Message ID | 20180718135302.4927-2-joel@jms.id.au (mailing list archive) |
---|---|
State | New, archived |
Headers | show |
On Wed, 18 Jul 2018, at 23:23, Joel Stanley wrote: > - Increase kernel log buffer size > > - Enable security related features: > SLAB_FREELIST_RANDOM > STRICT_KERNEL_RW > CC_STACKPROTECTOR_STRONG > HARDENED_USERCOPY > FORTIFY_SOURCE > > - Enable new support: > hardware random number generator > FSI and client drivers > DRM GFX driver > > - Disable unwanted features: > ARM_APPENDED_DTB > ARM_ATAG_DTB_COMPAT > BLK_DEV_RAM > > - Sync G4 and G5 with OpenBMC configurations > BLK_DEV_LOOP, for updater mechanic > CRYPTO_HMAC, for libsdbus features > CRYPTO_SHA256 > CRYPTO_USER_API_HASH > > Signed-off-by: Joel Stanley <joel@jms.id.au> Reviewed-by: Andrew Jeffery <andrew@aj.id.au> > --- > arch/arm/configs/aspeed_g4_defconfig | 94 +++++++++++++++++++++----- > arch/arm/configs/aspeed_g5_defconfig | 98 ++++++++++++++++++++++------ > 2 files changed, 157 insertions(+), 35 deletions(-) > > diff --git a/arch/arm/configs/aspeed_g4_defconfig b/arch/arm/configs/ > aspeed_g4_defconfig > index be714ea088ed..39d3deeccbf4 100644 > --- a/arch/arm/configs/aspeed_g4_defconfig > +++ b/arch/arm/configs/aspeed_g4_defconfig > @@ -3,30 +3,39 @@ CONFIG_KERNEL_XZ=y > CONFIG_SYSVIPC=y > CONFIG_NO_HZ_IDLE=y > CONFIG_HIGH_RES_TIMERS=y > -CONFIG_LOG_BUF_SHIFT=14 > +CONFIG_IKCONFIG=y > +CONFIG_IKCONFIG_PROC=y > +CONFIG_LOG_BUF_SHIFT=16 > CONFIG_CGROUPS=y > CONFIG_BLK_DEV_INITRD=y > # CONFIG_RD_BZIP2 is not set > # CONFIG_RD_LZO is not set > # CONFIG_RD_LZ4 is not set > -CONFIG_KALLSYMS_ALL=y > -CONFIG_BPF_SYSCALL=y > +# CONFIG_UID16 is not set > +# CONFIG_SYSFS_SYSCALL is not set > # CONFIG_AIO is not set > +CONFIG_BPF_SYSCALL=y > CONFIG_EMBEDDED=y > +CONFIG_PERF_EVENTS=y > # CONFIG_COMPAT_BRK is not set > CONFIG_SLAB=y > +CONFIG_SLAB_FREELIST_RANDOM=y > CONFIG_JUMP_LABEL=y > +CONFIG_STRICT_KERNEL_RWX=y > CONFIG_GCC_PLUGINS=y > -CONFIG_MODULES=y > -CONFIG_MODULE_UNLOAD=y > # CONFIG_LBDAF is not set > +# CONFIG_BLK_DEV_BSG is not set > +# CONFIG_BLK_DEBUG_FS is not set > +# CONFIG_IOSCHED_DEADLINE is not set > +# CONFIG_MQ_IOSCHED_DEADLINE is not set > +# CONFIG_MQ_IOSCHED_KYBER is not set > # CONFIG_ARCH_MULTI_V7 is not set > CONFIG_ARCH_ASPEED=y > CONFIG_MACH_ASPEED_G4=y > CONFIG_VMSPLIT_2G=y > CONFIG_AEABI=y > -# CONFIG_CPU_SW_DOMAIN_PAN is not set > # CONFIG_COMPACTION is not set > +CONFIG_UACCESS_WITH_MEMCPY=y > CONFIG_SECCOMP=y > # CONFIG_ATAGS is not set > CONFIG_ZBOOT_ROM_TEXT=0x0 > @@ -47,8 +56,14 @@ CONFIG_SYN_COOKIES=y > # CONFIG_INET_XFRM_MODE_TUNNEL is not set > # CONFIG_INET_XFRM_MODE_BEET is not set > # CONFIG_INET_DIAG is not set > -# CONFIG_IPV6 is not set > +# CONFIG_INET6_XFRM_MODE_TRANSPORT is not set > +# CONFIG_INET6_XFRM_MODE_TUNNEL is not set > +# CONFIG_INET6_XFRM_MODE_BEET is not set > +CONFIG_NETFILTER=y > +# CONFIG_NETFILTER_ADVANCED is not set > +CONFIG_VLAN_8021Q=y > CONFIG_NET_NCSI=y > +CONFIG_BPF_STREAM_PARSER=y > # CONFIG_WIRELESS is not set > CONFIG_UEVENT_HELPER_PATH="/sbin/hotplug" > CONFIG_DEVTMPFS=y > @@ -58,11 +73,12 @@ CONFIG_MTD=y > CONFIG_MTD_BLOCK=y > CONFIG_MTD_PARTITIONED_MASTER=y > CONFIG_MTD_SPI_NOR=y > +# CONFIG_MTD_SPI_NOR_USE_4K_SECTORS is not set > CONFIG_SPI_ASPEED_SMC=y > CONFIG_MTD_UBI=y > CONFIG_MTD_UBI_FASTMAP=y > CONFIG_MTD_UBI_BLOCK=y > -CONFIG_BLK_DEV_RAM=y > +CONFIG_BLK_DEV_LOOP=y > CONFIG_ASPEED_LPC_CTRL=y > CONFIG_ASPEED_LPC_SNOOP=y > CONFIG_EEPROM_AT24=y > @@ -70,18 +86,26 @@ CONFIG_NETDEVICES=y > CONFIG_NETCONSOLE=y > # CONFIG_NET_VENDOR_ALACRITECH is not set > # CONFIG_NET_VENDOR_AMAZON is not set > +# CONFIG_NET_VENDOR_AQUANTIA is not set > # CONFIG_NET_VENDOR_ARC is not set > -# CONFIG_NET_CADENCE is not set > +# CONFIG_NET_VENDOR_AURORA is not set > # CONFIG_NET_VENDOR_BROADCOM is not set > +# CONFIG_NET_VENDOR_CADENCE is not set > +# CONFIG_NET_VENDOR_CAVIUM is not set > # CONFIG_NET_VENDOR_CIRRUS is not set > +# CONFIG_NET_VENDOR_CORTINA is not set > # CONFIG_NET_VENDOR_EZCHIP is not set > CONFIG_FTGMAC100=y > # CONFIG_NET_VENDOR_HISILICON is not set > +# CONFIG_NET_VENDOR_HUAWEI is not set > # CONFIG_NET_VENDOR_INTEL is not set > # CONFIG_NET_VENDOR_MARVELL is not set > +# CONFIG_NET_VENDOR_MELLANOX is not set > # CONFIG_NET_VENDOR_MICREL is not set > +# CONFIG_NET_VENDOR_MICROSEMI is not set > # CONFIG_NET_VENDOR_NATSEMI is not set > # CONFIG_NET_VENDOR_NETRONOME is not set > +# CONFIG_NET_VENDOR_NI is not set > # CONFIG_NET_VENDOR_QUALCOMM is not set > # CONFIG_NET_VENDOR_RENESAS is not set > # CONFIG_NET_VENDOR_ROCKER is not set > @@ -89,13 +113,20 @@ CONFIG_FTGMAC100=y > # CONFIG_NET_VENDOR_SEEQ is not set > # CONFIG_NET_VENDOR_SOLARFLARE is not set > # CONFIG_NET_VENDOR_SMSC is not set > +# CONFIG_NET_VENDOR_SOCIONEXT is not set > # CONFIG_NET_VENDOR_STMICRO is not set > +# CONFIG_NET_VENDOR_SYNOPSYS is not set > # CONFIG_NET_VENDOR_VIA is not set > # CONFIG_NET_VENDOR_WIZNET is not set > CONFIG_BROADCOM_PHY=y > CONFIG_REALTEK_PHY=y > +# CONFIG_USB_NET_DRIVERS is not set > # CONFIG_WLAN is not set > -# CONFIG_INPUT is not set > +CONFIG_INPUT_EVDEV=y > +# CONFIG_KEYBOARD_ATKBD is not set > +CONFIG_KEYBOARD_GPIO=y > +CONFIG_KEYBOARD_GPIO_POLLED=y > +# CONFIG_INPUT_MOUSE is not set > # CONFIG_SERIO is not set > # CONFIG_VT is not set > # CONFIG_LEGACY_PTYS is not set > @@ -108,9 +139,9 @@ CONFIG_SERIAL_8250_EXTENDED=y > CONFIG_SERIAL_8250_ASPEED_VUART=y > CONFIG_SERIAL_8250_SHARE_IRQ=y > CONFIG_SERIAL_OF_PLATFORM=y > +CONFIG_ASPEED_KCS_IPMI_BMC=y > CONFIG_ASPEED_BT_IPMI_BMC=y > -# CONFIG_HW_RANDOM is not set > -CONFIG_I2C=y > +CONFIG_HW_RANDOM_TIMERIOMEM=y > # CONFIG_I2C_COMPAT is not set > CONFIG_I2C_CHARDEV=y > CONFIG_I2C_MUX=y > @@ -129,9 +160,16 @@ CONFIG_SENSORS_LM75=y > CONFIG_SENSORS_NCT7904=y > CONFIG_PMBUS=y > CONFIG_SENSORS_ADM1275=y > +CONFIG_SENSORS_IBM_CFFPS=y > +CONFIG_SENSORS_IR35221=y > CONFIG_SENSORS_LM25066=y > +CONFIG_SENSORS_MAX31785=y > CONFIG_SENSORS_UCD9000=y > +CONFIG_SENSORS_UCD9200=y > CONFIG_SENSORS_TMP421=y > +CONFIG_SENSORS_W83773G=y > +CONFIG_WATCHDOG_SYSFS=y > +CONFIG_DRM=y > CONFIG_USB=y > CONFIG_USB_ANNOUNCE_NEW_DEVICES=y > CONFIG_USB_DYNAMIC_MINORS=y > @@ -159,6 +197,8 @@ CONFIG_NEW_LEDS=y > CONFIG_LEDS_CLASS=y > CONFIG_LEDS_CLASS_FLASH=y > CONFIG_LEDS_GPIO=y > +CONFIG_LEDS_PCA955X=y > +CONFIG_LEDS_PCA955X_GPIO=y > CONFIG_LEDS_TRIGGERS=y > CONFIG_LEDS_TRIGGER_TIMER=y > CONFIG_LEDS_TRIGGER_HEARTBEAT=y > @@ -167,33 +207,55 @@ CONFIG_RTC_CLASS=y > CONFIG_RTC_DRV_DS1307=y > CONFIG_RTC_DRV_PCF8523=y > CONFIG_RTC_DRV_RV8803=y > -CONFIG_MAILBOX=y > +# CONFIG_VIRTIO_MENU is not set > # CONFIG_IOMMU_SUPPORT is not set > CONFIG_IIO=y > CONFIG_ASPEED_ADC=y > +CONFIG_MAX1363=y > CONFIG_BMP280=y > +CONFIG_FSI=y > +CONFIG_FSI_MASTER_GPIO=y > +CONFIG_FSI_MASTER_HUB=y > +CONFIG_FSI_SCOM=y > +CONFIG_FSI_SBEFIFO=y > CONFIG_FIRMWARE_MEMMAP=y > CONFIG_FANOTIFY=y > CONFIG_OVERLAY_FS=y > CONFIG_TMPFS=y > CONFIG_JFFS2_FS=y > +# CONFIG_JFFS2_FS_WRITEBUFFER is not set > CONFIG_JFFS2_SUMMARY=y > CONFIG_JFFS2_FS_XATTR=y > CONFIG_UBIFS_FS=y > CONFIG_SQUASHFS=y > CONFIG_SQUASHFS_XZ=y > +CONFIG_SQUASHFS_ZSTD=y > +# CONFIG_NETWORK_FILESYSTEMS is not set > CONFIG_PRINTK_TIME=y > CONFIG_DYNAMIC_DEBUG=y > +CONFIG_DEBUG_INFO=y > +CONFIG_DEBUG_INFO_REDUCED=y > +CONFIG_DEBUG_INFO_DWARF4=y > +CONFIG_GDB_SCRIPTS=y > CONFIG_STRIP_ASM_SYMS=y > -CONFIG_DEBUG_FS=y > +CONFIG_SOFTLOCKUP_DETECTOR=y > +# CONFIG_DETECT_HUNG_TASK