Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: disable PCI busmastering on bridges during boot #899

Merged
merged 1 commit into from
Feb 19, 2024

Conversation

nberlee
Copy link
Contributor

@nberlee nberlee commented Feb 18, 2024

Enables CONFIG_EFI_DISABLE_PCI_DMA to improve boot security to protect from malicious PCI hardware.

Fixes #898

Not sure where CONFIG_TOOLS_SUPPORT_RELR comes from, this was added after make kernel-olddefconfig

@frezbo
Copy link
Member

frezbo commented Feb 18, 2024

Not sure where CONFIG_TOOLS_SUPPORT_RELR comes from, this was added after make kernel-olddefconfig

sorry, that's on me from 65006ed (must not forgot to run olddefconfig

Enables CONFIG_EFI_DISABLE_PCI_DMA to improve boot security to protect from
malicious PCI hardware.

Not sure where CONFIG_TOOLS_SUPPORT_RELR comes from, this was added after
make kernel-olddefconfig

Signed-off-by: Nico Berlee <nico.berlee@on2it.net>
Signed-off-by: Noel Georgi <git@frezbo.dev>
@frezbo
Copy link
Member

frezbo commented Feb 19, 2024

/m

@talos-bot talos-bot merged commit 87eb013 into siderolabs:main Feb 19, 2024
14 checks passed
smira added a commit to smira/talos that referenced this pull request Feb 20, 2024
Pulls in following PRs:

* siderolabs/pkgs#893
* siderolabs/pkgs#896
* siderolabs/pkgs#889
* siderolabs/pkgs#899
* siderolabs/pkgs#902

Signed-off-by: Andrey Smirnov <andrey.smirnov@siderolabs.com>
smira added a commit to smira/talos that referenced this pull request Feb 20, 2024
Pulls in following PRs:

* siderolabs/pkgs#893
* siderolabs/pkgs#896
* siderolabs/pkgs#889
* siderolabs/pkgs#899
* siderolabs/pkgs#902

Signed-off-by: Andrey Smirnov <andrey.smirnov@siderolabs.com>
smira added a commit to smira/talos that referenced this pull request Feb 21, 2024
Pulls in following PRs:

* siderolabs/pkgs#893
* siderolabs/pkgs#896
* siderolabs/pkgs#889
* siderolabs/pkgs#899
* siderolabs/pkgs#902

Signed-off-by: Andrey Smirnov <andrey.smirnov@siderolabs.com>
(cherry picked from commit 9b62919)
smira added a commit to smira/talos that referenced this pull request Feb 21, 2024
Pulls in following PRs:

* siderolabs/pkgs#893
* siderolabs/pkgs#896
* siderolabs/pkgs#889
* siderolabs/pkgs#899
* siderolabs/pkgs#902

Signed-off-by: Andrey Smirnov <andrey.smirnov@siderolabs.com>
(cherry picked from commit 9b62919)
dsseng pushed a commit to dsseng/talos that referenced this pull request Mar 7, 2024
Pulls in following PRs:

* siderolabs/pkgs#893
* siderolabs/pkgs#896
* siderolabs/pkgs#889
* siderolabs/pkgs#899
* siderolabs/pkgs#902

Signed-off-by: Andrey Smirnov <andrey.smirnov@siderolabs.com>
smira added a commit to smira/pkgs that referenced this pull request May 16, 2024
This effectively reverts siderolabs#899 completely.

Fixes siderolabs/talos#8743

Signed-off-by: Andrey Smirnov <andrey.smirnov@siderolabs.com>
smira added a commit to smira/pkgs that referenced this pull request May 16, 2024
This effectively reverts siderolabs#899 completely.

Fixes siderolabs/talos#8743

Signed-off-by: Andrey Smirnov <andrey.smirnov@siderolabs.com>
(cherry picked from commit f414bbd)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Refused
Development

Successfully merging this pull request may close these issues.

enable CONFIG_EFI_DISABLE_PCI_DMA to improve boot security from malicious PCI hardware
3 participants