From 214700254ecff39e047eac0716091bd61ca2d92a Mon Sep 17 00:00:00 2001 From: Michael Benedict Date: Thu, 21 Feb 2019 20:53:30 +0700 Subject: [PATCH] defconfig: disable samsung unnecessary security feature Signed-off-by: Michael Benedict --- .../configs/exynos8895-dream2lte_defconfig | 31 ++++++------------ .../configs/exynos8895-dreamlte_defconfig | 31 ++++++------------ .../configs/exynos8895-greatlte_defconfig | 32 +++++++------------ 3 files changed, 31 insertions(+), 63 deletions(-) diff --git a/arch/arm64/configs/exynos8895-dream2lte_defconfig b/arch/arm64/configs/exynos8895-dream2lte_defconfig index da650f459cf6..ec2ebee575ba 100644 --- a/arch/arm64/configs/exynos8895-dream2lte_defconfig +++ b/arch/arm64/configs/exynos8895-dream2lte_defconfig @@ -418,23 +418,17 @@ CONFIG_HMP_FREQUENCY_INVARIANT_SCALE=y CONFIG_SCHED_HMP_TASK_BASED_SOFTLANDING=y CONFIG_NR_CPUS=8 CONFIG_HOTPLUG_CPU=y -CONFIG_TIMA=y +# CONFIG_TIMA is not set # CONFIG_TIMA_LKMAUTH is not set -CONFIG_RKP=y -CONFIG_UH_RKP=y -# CONFIG_RKP_DEBUG is not set -CONFIG_RKP_KDP=y -CONFIG_RKP_NS_PROT=y -CONFIG_RKP_DMAP_PROT=y -CONFIG_RKP_6G=y +# CONFIG_RKP is not set +# CONFIG_UH_RKP is not set CONFIG_RELOCATABLE_KERNEL=y # # Control Flow Protection # -CONFIG_RKP_CFP=y -CONFIG_RKP_CFP_JOPP=y -CONFIG_RKP_CFP_JOPP_MAGIC=0x00be7bad +# CONFIG_RKP_CFP is not set +# CONFIG_RKP_CFP_JOPP is not set # CONFIG_PREEMPT_NONE is not set # CONFIG_PREEMPT_VOLUNTARY is not set CONFIG_PREEMPT=y @@ -1048,7 +1042,7 @@ CONFIG_NET_SCH_FIFO=y # CONFIG_HSR is not set # CONFIG_NET_SWITCHDEV is not set # CONFIG_NET_L3_MASTER_DEV is not set -CONFIG_KNOX_NCM=y +# CONFIG_KNOX_NCM is not set CONFIG_RPS=y CONFIG_RFS_ACCEL=y CONFIG_XPS=y @@ -1249,7 +1243,7 @@ CONFIG_BLK_DEV_RAM_SIZE=8192 # CONFIG_HP_ILO is not set # CONFIG_APDS9802ALS is not set # CONFIG_ISL29003 is not set -CONFIG_KNOX_KAP=y +# CONFIG_KNOX_KAP is not set # CONFIG_ISL29020 is not set # CONFIG_SENSORS_TSL2550 is not set # CONFIG_SENSORS_BH1780 is not set @@ -1267,7 +1261,6 @@ CONFIG_UID_SYS_STATS=y # CONFIG_UID_SYS_STATS_DEBUG is not set # CONFIG_MEMORY_STATE_TIME is not set CONFIG_EXYNOS_IMA=y -CONFIG_TIMA_LOG=y # CONFIG_FAN_G761 is not set # CONFIG_C2PORT is not set @@ -3669,6 +3662,7 @@ CONFIG_USB_SERIAL_PL2303=y # CONFIG_USB_PHY is not set # CONFIG_USB_OTG_WAKELOCK is not set # CONFIG_NOP_USB_XCEIV is not set +# CONFIG_DUAL_ROLE_USB_INTF is not set # CONFIG_USB_GPIO_VBUS is not set # CONFIG_USB_ISP1301 is not set # CONFIG_USB_ULPI is not set @@ -3765,7 +3759,6 @@ CONFIG_USB_CONFIGFS_F_MIDI=y # # USB Power Delivery and Type-C drivers # -CONFIG_TYPEC=y # CONFIG_UWB is not set CONFIG_MMC=y # CONFIG_MMC_DEBUG is not set @@ -5251,10 +5244,7 @@ CONFIG_HAVE_ARCH_KGDB=y # # Samsung Rooting Restriction Feature # -CONFIG_SEC_RESTRICT_ROOTING=y -CONFIG_SEC_RESTRICT_SETUID=y -CONFIG_SEC_RESTRICT_FORK=y -CONFIG_SEC_RESTRICT_ROOTING_LOG=y +# CONFIG_SEC_RESTRICT_ROOTING is not set # # Security options @@ -5298,8 +5288,7 @@ CONFIG_INTEGRITY=y CONFIG_INTEGRITY_AUDIT=y # CONFIG_IMA is not set # CONFIG_EVM is not set -# CONFIG_TZ_ICCC is not set -CONFIG_SECURITY_DEFEX=y +# CONFIG_SECURITY_DEFEX is not set # CONFIG_DEFEX_KERNEL_ONLY is not set CONFIG_SECURITY_DSMS=y CONFIG_DEFAULT_SECURITY_SELINUX=y diff --git a/arch/arm64/configs/exynos8895-dreamlte_defconfig b/arch/arm64/configs/exynos8895-dreamlte_defconfig index 1965ec3853cc..13f28a922081 100644 --- a/arch/arm64/configs/exynos8895-dreamlte_defconfig +++ b/arch/arm64/configs/exynos8895-dreamlte_defconfig @@ -418,23 +418,17 @@ CONFIG_HMP_FREQUENCY_INVARIANT_SCALE=y CONFIG_SCHED_HMP_TASK_BASED_SOFTLANDING=y CONFIG_NR_CPUS=8 CONFIG_HOTPLUG_CPU=y -CONFIG_TIMA=y +# CONFIG_TIMA is not set # CONFIG_TIMA_LKMAUTH is not set -CONFIG_RKP=y -CONFIG_UH_RKP=y -# CONFIG_RKP_DEBUG is not set -CONFIG_RKP_KDP=y -CONFIG_RKP_NS_PROT=y -CONFIG_RKP_DMAP_PROT=y -CONFIG_RKP_6G=y +# CONFIG_RKP is not set +# CONFIG_UH_RKP is not set CONFIG_RELOCATABLE_KERNEL=y # # Control Flow Protection # -CONFIG_RKP_CFP=y -CONFIG_RKP_CFP_JOPP=y -CONFIG_RKP_CFP_JOPP_MAGIC=0x00be7bad +# CONFIG_RKP_CFP is not set +# CONFIG_RKP_CFP_JOPP is not set # CONFIG_PREEMPT_NONE is not set # CONFIG_PREEMPT_VOLUNTARY is not set CONFIG_PREEMPT=y @@ -1048,7 +1042,7 @@ CONFIG_NET_SCH_FIFO=y # CONFIG_HSR is not set # CONFIG_NET_SWITCHDEV is not set # CONFIG_NET_L3_MASTER_DEV is not set -CONFIG_KNOX_NCM=y +# CONFIG_KNOX_NCM is not set CONFIG_RPS=y CONFIG_RFS_ACCEL=y CONFIG_XPS=y @@ -1249,7 +1243,7 @@ CONFIG_BLK_DEV_RAM_SIZE=8192 # CONFIG_HP_ILO is not set # CONFIG_APDS9802ALS is not set # CONFIG_ISL29003 is not set -CONFIG_KNOX_KAP=y +# CONFIG_KNOX_KAP is not set # CONFIG_ISL29020 is not set # CONFIG_SENSORS_TSL2550 is not set # CONFIG_SENSORS_BH1780 is not set @@ -1267,7 +1261,6 @@ CONFIG_UID_SYS_STATS=y # CONFIG_UID_SYS_STATS_DEBUG is not set # CONFIG_MEMORY_STATE_TIME is not set CONFIG_EXYNOS_IMA=y -CONFIG_TIMA_LOG=y # CONFIG_FAN_G761 is not set # CONFIG_C2PORT is not set @@ -3669,6 +3662,7 @@ CONFIG_USB_SERIAL_PL2303=y # CONFIG_USB_PHY is not set # CONFIG_USB_OTG_WAKELOCK is not set # CONFIG_NOP_USB_XCEIV is not set +# CONFIG_DUAL_ROLE_USB_INTF is not set # CONFIG_USB_GPIO_VBUS is not set # CONFIG_USB_ISP1301 is not set # CONFIG_USB_ULPI is not set @@ -3765,7 +3759,6 @@ CONFIG_USB_CONFIGFS_F_MIDI=y # # USB Power Delivery and Type-C drivers # -CONFIG_TYPEC=y # CONFIG_UWB is not set CONFIG_MMC=y # CONFIG_MMC_DEBUG is not set @@ -5251,10 +5244,7 @@ CONFIG_HAVE_ARCH_KGDB=y # # Samsung Rooting Restriction Feature # -CONFIG_SEC_RESTRICT_ROOTING=y -CONFIG_SEC_RESTRICT_SETUID=y -CONFIG_SEC_RESTRICT_FORK=y -CONFIG_SEC_RESTRICT_ROOTING_LOG=y +# CONFIG_SEC_RESTRICT_ROOTING is not set # # Security options @@ -5298,8 +5288,7 @@ CONFIG_INTEGRITY=y CONFIG_INTEGRITY_AUDIT=y # CONFIG_IMA is not set # CONFIG_EVM is not set -# CONFIG_TZ_ICCC is not set -CONFIG_SECURITY_DEFEX=y +# CONFIG_SECURITY_DEFEX is not set # CONFIG_DEFEX_KERNEL_ONLY is not set CONFIG_SECURITY_DSMS=y CONFIG_DEFAULT_SECURITY_SELINUX=y diff --git a/arch/arm64/configs/exynos8895-greatlte_defconfig b/arch/arm64/configs/exynos8895-greatlte_defconfig index be6548894614..74cdf77c17b5 100644 --- a/arch/arm64/configs/exynos8895-greatlte_defconfig +++ b/arch/arm64/configs/exynos8895-greatlte_defconfig @@ -420,23 +420,17 @@ CONFIG_HMP_FREQUENCY_INVARIANT_SCALE=y CONFIG_SCHED_HMP_TASK_BASED_SOFTLANDING=y CONFIG_NR_CPUS=8 CONFIG_HOTPLUG_CPU=y -CONFIG_TIMA=y +# CONFIG_TIMA is not set # CONFIG_TIMA_LKMAUTH is not set -CONFIG_RKP=y -CONFIG_UH_RKP=y -# CONFIG_RKP_DEBUG is not set -CONFIG_RKP_KDP=y -CONFIG_RKP_NS_PROT=y -CONFIG_RKP_DMAP_PROT=y -CONFIG_RKP_6G=y +# CONFIG_RKP is not set +# CONFIG_UH_RKP is not set CONFIG_RELOCATABLE_KERNEL=y # # Control Flow Protection # -CONFIG_RKP_CFP=y -CONFIG_RKP_CFP_JOPP=y -CONFIG_RKP_CFP_JOPP_MAGIC=0x00be7bad +# CONFIG_RKP_CFP is not set +# CONFIG_RKP_CFP_JOPP is not set # CONFIG_PREEMPT_NONE is not set # CONFIG_PREEMPT_VOLUNTARY is not set CONFIG_PREEMPT=y @@ -504,6 +498,7 @@ CONFIG_MMAP_READAROUND_LIMIT=32 CONFIG_LARGE_DIRTY_BUFFER=y CONFIG_MAX_DIRTY_THRESH_PAGES=76800 CONFIG_BALANCE_ANON_FILE_RECLAIM=y +# CONFIG_RBIN is not set CONFIG_SECCOMP=y # CONFIG_XEN is not set CONFIG_FORCE_MAX_ZONEORDER=11 @@ -1049,7 +1044,7 @@ CONFIG_NET_SCH_FIFO=y # CONFIG_HSR is not set # CONFIG_NET_SWITCHDEV is not set # CONFIG_NET_L3_MASTER_DEV is not set -CONFIG_KNOX_NCM=y +# CONFIG_KNOX_NCM is not set CONFIG_RPS=y CONFIG_RFS_ACCEL=y CONFIG_XPS=y @@ -1250,7 +1245,7 @@ CONFIG_BLK_DEV_RAM_SIZE=8192 # CONFIG_HP_ILO is not set # CONFIG_APDS9802ALS is not set # CONFIG_ISL29003 is not set -CONFIG_KNOX_KAP=y +# CONFIG_KNOX_KAP is not set # CONFIG_ISL29020 is not set # CONFIG_SENSORS_TSL2550 is not set # CONFIG_SENSORS_BH1780 is not set @@ -1268,7 +1263,6 @@ CONFIG_UID_SYS_STATS=y # CONFIG_UID_SYS_STATS_DEBUG is not set # CONFIG_MEMORY_STATE_TIME is not set CONFIG_EXYNOS_IMA=y -CONFIG_TIMA_LOG=y # CONFIG_FAN_G761 is not set # CONFIG_C2PORT is not set @@ -3670,6 +3664,7 @@ CONFIG_USB_SERIAL_PL2303=y # CONFIG_USB_PHY is not set # CONFIG_USB_OTG_WAKELOCK is not set # CONFIG_NOP_USB_XCEIV is not set +# CONFIG_DUAL_ROLE_USB_INTF is not set # CONFIG_USB_GPIO_VBUS is not set # CONFIG_USB_ISP1301 is not set # CONFIG_USB_ULPI is not set @@ -3766,7 +3761,6 @@ CONFIG_USB_CONFIGFS_F_MIDI=y # # USB Power Delivery and Type-C drivers # -CONFIG_TYPEC=y # CONFIG_UWB is not set CONFIG_MMC=y # CONFIG_MMC_DEBUG is not set @@ -5253,10 +5247,7 @@ CONFIG_HAVE_ARCH_KGDB=y # # Samsung Rooting Restriction Feature # -CONFIG_SEC_RESTRICT_ROOTING=y -CONFIG_SEC_RESTRICT_SETUID=y -CONFIG_SEC_RESTRICT_FORK=y -CONFIG_SEC_RESTRICT_ROOTING_LOG=y +# CONFIG_SEC_RESTRICT_ROOTING is not set # # Security options @@ -5300,8 +5291,7 @@ CONFIG_INTEGRITY=y CONFIG_INTEGRITY_AUDIT=y # CONFIG_IMA is not set # CONFIG_EVM is not set -# CONFIG_TZ_ICCC is not set -CONFIG_SECURITY_DEFEX=y +# CONFIG_SECURITY_DEFEX is not set # CONFIG_DEFEX_KERNEL_ONLY is not set CONFIG_SECURITY_DSMS=y CONFIG_DEFAULT_SECURITY_SELINUX=y -- 2.20.1