBUG CONFIG_SSB_SILENT CONFIG_STE_MODEM_RPROC CONFIG_STRIP CONFIG_SYNOPSYS_DWC_ETH_QOS CONFIG_TEST_FIND_BIT CONFIG_TI_DAC7512 CONFIG_TOUCHSCREEN_FT6236 CONFIG_TOUCHSCREEN_INTEL_MID CONFIG_TR CONFIG_TRACE_ENUM_MAP_FILE CONFIG_TSL2x7x CONFIG_UCSI CONFIG_UIO_PDRV CONFIG_USB_ATMEL CONFIG_USB_CHIPIDEA_ULPI CONFIG_USB_DEBUG CONFIG_USB_EZUSB CONFIG_USB_GADGET_LEGACY CONFIG_USB_SERIAL_KEYSPAN_MPR CONFIG_USB_SERIAL_KEYSPAN_USA18X CONFIG_USB_SERIAL_KEYSPAN_USA19 CONFIG_USB_SERIAL_KEYSPAN_USA19QI CONFIG_USB_SERIAL_KEYSPAN_USA19QW CONFIG_USB_SERIAL_KEYSPAN_USA19W CONFIG_USB_SERIAL_KEYSPAN_USA28 CONFIG_USB_SERIAL_KEYSPAN_USA28X CONFIG_USB_SERIAL_KEYSPAN_USA28XA CONFIG_USB_SERIAL_KEYSPAN_USA28XB CONFIG_USB_SERIAL_KEYSPAN_USA49W CONFIG_USB_SERIAL_KEYSPAN_USA49WLC CONFIG_USE_THIN_ARCHIVES CONFIG_VIDEO_CPIA CONFIG_VIDEO_SAMSUNG_S5P_TV CONFIG_VIDEO_SH_MOBILE_CSI2 CONFIG_VIDEO_STK1160_AC97 CONFIG_VIDEO_TW686X_KH CONFIG_VIDEO_VIVI CONFIG_W1_SLAVE_BQ27000 CONFIG_W1_SLAVE_DS2760 CONFIG_XEN_DEBUG CONFIG_XEN_SCRUB_PAGES Signed-off-by: Paul Bolle <pebolle@tiscali.nl> |
||
Justin M. Forbes
|
f20e0a3b66 | Update efi-lockdown patch with current. |