diff --git a/ciq/configs/kernel-aarch64-64k-debug.config b/ciq/configs/kernel-aarch64-64k-debug.config index cb58edf2e1d2d..0c76303decc33 100644 --- a/ciq/configs/kernel-aarch64-64k-debug.config +++ b/ciq/configs/kernel-aarch64-64k-debug.config @@ -1,4 +1,3 @@ -# arm64 # # Automatically generated file; DO NOT EDIT. # Linux/arm64 6.12.15 Kernel Configuration @@ -7830,10 +7829,10 @@ CONFIG_SECURITY_YAMA=y # CONFIG_SECURITY_SAFESETID is not set CONFIG_SECURITY_LOCKDOWN_LSM=y CONFIG_SECURITY_LOCKDOWN_LSM_EARLY=y -CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT=y CONFIG_LOCK_DOWN_KERNEL_FORCE_NONE=y # CONFIG_LOCK_DOWN_KERNEL_FORCE_INTEGRITY is not set # CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY is not set +CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT=y CONFIG_SECURITY_LANDLOCK=y # CONFIG_SECURITY_IPE is not set CONFIG_INTEGRITY=y diff --git a/ciq/configs/kernel-aarch64-64k.config b/ciq/configs/kernel-aarch64-64k.config index 20b7f57192be0..c06e1f9cab7ad 100644 --- a/ciq/configs/kernel-aarch64-64k.config +++ b/ciq/configs/kernel-aarch64-64k.config @@ -1,4 +1,3 @@ -# arm64 # # Automatically generated file; DO NOT EDIT. # Linux/arm64 6.12.15 Kernel Configuration @@ -7808,10 +7807,10 @@ CONFIG_SECURITY_YAMA=y # CONFIG_SECURITY_SAFESETID is not set CONFIG_SECURITY_LOCKDOWN_LSM=y CONFIG_SECURITY_LOCKDOWN_LSM_EARLY=y -CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT=y CONFIG_LOCK_DOWN_KERNEL_FORCE_NONE=y # CONFIG_LOCK_DOWN_KERNEL_FORCE_INTEGRITY is not set # CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY is not set +CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT=y CONFIG_SECURITY_LANDLOCK=y # CONFIG_SECURITY_IPE is not set CONFIG_INTEGRITY=y diff --git a/ciq/configs/kernel-aarch64.config b/ciq/configs/kernel-aarch64.config index ee3db9ed518c4..276a8cad32bde 100644 --- a/ciq/configs/kernel-aarch64.config +++ b/ciq/configs/kernel-aarch64.config @@ -1,4 +1,3 @@ -# arm64 # # Automatically generated file; DO NOT EDIT. # Linux/arm64 6.12.15 Kernel Configuration @@ -7814,10 +7813,10 @@ CONFIG_SECURITY_YAMA=y # CONFIG_SECURITY_SAFESETID is not set CONFIG_SECURITY_LOCKDOWN_LSM=y CONFIG_SECURITY_LOCKDOWN_LSM_EARLY=y -CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT=y CONFIG_LOCK_DOWN_KERNEL_FORCE_NONE=y # CONFIG_LOCK_DOWN_KERNEL_FORCE_INTEGRITY is not set # CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY is not set +CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT=y CONFIG_SECURITY_LANDLOCK=y # CONFIG_SECURITY_IPE is not set CONFIG_INTEGRITY=y diff --git a/ciq/configs/kernel-x86_64-debug.config b/ciq/configs/kernel-x86_64-debug.config index 58fae1a6b7bdd..aba02a18b341a 100644 --- a/ciq/configs/kernel-x86_64-debug.config +++ b/ciq/configs/kernel-x86_64-debug.config @@ -1,4 +1,3 @@ -# x86_64 # # Automatically generated file; DO NOT EDIT. # Linux/x86_64 6.12.15 Kernel Configuration @@ -463,8 +462,6 @@ CONFIG_PERF_EVENTS_AMD_UNCORE=y CONFIG_PERF_EVENTS_AMD_BRS=y # end of Performance monitoring -CONFIG_X86_16BIT=y -CONFIG_X86_ESPFIX64=y CONFIG_X86_VSYSCALL_EMULATION=y CONFIG_X86_IOPL_IOPERM=y CONFIG_MICROCODE=y @@ -510,10 +507,10 @@ CONFIG_EFI_STUB=y CONFIG_EFI_HANDOVER_PROTOCOL=y CONFIG_EFI_MIXED=y CONFIG_EFI_RUNTIME_MAP=y - CONFIG_HZ_100=y +CONFIG_HZ_100=y # CONFIG_HZ_250 is not set # CONFIG_HZ_300 is not set -# CONFIG_HZ=1000 is not set +# CONFIG_HZ_1000 is not set CONFIG_HZ=100 CONFIG_SCHED_HRTICK=y