From: Alexander Popov Date: Wed, 18 Mar 2020 11:27:17 +0000 (+0300) Subject: IOMMU_SUPPORT is needed for all architectures X-Git-Tag: v0.5.5~11 X-Git-Url: https://jxself.org/git/?a=commitdiff_plain;h=487ad8477e84a23b0aa3ae504c0bd765e38ab909;p=kconfig-hardened-check.git IOMMU_SUPPORT is needed for all architectures --- diff --git a/kconfig-hardened-check.py b/kconfig-hardened-check.py index 5f12249..3b9a254 100755 --- a/kconfig-hardened-check.py +++ b/kconfig-hardened-check.py @@ -238,14 +238,14 @@ def construct_checklist(checklist, arch): checklist.append(OptCheck('GCC_PLUGINS', 'y', 'defconfig', 'self_protection')) checklist.append(OR(OptCheck('REFCOUNT_FULL', 'y', 'defconfig', 'self_protection'), \ VerCheck((5, 5)))) # REFCOUNT_FULL is enabled by default since v5.5 + iommu_support_is_set = OptCheck('IOMMU_SUPPORT', 'y', 'defconfig', 'self_protection') # is needed for mitigating DMA attacks + checklist.append(iommu_support_is_set) if arch == 'X86_64' or arch == 'X86_32': checklist.append(OptCheck('MICROCODE', 'y', 'defconfig', 'self_protection')) # is needed for mitigating CPU bugs checklist.append(OptCheck('RETPOLINE', 'y', 'defconfig', 'self_protection')) checklist.append(OptCheck('X86_SMAP', 'y', 'defconfig', 'self_protection')) checklist.append(OR(OptCheck('X86_UMIP', 'y', 'defconfig', 'self_protection'), \ OptCheck('X86_INTEL_UMIP', 'y', 'defconfig', 'self_protection'))) - iommu_support_is_set = OptCheck('IOMMU_SUPPORT', 'y', 'defconfig', 'self_protection') # is needed for mitigating DMA attacks - checklist.append(iommu_support_is_set) checklist.append(OptCheck('SYN_COOKIES', 'y', 'defconfig', 'self_protection')) # another reason? if arch == 'X86_64': checklist.append(OptCheck('PAGE_TABLE_ISOLATION', 'y', 'defconfig', 'self_protection'))