Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1496966

Re: [PATCH] Let CONFIG_STRICT_DEVMEM depends on CONFIG_DEVMEM

From Dave Young <dyoung@redhat.com>
Newsgroups linux.kernel
Subject Re: [PATCH] Let CONFIG_STRICT_DEVMEM depends on CONFIG_DEVMEM
Date 2016-10-07 04:10 +0200
Message-ID <spsLM-1l4-1@gated-at.bofh.it> (permalink)
References <sp9g6-44b-5@gated-at.bofh.it> <spoyt-6y4-21@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 10/06/16 at 02:39pm, Kees Cook wrote:
> On Wed, Oct 5, 2016 at 10:12 PM, Dave Young <dyoung@redhat.com> wrote:
> > With CONFIG_DEVMEM not set, CONFIG_STRICT_DEVMEM will be useless
> > even if it is set =y, thus let's update the dependency in Kconfig.
> >
> > Signed-off-by: Dave Young <dyoung@redhat.com>
> 
> Acked-by: Kees Cook <keescook@chromium.org>
> 
> > ---
> >  lib/Kconfig.debug |    2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > --- linux-x86.orig/lib/Kconfig.debug
> > +++ linux-x86/lib/Kconfig.debug
> > @@ -1980,7 +1980,7 @@ config ARCH_HAS_DEVMEM_IS_ALLOWED
> >
> >  config STRICT_DEVMEM
> >         bool "Filter access to /dev/mem"
> > -       depends on MMU
> > +       depends on MMU && DEVMEM
> >         depends on ARCH_HAS_DEVMEM_IS_ALLOWED
> >         default y if TILE || PPC
> >         ---help---
> 
> While we're at it, can we make DEVKMEM default=n? The help text even
> suggests making it "n".

It's fine to me, will send another patch for that.

Thanks
Dave

> 
> -Kees
> 
> -- 
> Kees Cook
> Nexus Security

Back to linux.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

[PATCH] Let CONFIG_STRICT_DEVMEM depends on CONFIG_DEVMEM Dave Young <dyoung@redhat.com> - 2016-10-06 07:20 +0200
  Re: [PATCH] Let CONFIG_STRICT_DEVMEM depends on CONFIG_DEVMEM Kees Cook <keescook@chromium.org> - 2016-10-06 23:40 +0200
    Re: [PATCH] Let CONFIG_STRICT_DEVMEM depends on CONFIG_DEVMEM Dave Young <dyoung@redhat.com> - 2016-10-07 04:10 +0200

csiph-web