is not set > CONFIG_WQ_WATCHDOG=y > +CONFIG_PANIC_ON_OOPS=y > CONFIG_PANIC_TIMEOUT=-1 > # CONFIG_SCHED_DEBUG is not set > CONFIG_SCHED_STACK_END_CHECK=y > -CONFIG_STACKTRACE=y > -# CONFIG_FTRACE is not set > +CONFIG_FUNCTION_TRACER=y > +# CONFIG_TRACING_EVENTS_GPIO is not set > +# CONFIG_RUNTIME_TESTING_MENU is not set > +CONFIG_DEBUG_WX=y > CONFIG_DEBUG_USER=y > +CONFIG_HARDENED_USERCOPY=y > +CONFIG_FORTIFY_SOURCE=y > # CONFIG_CRYPTO_ECHAINIV is not set > +CONFIG_CRYPTO_HMAC=y > +CONFIG_CRYPTO_SHA256=y > +CONFIG_CRYPTO_USER_API_HASH=y > # CONFIG_CRYPTO_HW is not set > # CONFIG_XZ_DEC_X86 is not set > # CONFIG_XZ_DEC_POWERPC is not set > diff --git a/arch/arm/configs/aspeed_g5_defconfig b/arch/arm/configs/ > aspeed_g5_defconfig > index 38e9b2d43df3..2d7d715b239f 100644 > --- a/arch/arm/configs/aspeed_g5_defconfig > +++ b/arch/arm/configs/aspeed_g5_defconfig > @@ -3,40 +3,47 @@ CONFIG_KERNEL_XZ=y > CONFIG_SYSVIPC=y > CONFIG_NO_HZ_IDLE=y > CONFIG_HIGH_RES_TIMERS=y > -CONFIG_LOG_BUF_SHIFT=14 > +CONFIG_IKCONFIG=y > +CONFIG_IKCONFIG_PROC=y > +CONFIG_LOG_BUF_SHIFT=16 > CONFIG_CGROUPS=y > CONFIG_BLK_DEV_INITRD=y > # CONFIG_RD_BZIP2 is not set > # CONFIG_RD_LZO is not set > # CONFIG_RD_LZ4 is not set > -CONFIG_KALLSYMS_ALL=y > -CONFIG_BPF_SYSCALL=y > +# CONFIG_UID16 is not set > +# CONFIG_SYSFS_SYSCALL is not set > # CONFIG_AIO is not set > +CONFIG_BPF_SYSCALL=y > CONFIG_EMBEDDED=y > +CONFIG_PERF_EVENTS=y > # CONFIG_COMPAT_BRK is not set > CONFIG_SLAB=y > +CONFIG_SLAB_FREELIST_RANDOM=y > CONFIG_JUMP_LABEL=y > +CONFIG_STRICT_KERNEL_RWX=y > CONFIG_GCC_PLUGINS=y > -CONFIG_MODULES=y > -CONFIG_MODULE_UNLOAD=y > # CONFIG_LBDAF is not set > +# CONFIG_BLK_DEV_BSG is not set > +# CONFIG_BLK_DEBUG_FS is not set > +# CONFIG_IOSCHED_DEADLINE is not set > +# CONFIG_MQ_IOSCHED_DEADLINE is not set > +# CONFIG_MQ_IOSCHED_KYBER is not set > CONFIG_ARCH_MULTI_V6=y > # CONFIG_ARCH_MULTI_V7 is not set > CONFIG_ARCH_ASPEED=y > CONFIG_MACH_ASPEED_G5=y > # CONFIG_CACHE_L2X0 is not set > CONFIG_VMSPLIT_2G=y > -CONFIG_AEABI=y > -# CONFIG_CPU_SW_DOMAIN_PAN is not set > # CONFIG_COMPACTION is not set > +CONFIG_UACCESS_WITH_MEMCPY=y > CONFIG_SECCOMP=y > # CONFIG_ATAGS is not set > CONFIG_ZBOOT_ROM_TEXT=0x0 > CONFIG_ZBOOT_ROM_BSS=0x0 > -CONFIG_ARM_APPENDED_DTB=y > -CONFIG_ARM_ATAG_DTB_COMPAT=y > CONFIG_KEXEC=y > # CONFIG_CORE_DUMP_DEFAULT_ELF_HEADERS is not set > +# CONFIG_SUSPEND is not set > CONFIG_NET=y > CONFIG_PACKET=y > CONFIG_PACKET_DIAG=y > @@ -49,8 +56,14 @@ CONFIG_SYN_COOKIES=y > # CONFIG_INET_XFRM_MODE_TUNNEL is not set > # CONFIG_INET_XFRM_MODE_BEET is not set > # CONFIG_INET_DIAG is not set > -# CONFIG_IPV6 is not set > +# CONFIG_INET6_XFRM_MODE_TRANSPORT is not set > +# CONFIG_INET6_XFRM_MODE_TUNNEL is not set > +# CONFIG_INET6_XFRM_MODE_BEET is not set > +CONFIG_NETFILTER=y > +# CONFIG_NETFILTER_ADVANCED is not set > +CONFIG_VLAN_8021Q=y > CONFIG_NET_NCSI=y > +CONFIG_BPF_STREAM_PARSER=y > # CONFIG_WIRELESS is not set > CONFIG_UEVENT_HELPER_PATH="/sbin/hotplug" > CONFIG_DEVTMPFS=y > @@ -60,11 +73,12 @@ CONFIG_MTD=y > CONFIG_MTD_BLOCK=y > CONFIG_MTD_PARTITIONED_MASTER=y > CONFIG_MTD_SPI_NOR=y > +# CONFIG_MTD_SPI_NOR_USE_4K_SECTORS is not set > CONFIG_SPI_ASPEED_SMC=y > CONFIG_MTD_UBI=y > CONFIG_MTD_UBI_FASTMAP=y > CONFIG_MTD_UBI_BLOCK=y > -CONFIG_BLK_DEV_RAM=y > +CONFIG_BLK_DEV_LOOP=y > CONFIG_ASPEED_LPC_CTRL=y > CONFIG_ASPEED_LPC_SNOOP=y > CONFIG_EEPROM_AT24=y > @@ -72,18 +86,26 @@ CONFIG_NETDEVICES=y > CONFIG_NETCONSOLE=y > # CONFIG_NET_VENDOR_ALACRITECH is not set > # CONFIG_NET_VENDOR_AMAZON is not set > +# CONFIG_NET_VENDOR_AQUANTIA is not set > # CONFIG_NET_VENDOR_ARC is not set > -# CONFIG_NET_CADENCE is not set > +# CONFIG_NET_VENDOR_AURORA