public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH] Kconfig: Make STRICT_DEVMEM default-y on x86 and arm64
@ 2017-12-01 20:10 Kees Cook
  2017-12-01 20:46 ` Laura Abbott
                   ` (3 more replies)
  0 siblings, 4 replies; 6+ messages in thread
From: Kees Cook @ 2017-12-01 20:10 UTC (permalink / raw)
  To: Andrew Morton
  Cc: linux-kernel, kernel-hardening, Mark Rutland, Will Deacon,
	Laura Abbott, x86

Distros have been shipping with CONFIG_STRICT_DEVMEM=y for years now. It
is probably time to flip this default for x86 and arm64.

Signed-off-by: Kees Cook <keescook@chromium.org>
---
 lib/Kconfig.debug | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/lib/Kconfig.debug b/lib/Kconfig.debug
index 947d3e2ed5c2..39b123d04a36 100644
--- a/lib/Kconfig.debug
+++ b/lib/Kconfig.debug
@@ -1985,7 +1985,7 @@ config STRICT_DEVMEM
 	bool "Filter access to /dev/mem"
 	depends on MMU && DEVMEM
 	depends on ARCH_HAS_DEVMEM_IS_ALLOWED
-	default y if TILE || PPC
+	default y if TILE || PPC || X86 || ARM64
 	---help---
 	  If this option is disabled, you allow userspace (root) access to all
 	  of memory, including kernel and userspace memory. Accidental
-- 
2.7.4


-- 
Kees Cook
Pixel Security

^ permalink raw reply related	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2017-12-19 13:33 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-12-01 20:10 [PATCH] Kconfig: Make STRICT_DEVMEM default-y on x86 and arm64 Kees Cook
2017-12-01 20:46 ` Laura Abbott
2017-12-04 15:56 ` Will Deacon
2017-12-04 18:19   ` Kees Cook
2017-12-12 10:56 ` [tip:core/debug] " tip-bot for Kees Cook
2017-12-19 13:33 ` [kernel-hardening] [PATCH] " Ard Biesheuvel

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox