X-Git-Url: http://plrg.eecs.uci.edu/git/?a=blobdiff_plain;f=security%2FKconfig;h=d9c9b1f76059af4863c2edfc5672c4fdbe2edc84;hb=5776aafc5bed08447fdb578d19f40159f4981d0c;hp=ddb3e8a8d9bd4cf0ae9c9e77f719c7009035ddda;hpb=25ad2e1898f035267986af949b17fa530d26ec11;p=firefly-linux-kernel-4.4.55.git diff --git a/security/Kconfig b/security/Kconfig index ddb3e8a8d9bd..d9c9b1f76059 100644 --- a/security/Kconfig +++ b/security/Kconfig @@ -18,6 +18,15 @@ config SECURITY_DMESG_RESTRICT If you are unsure how to answer this question, answer N. +config SECURITY_PERF_EVENTS_RESTRICT + bool "Restrict unprivileged use of performance events" + depends on PERF_EVENTS + help + If you say Y here, the kernel.perf_event_paranoid sysctl + will be set to 3 by default, and no unprivileged use of the + perf_event_open syscall will be permitted unless it is + changed. + config SECURITY bool "Enable different security models" depends on SYSFS @@ -136,6 +145,7 @@ config HAVE_ARCH_HARDENED_USERCOPY config HARDENED_USERCOPY bool "Harden memory copies between kernel and userspace" depends on HAVE_ARCH_HARDENED_USERCOPY + depends on HAVE_HARDENED_USERCOPY_ALLOCATOR select BUG help This option checks for obviously wrong memory regions when @@ -163,6 +173,8 @@ source security/tomoyo/Kconfig source security/apparmor/Kconfig source security/yama/Kconfig +source security/optee_linuxdriver/Kconfig + source security/integrity/Kconfig choice