is not set > # CONFIG_NET_VENDOR_BROADCOM is not set > +# CONFIG_NET_VENDOR_CADENCE is not set > +# CONFIG_NET_VENDOR_CAVIUM is not set > # CONFIG_NET_VENDOR_CIRRUS is not set > +# CONFIG_NET_VENDOR_CORTINA is not set > # CONFIG_NET_VENDOR_EZCHIP is not set > CONFIG_FTGMAC100=y > # CONFIG_NET_VENDOR_HISILICON is not set > +# CONFIG_NET_VENDOR_HUAWEI is not set > # CONFIG_NET_VENDOR_INTEL is not set > # CONFIG_NET_VENDOR_MARVELL is not set > +# CONFIG_NET_VENDOR_MELLANOX is not set > # CONFIG_NET_VENDOR_MICREL is not set > +# CONFIG_NET_VENDOR_MICROSEMI is not set > # CONFIG_NET_VENDOR_NATSEMI is not set > # CONFIG_NET_VENDOR_NETRONOME is not set > +# CONFIG_NET_VENDOR_NI is not set > # CONFIG_NET_VENDOR_QUALCOMM is not set > # CONFIG_NET_VENDOR_RENESAS is not set > # CONFIG_NET_VENDOR_ROCKER is not set > @@ -91,13 +113,20 @@ CONFIG_FTGMAC100=y > # CONFIG_NET_VENDOR_SEEQ is not set > # CONFIG_NET_VENDOR_SOLARFLARE is not set > # CONFIG_NET_VENDOR_SMSC is not set > +# CONFIG_NET_VENDOR_SOCIONEXT is not set > # CONFIG_NET_VENDOR_STMICRO is not set > +# CONFIG_NET_VENDOR_SYNOPSYS is not set > # CONFIG_NET_VENDOR_VIA is not set > # CONFIG_NET_VENDOR_WIZNET is not set > CONFIG_BROADCOM_PHY=y > CONFIG_REALTEK_PHY=y > +# CONFIG_USB_NET_DRIVERS is not set > # CONFIG_WLAN is not set > -# CONFIG_INPUT is not set > +CONFIG_INPUT_EVDEV=y > +# CONFIG_KEYBOARD_ATKBD is not set > +CONFIG_KEYBOARD_GPIO=y > +CONFIG_KEYBOARD_GPIO_POLLED=y > +# CONFIG_INPUT_MOUSE is not set > # CONFIG_SERIO is not set > # CONFIG_VT is not set > # CONFIG_LEGACY_PTYS is not set > @@ -110,9 +139,9 @@ CONFIG_SERIAL_8250_EXTENDED=y > CONFIG_SERIAL_8250_ASPEED_VUART=y > CONFIG_SERIAL_8250_SHARE_IRQ=y > CONFIG_SERIAL_OF_PLATFORM=y > +CONFIG_ASPEED_KCS_IPMI_BMC=y > CONFIG_ASPEED_BT_IPMI_BMC=y > -# CONFIG_HW_RANDOM is not set > -CONFIG_I2C=y > +CONFIG_HW_RANDOM_TIMERIOMEM=y > # CONFIG_I2C_COMPAT is not set > CONFIG_I2C_CHARDEV=y > CONFIG_I2C_MUX=y > @@ -131,9 +160,16 @@ CONFIG_SENSORS_LM75=y > CONFIG_SENSORS_NCT7904=y > CONFIG_PMBUS=y > CONFIG_SENSORS_ADM1275=y > +CONFIG_SENSORS_IBM_CFFPS=y > +CONFIG_SENSORS_IR35221=y > CONFIG_SENSORS_LM25066=y > +CONFIG_SENSORS_MAX31785=y > CONFIG_SENSORS_UCD9000=y > +CONFIG_SENSORS_UCD9200=y > CONFIG_SENSORS_TMP421=y > +CONFIG_SENSORS_W83773G=y > +CONFIG_WATCHDOG_SYSFS=y > +CONFIG_DRM=y > CONFIG_USB=y > CONFIG_USB_ANNOUNCE_NEW_DEVICES=y > CONFIG_USB_DYNAMIC_MINORS=y > @@ -161,6 +197,8 @@ CONFIG_NEW_LEDS=y > CONFIG_LEDS_CLASS=y > CONFIG_LEDS_CLASS_FLASH=y > CONFIG_LEDS_GPIO=y > +CONFIG_LEDS_PCA955X=y > +CONFIG_LEDS_PCA955X_GPIO=y > CONFIG_LEDS_TRIGGERS=y > CONFIG_LEDS_TRIGGER_TIMER=y > CONFIG_LEDS_TRIGGER_HEARTBEAT=y > @@ -169,33 +207,55 @@ CONFIG_RTC_CLASS=y > CONFIG_RTC_DRV_DS1307=y > CONFIG_RTC_DRV_PCF8523=y > CONFIG_RTC_DRV_RV8803=y > -CONFIG_MAILBOX=y > +# CONFIG_VIRTIO_MENU is not set > # CONFIG_IOMMU_SUPPORT is not set > CONFIG_IIO=y > CONFIG_ASPEED_ADC=y > +CONFIG_MAX1363=y > CONFIG_BMP280=y > +CONFIG_FSI=y > +CONFIG_FSI_MASTER_GPIO=y > +CONFIG_FSI_MASTER_HUB=y > +CONFIG_FSI_SCOM=y > +CONFIG_FSI_SBEFIFO=y > CONFIG_FIRMWARE_MEMMAP=y > CONFIG_FANOTIFY=y > CONFIG_OVERLAY_FS=y > CONFIG_TMPFS=y > CONFIG_JFFS2_FS=y > +# CONFIG_JFFS2_FS_WRITEBUFFER is not set > CONFIG_JFFS2_SUMMARY=y > CONFIG_JFFS2_FS_XATTR=y > CONFIG_UBIFS_FS=y > CONFIG_SQUASHFS=y > CONFIG_SQUASHFS_XZ=y > +CONFIG_SQUASHFS_ZSTD=y > +# CONFIG_NETWORK_FILESYSTEMS is not set > CONFIG_PRINTK_TIME=y > CONFIG_DYNAMIC_DEBUG=y > +CONFIG_DEBUG_INFO=y > +CONFIG_DEBUG_INFO_REDUCED=y > +CONFIG_DEBUG_INFO_DWARF4=y > +CONFIG_GDB_SCRIPTS=y > CONFIG_STRIP_ASM_SYMS=y > -CONFIG_DEBUG_FS=y > +CONFIG_SOFTLOCKUP_DETECTOR=y > +# CONFIG_DETECT_HUNG_TASK is not set > CONFIG_WQ_WATCHDOG=y > +CONFIG_PANIC_ON_OOPS=y > CONFIG_PANIC_TIMEOUT=-1 > # CONFIG_SCHED_DEBUG is not set > CONFIG_SCHED_STACK_END_CHECK=y > -CONFIG_STACKTRACE=y > -# CONFIG_FTRACE is not set > +CONFIG_FUNCTION_TRACER=y > +# CONFIG_TRACING_EVENTS_GPIO is not set > +# CONFIG_RUNTIME_TESTING_MENU is not set > +CONFIG_DEBUG_WX=y > CONFIG_DEBUG_USER=y > +CONFIG_HARDENED_USERCOPY=y > +CONFIG_FORTIFY_SOURCE=y > # CONFIG_CRYPTO_ECHAINIV is not set > +CONFIG_CRYPTO_HMAC=y > +CONFIG_CRYPTO_SHA256=y > +CONFIG_CRYPTO_USER_API_HASH=y > # CONFIG_CRYPTO_HW is not set > # CONFIG_XZ_DEC_X86 is not set > # CONFIG_XZ_DEC_POWERPC is not set > -- > 2.17.1 >
diff --git a/arch/arm/configs/aspeed_g4_defconfig b/arch/arm/configs/aspeed_g4_defconfig index be714ea088ed..39d3deeccbf4 100644 --- a/arch/arm/configs/aspeed_g4_defconfig +++ b/arch/arm/configs/aspeed_g4_defconfig @@ -3,30 +3,39 @@ CONFIG_KERNEL_XZ=y CONFIG_SYSVIPC=y CONFIG_NO_HZ_IDLE=y CONFIG_HIGH_RES_TIMERS=y -CONFIG_LOG_BUF_SHIFT=14 +CONFIG_IKCONFIG=y +CONFIG_IKCONFIG_PROC=y +CONFIG_LOG_BUF_SHIFT=16 CONFIG_CGROUPS=y CONFIG_BLK_DEV_INITRD=y # CONFIG_RD_BZIP2 is not set # CONFIG_RD_LZO is not set # CONFIG_RD_LZ4 is not set -CONFIG_KALLSYMS_ALL=y -CONFIG_BPF_SYSCALL=y +# CONFIG_UID16 is not set +# CONFIG_SYSFS_SYSCALL is not set # CONFIG_AIO is not set +CONFIG_BPF_SYSCALL=y CONFIG_EMBEDDED=y +CONFIG_PERF_EVENTS=y # CONFIG_COMPAT_BRK is not set CONFIG_SLAB=y +CONFIG_SLAB_FREELIST_RANDOM=y CONFIG_JUMP_LABEL=y +CONFIG_STRICT_KERNEL_RWX=y CONFIG_GCC_PLUGINS=y -CONFIG_MODULES=y -CONFIG_MODULE_UNLOAD=y # CONFIG_LBDAF is not set +# CONFIG_BLK_DEV_BSG is not set +# CONFIG_BLK_DEBUG_FS is not set +# CONFIG_IOSCHED_DEADLINE is not set +# CONFIG_MQ_IOSCHED_DEADLINE is not set +# CONFIG_MQ_IOSCHED_KYBER is not set # CONFIG_ARCH_MULTI_V7 is not set CONFIG_ARCH_ASPEED=y CONFIG_MACH_ASPEED_G4=y CONFIG_VMSPLIT_2G=y CONFIG_AEABI=y -# CONFIG_CPU_SW_DOMAIN_PAN is not set # CONFIG_COMPACTION is not set +CONFIG_UACCESS_WITH_MEMCPY=y CONFIG_SECCOMP=y # CONFIG_ATAGS is not set CONFIG_ZBOOT_ROM_TEXT=0x0 @@ -47,8 +56,14 @@ CONFIG_SYN_COOKIES=y # CONFIG_INET_XFRM_MODE_TUNNEL is not set # CONFIG_INET_XFRM_MODE_BEET is not set # CONFIG_INET_DIAG is not set -# CONFIG_IPV6 is not set +# CONFIG_INET6_XFRM_MODE_TRANSPORT is not set +# CONFIG_INET6_XFRM_MODE_TUNNEL is not set +# CONFIG_INET6_XFRM_MODE_BEET is not set +CONFIG_NETFILTER=y +# CONFIG_NETFILTER_ADVANCED is not set +CONFIG_VLAN_8021Q=y CONFIG_NET_NCSI=y +CONFIG_BPF_STREAM_PARSER=y # CONFIG_WIRELESS is not set CONFIG_UEVENT_HELPER_PATH="/sbin/hotplug" CONFIG_DEVTMPFS=y @@ -58,11 +73,12 @@ CONFIG_MTD=y CONFIG_MTD_BLOCK=y CONFIG_MTD_PARTITIONED_MASTER=y CONFIG_MTD_SPI_NOR=y +# CONFIG_MTD_SPI_NOR_USE_4K_SECTORS is not set CONFIG_SPI_ASPEED_SMC=y CONFIG_MTD_UBI=y CONFIG_MTD_UBI_FASTMAP=y CONFIG_MTD_UBI_BLOCK=y -CONFIG_BLK_DEV_RAM=y +CONFIG_BLK_DEV_LOOP=y CONFIG_ASPEED_LPC_CTRL=y CONFIG_ASPEED_LPC_SNOOP=y CONFIG_EEPROM_AT24=y @@ -70,18 +86,26 @@ CONFIG_NETDEVICES=y CONFIG_NETCONSOLE=y # CONFIG_NET_VENDOR_ALACRITECH is not set # CONFIG_NET_VENDOR_AMAZON is not set +# CONFIG_NET_VENDOR_AQUANTIA is not set # CONFIG_NET_VENDOR_ARC is not set -# CONFIG_NET_CADENCE is not set +# CONFIG_NET_VENDOR_AURORA is not set # CONFIG_NET_VENDOR_BROADCOM is not set +# CONFIG_NET_VENDOR_CADENCE is not set +# CONFIG_NET_VENDOR_CAVIUM is not set # CONFIG_NET_VENDOR_CIRRUS is not set +# CONFIG_NET_VENDOR_CORTINA is not set # CONFIG_NET_VENDOR_EZCHIP is not set CONFIG_FTGMAC100=y # CONFIG_NET_VENDOR_HISILICON is not set +# CONFIG_NET_VENDOR_HUAWEI is not set # CONFIG_NET_VENDOR_INTEL is not set # CONFIG_NET_VENDOR_MARVELL is not set +# CONFIG_NET_VENDOR_MELLANOX is not set # CONFIG_NET_VENDOR_MICREL is not set +# CONFIG_NET_VENDOR_MICROSEMI is not set # CONFIG_NET_VENDOR_NATSEMI is not set # CONFIG_NET_VENDOR_NETRONOME is not set +# CONFIG_NET_VENDOR_NI is not set # CONFIG_NET_VENDOR_QUALCOMM is not set # CONFIG_NET_VENDOR_RENESAS is not set # CONFIG_NET_VENDOR_ROCKER is not set @@ -89,13 +113,20 @@ CONFIG_FTGMAC100=y # CONFIG_NET_VENDOR_SEEQ is not set # CONFIG_NET_VENDOR_SOLARFLARE is not set # CONFIG_NET_VENDOR_SMSC is not set +# CONFIG_NET_VENDOR_SOCIONEXT is not set # CONFIG_NET_VENDOR_STMICRO is not set +# CONFIG_NET_VENDOR_SYNOPSYS is not set # CONFIG_NET_VENDOR_VIA is not set # CONFIG_NET_VENDOR_WIZNET is not set CONFIG_BROADCOM_PHY=y CONFIG_REALTEK_PHY=y +# CONFIG_USB_NET_DRIVERS is not set # CONFIG_WLAN is not set -# CONFIG_INPUT is not set +CONFIG_INPUT_EVDEV=y +# CONFIG_KEYBOARD_ATKBD is not set +CONFIG_KEYBOARD_GPIO=y +CONFIG_KEYBOARD_GPIO_POLLED=y +# CONFIG_INPUT_MOUSE is not set # CONFIG_SERIO is not set # CONFIG_VT is not set # CONFIG_LEGACY_PTYS is not set @@ -108,9 +139,9 @@ CONFIG_SERIAL_8250_EXTENDED=y CONFIG_SERIAL_8250_ASPEED_VUART=y CONFIG_SERIAL_8250_SHARE_IRQ=y CONFIG_SERIAL_OF_PLATFORM=y +CONFIG_ASPEED_KCS_IPMI_BMC=y CONFIG_ASPEED_BT_IPMI_BMC=y -# CONFIG_HW_RANDOM is not set -CONFIG_I2C=y +CONFIG_HW_RANDOM_TIMERIOMEM=y # CONFIG_I2C_COMPAT is not set CONFIG_I2C_CHARDEV=y CONFIG_I2C_MUX=y @@ -129,9 +160,16 @@ CONFIG_SENSORS_LM75=y CONFIG_SENSORS_NCT7904=y CONFIG_PMBUS=y CONFIG_SENSORS_ADM1275=y +CONFIG_SENSORS_IBM_CFFPS=y +CONFIG_SENSORS_IR35221=y CONFIG_SENSORS_LM25066=y +CONFIG_SENSORS_MAX31785=y CONFIG_SENSORS_UCD9000=y +CONFIG_SENSORS_UCD9200=y CONFIG_SENSORS_TMP421=y +CONFIG_SENSORS_W83773G=y +CONFIG_WATCHDOG_SYSFS=y +CONFIG_DRM=y CONFIG_USB=y CONFIG_USB_ANNOUNCE_NEW_DEVICES=y CONFIG_USB_DYNAMIC_MINORS=y @@ -159,6 +197,8 @@ CONFIG_NEW_LEDS=y CONFIG_LEDS_CLASS=y CONFIG_LEDS_CLASS_FLASH=y CONFIG_LEDS_GPIO=y +CONFIG_LEDS_PCA955X=y +CONFIG_LEDS_PCA955X_GPIO=y CONFIG_LEDS_TRIGGERS=y CONFIG_LEDS_TRIGGER_TIMER=y CONFIG_LEDS_TRIGGER_HEARTBEAT=y @@ -167,33 +207,55 @@ CONFIG_RTC_CLASS=y CONFIG_RTC_DRV_DS1307=y CONFIG_RTC_DRV_PCF8523=y CONFIG_RTC_DRV_RV8803=y -CONFIG_MAILBOX=y +# CONFIG_VIRTIO_MENU is not set # CONFIG_IOMMU_SUPPORT is not set CONFIG_IIO=y CONFIG_ASPEED_ADC=y +CONFIG_MAX1363=y CONFIG_BMP280=y +CONFIG_FSI=y +CONFIG_FSI_MASTER_GPIO=y +CONFIG_FSI_MASTER_HUB=y +CONFIG_FSI_SCOM=y +CONFIG_FSI_SBEFIFO=y CONFIG_FIRMWARE_MEMMAP=y CONFIG_FANOTIFY=y CONFIG_OVERLAY_FS=y CONFIG_TMPFS=y CONFIG_JFFS2_FS=y +# CONFIG_JFFS2_FS_WRITEBUFFER is not set CONFIG_JFFS2_SUMMARY=y CONFIG_JFFS2_FS_XATTR=y CONFIG_UBIFS_FS=y CONFIG_SQUASHFS=y CONFIG_SQUASHFS_XZ=y +CONFIG_SQUASHFS_ZSTD=y +# CONFIG_NETWORK_FILESYSTEMS is not set CONFIG_PRINTK_TIME=y CONFIG_DYNAMIC_DEBUG=y +CONFIG_DEBUG_INFO=y +CONFIG_DEBUG_INFO_REDUCED=y +CONFIG_DEBUG_INFO_DWARF4=y +CONFIG_GDB_SCRIPTS=y CONFIG_STRIP_ASM_SYMS=y -CONFIG_DEBUG_FS=y +CONFIG_SOFTLOCKUP_DETECTOR=y +# CONFIG_DETECT_HUNG_TASK is not set CONFIG_WQ_WATCHDOG=y +CONFIG_PANIC_ON_OOPS=y CONFIG_PANIC_TIMEOUT=-1 # CONFIG_SCHED_DEBUG is not set CONFIG_SCHED_STACK_END_CHECK=y -CONFIG_STACKTRACE=y -# CONFIG_FTRACE is not set +CONFIG_FUNCTION_TRACER=y +# CONFIG_TRACING_EVENTS_GPIO is not set +# CONFIG_RUNTIME_TESTING_MENU is not set +CONFIG_DEBUG_WX=y CONFIG_DEBUG_USER=y +CONFIG_HARDENED_USERCOPY=y +CONFIG_FORTIFY_SOURCE=y # CONFIG_CRYPTO_ECHAINIV is not set +CONFIG_CRYPTO_HMAC=y +CONFIG_CRYPTO_SHA256=y +CONFIG_CRYPTO_USER_API_HASH=y # CONFIG_CRYPTO_HW is not set # CONFIG_XZ_DEC_X86 is not set # CONFIG_XZ_DEC_POWERPC is not set diff --git a/arch/arm/configs/aspeed_g5_defconfig b/arch/arm/configs/aspeed_g5_defconfig index 38e9b2d43df3..2d7d715b239f 100644 --- a/arch/arm/configs/aspeed_g5_defconfig +++ b/arch/arm/configs/aspeed_g5_defconfig @@ -3,40 +3,47 @@ CONFIG_KERNEL_XZ=y CONFIG_SYSVIPC=y CONFIG_NO_HZ_IDLE=y CONFIG_HIGH_RES_TIMERS=y -CONFIG_LOG_BUF_SHIFT=14 +CONFIG_IKCONFIG=y +CONFIG_IKCONFIG_PROC=y +CONFIG_LOG_BUF_SHIFT=16 CONFIG_CGROUPS=y CONFIG_BLK_DEV_INITRD=y # CONFIG_RD_BZIP2 is not set # CONFIG_RD_LZO is not set # CONFIG_RD_LZ4 is not set -CONFIG_KALLSYMS_ALL=y -CONFIG_BPF_SYSCALL=y +# CONFIG_UID16 is not set +# CONFIG_SYSFS_SYSCALL is not set # CONFIG_AIO is not set +CONFIG_BPF_SYSCALL=y CONFIG_EMBEDDED=y +CONFIG_PERF_EVENTS=y # CONFIG_COMPAT_BRK is not set CONFIG_SLAB=y +CONFIG_SLAB_FREELIST_RANDOM=y CONFIG_JUMP_LABEL=y +CONFIG_STRICT_KERNEL_RWX=y CONFIG_GCC_PLUGINS=y -CONFIG_MODULES=y -CONFIG_MODULE_UNLOAD=y # CONFIG_LBDAF is not set +# CONFIG_BLK_DEV_BSG is not set +# CONFIG_BLK_DEBUG_FS is not set +# CONFIG_IOSCHED_DEADLINE is not set +# CONFIG_MQ_IOSCHED_DEADLINE is not set +# CONFIG_MQ_IOSCHED_KYBER is not set CONFIG_ARCH_MULTI_V6=y # CONFIG_ARCH_MULTI_V7 is not set CONFIG_ARCH_ASPEED=y CONFIG_MACH_ASPEED_G5=y # CONFIG_CACHE_L2X0 is not set CONFIG_VMSPLIT_2G=y -CONFIG_AEABI=y -# CONFIG_CPU_SW_DOMAIN_PAN is not set # CONFIG_COMPACTION is not set +CONFIG_UACCESS_WITH_MEMCPY=y CONFIG_SECCOMP=y # CONFIG_ATAGS is not set CONFIG_ZBOOT_ROM_TEXT=0x0 CONFIG_ZBOOT_ROM_BSS=0x0 -CONFIG_ARM_APPENDED_DTB=y -CONFIG_ARM_ATAG_DTB_COMPAT=y CONFIG_KEXEC=y # CONFIG_CORE_DUMP_DEFAULT_ELF_HEADERS is not set +# CONFIG_SUSPEND is not set CONFIG_NET=y CONFIG_PACKET=y CONFIG_PACKET_DIAG=y @@ -49,8 +56,14 @@ CONFIG_SYN_COOKIES=y # CONFIG_INET_XFRM_MODE_TUNNEL is not set # CONFIG_INET_XFRM_MODE_BEET is not set # CONFIG_INET_DIAG is not set -# CONFIG_IPV6 is not set +# CONFIG_INET6_XFRM_MODE_TRANSPORT is not set +# CONFIG_INET6_XFRM_MODE_TUNNEL is not set +# CONFIG_INET6_XFRM_MODE_BEET is not set +CONFIG_NETFILTER=y +# CONFIG_NETFILTER_ADVANCED is not set +CONFIG_VLAN_8021Q=y CONFIG_NET_NCSI=y +CONFIG_BPF_STREAM_PARSER=y # CONFIG_WIRELESS is not set CONFIG_UEVENT_HELPER_PATH="/sbin/hotplug" CONFIG_DEVTMPFS=y @@ -60,11 +73,12 @@ CONFIG_MTD=y CONFIG_MTD_BLOCK=y CONFIG_MTD_PARTITIONED_MASTER=y CONFIG_MTD_SPI_NOR=y +# CONFIG_MTD_SPI_NOR_USE_4K_SECTORS is not set CONFIG_SPI_ASPEED_SMC=y CONFIG_MTD_UBI=y CONFIG_MTD_UBI_FASTMAP=y CONFIG_MTD_UBI_BLOCK=y -CONFIG_BLK_DEV_RAM=y +CONFIG_BLK_DEV_LOOP=y CONFIG_ASPEED_LPC_CTRL=y CONFIG_ASPEED_LPC_SNOOP=y CONFIG_EEPROM_AT24=y @@ -72,18 +86,26 @@ CONFIG_NETDEVICES=y CONFIG_NETCONSOLE=y # CONFIG_NET_VENDOR_ALACRITECH is not set # CONFIG_NET_VENDOR_AMAZON is not set +# CONFIG_NET_VENDOR_AQUANTIA is not set # CONFIG_NET_VENDOR_ARC is not set -# CONFIG_NET_CADENCE is not set +# CONFIG_NET_VENDOR_AURORA is not set # CONFIG_NET_VENDOR_BROADCOM is not set +# CONFIG_NET_VENDOR_CADENCE is not set +# CONFIG_NET_VENDOR_CAVIUM is not set # CONFIG_NET_VENDOR_CIRRUS is not set +# CONFIG_NET_VENDOR_CORTINA is not set # CONFIG_NET_VENDOR_EZCHIP is not set CONFIG_FTGMAC100=y # CONFIG_NET_VENDOR_HISILICON is not set +# CONFIG_NET_VENDOR_HUAWEI is not set # CONFIG_NET_VENDOR_INTEL is not set # CONFIG_NET_VENDOR_MARVELL is not set +# CONFIG_NET_VENDOR_MELLANOX is not set # CONFIG_NET_VENDOR_MICREL is not set +# CONFIG_NET_VENDOR_MICROSEMI is not set # CONFIG_NET_VENDOR_NATSEMI is not set # CONFIG_NET_VENDOR_NETRONOME is not set +# CONFIG_NET_VENDOR_NI is not set # CONFIG_NET_VENDOR_QUALCOMM is not set # CONFIG_NET_VENDOR_RENESAS is not set # CONFIG_NET_VENDOR_ROCKER is not set @@ -91,13 +113,20 @@ CONFIG_FTGMAC100=y # CONFIG_NET_VENDOR_SEEQ is not set # CONFIG_NET_VENDOR_SOLARFLARE is not set # CONFIG_NET_VENDOR_SMSC is not set +# CONFIG_NET_VENDOR_SOCIONEXT is not set # CONFIG_NET_VENDOR_STMICRO is not set +# CONFIG_NET_VENDOR_SYNOPSYS is not set # CONFIG_NET_VENDOR_VIA is not set # CONFIG_NET_VENDOR_WIZNET is not set CONFIG_BROADCOM_PHY=y CONFIG_REALTEK_PHY=y +# CONFIG_USB_NET_DRIVERS is not set # CONFIG_WLAN is not set -# CONFIG_INPUT is not set +CONFIG_INPUT_EVDEV=y +# CONFIG_KEYBOARD_ATKBD is not set +CONFIG_KEYBOARD_GPIO=y +CONFIG_KEYBOARD_GPIO_POLLED=y +# CONFIG_INPUT_MOUSE is not set # CONFIG_SERIO is not set # CONFIG_VT is not set # CONFIG_LEGACY_PTYS is not set @@ -110,9 +139,9 @@ CONFIG_SERIAL_8250_EXTENDED=y CONFIG_SERIAL_8250_ASPEED_VUART=y CONFIG_SERIAL_8250_SHARE_IRQ=y CONFIG_SERIAL_OF_PLATFORM=y +CONFIG_ASPEED_KCS_IPMI_BMC=y CONFIG_ASPEED_BT_IPMI_BMC=y -# CONFIG_HW_RANDOM is not set -CONFIG_I2C=y +CONFIG_HW_RANDOM_TIMERIOMEM=y # CONFIG_I2C_COMPAT is not set CONFIG_I2C_CHARDEV=y CONFIG_I2C_MUX=y @@ -131,9 +160,16 @@ CONFIG_SENSORS_LM75=y CONFIG_SENSORS_NCT7904=y CONFIG_PMBUS=y CONFIG_SENSORS_ADM1275=y +CONFIG_SENSORS_IBM_CFFPS=y +CONFIG_SENSORS_IR35221=y CONFIG_SENSORS_LM25066=y +CONFIG_SENSORS_MAX31785=y CONFIG_SENSORS_UCD9000=y +CONFIG_SENSORS_UCD9200=y CONFIG_SENSORS_TMP421=y +CONFIG_SENSORS_W83773G=y +CONFIG_WATCHDOG_SYSFS=y +CONFIG_DRM=y CONFIG_USB=y CONFIG_USB_ANNOUNCE_NEW_DEVICES=y CONFIG_USB_DYNAMIC_MINORS=y @@ -161,6 +197,8 @@ CONFIG_NEW_LEDS=y CONFIG_LEDS_CLASS=y CONFIG_LEDS_CLASS_FLASH=y CONFIG_LEDS_GPIO=y +CONFIG_LEDS_PCA955X=y +CONFIG_LEDS_PCA955X_GPIO=y CONFIG_LEDS_TRIGGERS=y CONFIG_LEDS_TRIGGER_TIMER=y CONFIG_LEDS_TRIGGER_HEARTBEAT=y @@ -169,33 +207,55 @@ CONFIG_RTC_CLASS=y CONFIG_RTC_DRV_DS1307=y CONFIG_RTC_DRV_PCF8523=y CONFIG_RTC_DRV_RV8803=y -CONFIG_MAILBOX=y +# CONFIG_VIRTIO_MENU is not set # CONFIG_IOMMU_SUPPORT is not set CONFIG_IIO=y CONFIG_ASPEED_ADC=y +CONFIG_MAX1363=y CONFIG_BMP280=y +CONFIG_FSI=y +CONFIG_FSI_MASTER_GPIO=y +CONFIG_FSI_MASTER_HUB=y +CONFIG_FSI_SCOM=y +CONFIG_FSI_SBEFIFO=y CONFIG_FIRMWARE_MEMMAP=y CONFIG_FANOTIFY=y CONFIG_OVERLAY_FS=y CONFIG_TMPFS=y CONFIG_JFFS2_FS=y +# CONFIG_JFFS2_FS_WRITEBUFFER is not set CONFIG_JFFS2_SUMMARY=y CONFIG_JFFS2_FS_XATTR=y CONFIG_UBIFS_FS=y CONFIG_SQUASHFS=y CONFIG_SQUASHFS_XZ=y +CONFIG_SQUASHFS_ZSTD=y +# CONFIG_NETWORK_FILESYSTEMS is not set CONFIG_PRINTK_TIME=y CONFIG_DYNAMIC_DEBUG=y +CONFIG_DEBUG_INFO=y +CONFIG_DEBUG_INFO_REDUCED=y +CONFIG_DEBUG_INFO_DWARF4=y +CONFIG_GDB_SCRIPTS=y CONFIG_STRIP_ASM_SYMS=y -CONFIG_DEBUG_FS=y +CONFIG_SOFTLOCKUP_DETECTOR=y +# CONFIG_DETECT_HUNG_TASK is not set CONFIG_WQ_WATCHDOG=y +CONFIG_PANIC_ON_OOPS=y CONFIG_PANIC_TIMEOUT=-1 # CONFIG_SCHED_DEBUG is not set CONFIG_SCHED_STACK_END_CHECK=y -CONFIG_STACKTRACE=y -# CONFIG_FTRACE is not set +CONFIG_FUNCTION_TRACER=y +# CONFIG_TRACING_EVENTS_GPIO is not set +# CONFIG_RUNTIME_TESTING_MENU is not set +CONFIG_DEBUG_WX=y CONFIG_DEBUG_USER=y +CONFIG_HARDENED_USERCOPY=y +CONFIG_FORTIFY_SOURCE=y # CONFIG_CRYPTO_ECHAINIV is not set +CONFIG_CRYPTO_HMAC=y +CONFIG_CRYPTO_SHA256=y +CONFIG_CRYPTO_USER_API_HASH=y # CONFIG_CRYPTO_HW is not set # CONFIG_XZ_DEC_X86 is not set # CONFIG_XZ_DEC_POWERPC is not set
- Increase kernel log buffer size - Enable security related features: SLAB_FREELIST_RANDOM STRICT_KERNEL_RW CC_STACKPROTECTOR_STRONG HARDENED_USERCOPY FORTIFY_SOURCE - Enable new support: hardware random number generator FSI and client drivers DRM GFX driver - Disable unwanted features: ARM_APPENDED_DTB ARM_ATAG_DTB_COMPAT BLK_DEV_RAM - Sync G4 and G5 with OpenBMC configurations BLK_DEV_LOOP, for updater mechanic CRYPTO_HMAC, for libsdbus features CRYPTO_SHA256 CRYPTO_USER_API_HASH Signed-off-by: Joel Stanley <joel@jms.id.au> --- arch/arm/configs/aspeed_g4_defconfig | 94 +++++++++++++++++++++----- arch/arm/configs/aspeed_g5_defconfig | 98 ++++++++++++++++++++++------ 2 files changed, 157 insertions(+), 35 deletions(-)