Skip to content
This repository has been archived by the owner on Mar 30, 2021. It is now read-only.

Upgrade SecureDrop grsec kernels to 4.14.154 and tweak EFI kernel config settings #52

Merged
merged 2 commits into from
Nov 14, 2019

Conversation

emkll
Copy link
Contributor

@emkll emkll commented Nov 5, 2019

Towards freedomofpress/securedrop#4989
Address issues with booting in NUCs in EFI-mode

  • Kernel build with this config boots successfully in on an EFI system
  • CONFIG_X86_INTEL_TSX_MODE_OFF=y in the config of booted system
  • CONFIG_IDA is not set in the config of booted system

Mirror EFI settings from 4.4 series
Per [0], CONFIG_EFI_VARS should be disabled if CONFIG_EFIVAR_FS is enabled

[0] https://wiki.archlinux.org/index.php/Unified_Extensible_Firmware_Interface
@conorsch
Copy link
Contributor

I've not verified behavior on the request hardware, so deferring final review. Still, these changes are shortly to be distributed to test/CI machines giving merge of:

Also removes IRDA from the configuration
@emkll emkll changed the title Tweak EFI kernel config settings Upgrade SecureDrop grsec kernels to 4.14.154 and tweak EFI kernel config settings Nov 13, 2019
Copy link
Contributor

@conorsch conorsch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving based on visual review. Once the packages land in the apt-test repo, we'll proceed with more hardware-based QA.

@conorsch conorsch merged commit 25614af into master Nov 14, 2019
@emkll emkll deleted the sd-4.14-efi branch November 19, 2019 15:19
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants