From: Vitaly Chikunov <vt@altlinux.org> To: ALT Linux kernel packages development <devel-kernel@lists.altlinux.org> Subject: Re: [d-kernel] [PATCH std-def] config: Update some config options Date: Wed, 11 May 2022 20:02:48 +0300 Message-ID: <20220511170248.utoxca4z2zdqxfmz@altlinux.org> (raw) In-Reply-To: <f2b6380a-1dd9-790f-118d-3a3ff01e574d@basealt.ru> On Wed, May 11, 2022 at 12:20:54PM +0300, Nikolai Kostrigin wrote: > Здравствуйте! > > 07.05.2022 21:40, Vitaly Chikunov пишет: > > Based on suggestions from Alexey V. Vissarionov <gremlin@altlinux.org>, > > but not completely following them. All mistakes are mine. > > > > - Mostly - add new hardware support. > > - Disable some legacy stuff. > > - Turn off SHA1 by default. > > - Set panic=60 by default. > > > > Signed-off-by: Vitaly Chikunov <vt@altlinux.org> > > --- > > config | 115 ++++++++++++++++++++++++++++----------------------------- > > 1 file changed, 57 insertions(+), 58 deletions(-) > > > [...] > > -CONFIG_PANIC_TIMEOUT=0 > > +CONFIG_PANIC_TIMEOUT=60 > > CONFIG_LOCKUP_DETECTOR=y > > CONFIG_SOFTLOCKUP_DETECTOR=y > > # CONFIG_BOOTPARAM_SOFTLOCKUP_PANIC is not set > > > Хотелось бы еще внести предложение изменить во всех ядрах (un-def, std-def) > > diff --git a/config b/config > index a41e871016a8..be80ba93c04d 100644 > --- a/config > +++ b/config > @@ -2323,7 +2323,7 @@ CONFIG_UEFI_CPER=y > CONFIG_UEFI_CPER_X86=y > CONFIG_EFI_DEV_PATH_PARSER=y > CONFIG_EFI_EARLYCON=y > -CONFIG_EFI_CUSTOM_SSDT_OVERLAYS=y > +# CONFIG_EFI_CUSTOM_SSDT_OVERLAYS is not set > > # > # Tegra firmware driver > > > ввиду того, что включение этой опции считается потенциальной уязвимостью для > режима UEFI SB [1]. > > "Is kernel upstream commit 75b0cea7bf307f362057cc778efe89af4c615354 present > in your kernel, if you boot chain includes a Linux kernel ? Так у нас этот коммит есть, следовательно угрозы от CONFIG_EFI_CUSTOM_SSDT_OVERLAYS не должно быть? > [...] > > And the configuration setting CONFIG_EFI_CUSTOM_SSDT_OVERLAYS is disabled." > > > [1] https://github.com/rhboot/shim-review/issues/233 > > -- > Best regards, > Nikolai Kostrigin > _______________________________________________ > devel-kernel mailing list > devel-kernel@lists.altlinux.org > https://lists.altlinux.org/mailman/listinfo/devel-kernel
prev parent reply other threads:[~2022-05-11 17:02 UTC|newest] Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top 2022-05-07 18:40 Vitaly Chikunov 2022-05-07 18:53 ` Vitaly Chikunov 2022-05-08 11:38 ` Andrey Savchenko 2022-05-07 20:02 ` Dmitry V. Levin 2022-05-07 20:11 ` Vitaly Chikunov 2022-05-07 20:16 ` Vitaly Chikunov 2022-05-08 8:57 ` Dmitry V. Levin 2022-05-08 9:49 ` Vitaly Chikunov 2022-05-08 11:36 ` Andrey Savchenko 2022-05-08 11:40 ` Vitaly Chikunov 2022-05-08 11:42 ` Vitaly Chikunov 2022-05-08 11:51 ` Andrey Savchenko 2022-05-08 11:54 ` Vitaly Chikunov 2022-05-11 9:20 ` Nikolai Kostrigin 2022-05-11 17:02 ` Vitaly Chikunov [this message]
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=20220511170248.utoxca4z2zdqxfmz@altlinux.org \ --to=vt@altlinux.org \ --cc=devel-kernel@lists.altlinux.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: link
ALT Linux kernel packages development This inbox may be cloned and mirrored by anyone: git clone --mirror http://lore.altlinux.org/devel-kernel/0 devel-kernel/git/0.git # If you have public-inbox 1.1+ installed, you may # initialize and index your mirror using the following commands: public-inbox-init -V2 devel-kernel devel-kernel/ http://lore.altlinux.org/devel-kernel \ devel-kernel@altlinux.org devel-kernel@altlinux.ru devel-kernel@altlinux.com public-inbox-index devel-kernel Example config snippet for mirrors. Newsgroup available over NNTP: nntp://lore.altlinux.org/org.altlinux.lists.devel-kernel AGPL code for this site: git clone https://public-inbox.org/public-inbox.git