CONFIG_ARCH_SUPPORTS_KEXEC=y @@ -539,12 +536,12 @@ CONFIG_RANDOMIZE_MEMORY_PHYSICAL_PADDING=0xa CONFIG_HOTPLUG_CPU=y # CONFIG_COMPAT_VDSO is not set CONFIG_LEGACY_VSYSCALL_XONLY=y -CONFIG_LEGACY_VSYSCALL_NONE=n +# CONFIG_LEGACY_VSYSCALL_NONE is not set # CONFIG_CMDLINE_BOOL is not set -CONFIG_MODIFY_LDT_SYSCALL=n +# CONFIG_MODIFY_LDT_SYSCALL is not set # CONFIG_STRICT_SIGALTSTACK_SIZE is not set CONFIG_HAVE_LIVEPATCH=y -CONFIG_LIVEPATCH=n +# CONFIG_LIVEPATCH is not set # end of Processor type and features CONFIG_CC_HAS_NAMED_AS=y @@ -8609,10 +8606,10 @@ CONFIG_SECURITY_YAMA=y # CONFIG_SECURITY_SAFESETID is not set CONFIG_SECURITY_LOCKDOWN_LSM=y CONFIG_SECURITY_LOCKDOWN_LSM_EARLY=y -CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT=y CONFIG_LOCK_DOWN_KERNEL_FORCE_NONE=y # CONFIG_LOCK_DOWN_KERNEL_FORCE_INTEGRITY is not set # CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY is not set +CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT=y CONFIG_SECURITY_LANDLOCK=y # CONFIG_SECURITY_IPE is not set CONFIG_INTEGRITY=y @@ -9532,7 +9529,6 @@ CONFIG_SAMPLES=y # CONFIG_SAMPLE_FPROBE is not set # CONFIG_SAMPLE_KFIFO is not set # CONFIG_SAMPLE_KDB is not set -# CONFIG_SAMPLE_LIVEPATCH is not set # CONFIG_SAMPLE_CONFIGFS is not set # CONFIG_SAMPLE_CONNECTOR is not set # CONFIG_SAMPLE_FANOTIFY_ERROR is not set diff --git a/ciq/configs/kernel-x86_64.config b/ciq/configs/kernel-x86_64.config index 1830d04dc78b1..1c8d168be14ae 100644 --- a/ciq/configs/kernel-x86_64.config +++ b/ciq/configs/kernel-x86_64.config @@ -1,4 +1,3 @@ -# x86_64 # # Automatically generated file; DO NOT EDIT. # Linux/x86_64 6.12.15 Kernel Configuration @@ -460,8 +459,6 @@ CONFIG_PERF_EVENTS_AMD_UNCORE=y CONFIG_PERF_EVENTS_AMD_BRS=y # end of Performance monitoring -CONFIG_X86_16BIT=y -CONFIG_X86_ESPFIX64=y CONFIG_X86_VSYSCALL_EMULATION=y CONFIG_X86_IOPL_IOPERM=y CONFIG_MICROCODE=y @@ -509,7 +506,7 @@ CONFIG_EFI_MIXED=y CONFIG_EFI_RUNTIME_MAP=y CONFIG_HZ_100=y # CONFIG_HZ_250 is not set -# CONFIG_HZ_300 is not seti +# CONFIG_HZ_300 is not set # CONFIG_HZ_1000 is not set CONFIG_HZ=100 CONFIG_SCHED_HRTICK=y @@ -536,12 +533,12 @@ CONFIG_RANDOMIZE_MEMORY_PHYSICAL_PADDING=0xa CONFIG_HOTPLUG_CPU=y # CONFIG_COMPAT_VDSO is not set CONFIG_LEGACY_VSYSCALL_XONLY=y -CONFIG_LEGACY_VSYSCALL_NONE=n +# CONFIG_LEGACY_VSYSCALL_NONE is not set # CONFIG_CMDLINE_BOOL is not set -CONFIG_MODIFY_LDT_SYSCALL=n +# CONFIG_MODIFY_LDT_SYSCALL is not set # CONFIG_STRICT_SIGALTSTACK_SIZE is not set CONFIG_HAVE_LIVEPATCH=y -CONFIG_LIVEPATCH=n +# CONFIG_LIVEPATCH is not set # end of Processor type and features CONFIG_CC_HAS_NAMED_AS=y @@ -8582,10 +8579,10 @@ CONFIG_SECURITY_YAMA=y # CONFIG_SECURITY_SAFESETID is not set CONFIG_SECURITY_LOCKDOWN_LSM=y CONFIG_SECURITY_LOCKDOWN_LSM_EARLY=y -CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT=y CONFIG_LOCK_DOWN_KERNEL_FORCE_NONE=y # CONFIG_LOCK_DOWN_KERNEL_FORCE_INTEGRITY is not set # CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY is not set +CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT=y CONFIG_SECURITY_LANDLOCK=y # CONFIG_SECURITY_IPE is not set CONFIG_INTEGRITY=y @@ -9468,7 +9465,6 @@ CONFIG_SAMPLES=y # CONFIG_SAMPLE_FPROBE is not set # CONFIG_SAMPLE_KFIFO is not set # CONFIG_SAMPLE_KDB is not set -# CONFIG_SAMPLE_LIVEPATCH is not set # CONFIG_SAMPLE_CONFIGFS is not set # CONFIG_SAMPLE_CONNECTOR is not set # CONFIG_SAMPLE_FANOTIFY_ERROR is not set