From d3a84712777d257e4c113b5cdeaa6ffb9a02ec01 Mon Sep 17 00:00:00 2001 From: 0x6fe1be2 <34159565+gfelber@users.noreply.github.com> Date: Sat, 1 Jun 2024 13:24:21 +0200 Subject: [PATCH] x86_64-dotconfig added X86_USER_SHADOW_STACK=y enabling X86_USER_SHADOW_STACK inside the kernel dotconfig for x86_64 to improve userland binary security. Control-flow Enforcement Technology (CET) Shadow Stack https://docs.kernel.org/next/x86/shstk.html --- srcpkgs/linux6.9/files/x86_64-dotconfig | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/srcpkgs/linux6.9/files/x86_64-dotconfig b/srcpkgs/linux6.9/files/x86_64-dotconfig index 9be4b5ffdd7a42..541b0e25dff2b0 100644 --- a/srcpkgs/linux6.9/files/x86_64-dotconfig +++ b/srcpkgs/linux6.9/files/x86_64-dotconfig @@ -490,7 +490,7 @@ CONFIG_X86_INTEL_TSX_MODE_OFF=y # CONFIG_X86_INTEL_TSX_MODE_ON is not set # CONFIG_X86_INTEL_TSX_MODE_AUTO is not set # CONFIG_X86_SGX is not set -# CONFIG_X86_USER_SHADOW_STACK is not set +CONFIG_X86_USER_SHADOW_STACK=y CONFIG_EFI=y CONFIG_EFI_STUB=y CONFIG_EFI_HANDOVER_PROTOCOL=y