Implement PresenceCheck and use it for LDISC_AUTOLOAD
authorAlexander Popov <alex.popov@linux.com>
Tue, 31 Mar 2020 13:57:03 +0000 (16:57 +0300)
committerAlexander Popov <alex.popov@linux.com>
Tue, 31 Mar 2020 13:57:03 +0000 (16:57 +0300)
Refers to #32

kconfig_hardened_check/__init__.py

index 4e3300cd0480bf7461b9c4efd2a5458b5425bd2f..0f3f3d3fe1d15659cd5694884edcc70f66024a13 100755 (executable)
@@ -130,6 +130,26 @@ class VerCheck:
             print('|   {}'.format(self.result), end='')
 
 
+class PresenceCheck:
+    def __init__(self, name):
+        self.name = name
+        self.state = None
+        self.result = None
+
+    def check(self):
+        if self.state is None:
+            self.result = 'FAIL: not present'
+            return False, self.result
+        else:
+            self.result = 'OK: is present'
+            return True, self.result
+
+    def table_print(self, with_results):
+        print('CONFIG_{:<84}'.format(self.name + ' is present'), end='')
+        if with_results:
+            print('|   {}'.format(self.result), end='')
+
+
 class ComplexOptCheck:
     def __init__(self, *opts):
         self.opts = opts
@@ -458,7 +478,7 @@ def construct_checklist(checklist, arch):
     checklist.append(OptCheck('X86_MSR',                  'is not set', 'clipos', 'cut_attack_surface')) # refers to LOCKDOWN
     checklist.append(OptCheck('X86_CPUID',                'is not set', 'clipos', 'cut_attack_surface'))
     checklist.append(AND(OptCheck('LDISC_AUTOLOAD',           'is not set', 'clipos', 'cut_attack_surface'), \
-                         VerCheck((5, 1)))) # LDISC_AUTOLOAD can be disabled since v5.1
+                         PresenceCheck('LDISC_AUTOLOAD')))
 
     checklist.append(OptCheck('AIO',                  'is not set', 'grapheneos', 'cut_attack_surface'))