Skip to content
Commit b0c8fdc7 authored by David Howells's avatar David Howells Committed by James Morris
Browse files

lockdown: Lock down perf when in confidentiality mode



Disallow the use of certain perf facilities that might allow userspace to
access kernel data.

Signed-off-by: default avatarDavid Howells <dhowells@redhat.com>
Signed-off-by: default avatarMatthew Garrett <mjg59@google.com>
Reviewed-by: default avatarKees Cook <keescook@chromium.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Arnaldo Carvalho de Melo <acme@kernel.org>
Signed-off-by: default avatarJames Morris <jmorris@namei.org>
parent 9d1f8be5
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment