1b2441318SGreg Kroah-Hartman# SPDX-License-Identifier: GPL-2.0 2fb32e03fSMathieu Desnoyers# 3fb32e03fSMathieu Desnoyers# General architecture dependent options 4fb32e03fSMathieu Desnoyers# 5125e5645SMathieu Desnoyers 61572497cSChristoph Hellwig# 71572497cSChristoph Hellwig# Note: arch/$(SRCARCH)/Kconfig needs to be included first so that it can 81572497cSChristoph Hellwig# override the default values in this file. 91572497cSChristoph Hellwig# 101572497cSChristoph Hellwigsource "arch/$(SRCARCH)/Kconfig" 111572497cSChristoph Hellwig 1222471e13SRandy Dunlapmenu "General architecture-dependent options" 1322471e13SRandy Dunlap 14692f66f2SHari Bathiniconfig CRASH_CORE 15692f66f2SHari Bathini bool 16692f66f2SHari Bathini 172965faa5SDave Youngconfig KEXEC_CORE 18692f66f2SHari Bathini select CRASH_CORE 192965faa5SDave Young bool 202965faa5SDave Young 21175fca3bSSven Schnelleconfig KEXEC_ELF 22175fca3bSSven Schnelle bool 23175fca3bSSven Schnelle 24467d2782SThiago Jung Bauermannconfig HAVE_IMA_KEXEC 25467d2782SThiago Jung Bauermann bool 26467d2782SThiago Jung Bauermann 275e6e9852SChristoph Hellwigconfig SET_FS 285e6e9852SChristoph Hellwig bool 295e6e9852SChristoph Hellwig 3005736e4aSThomas Gleixnerconfig HOTPLUG_SMT 3105736e4aSThomas Gleixner bool 3205736e4aSThomas Gleixner 33142781e1SThomas Gleixnerconfig GENERIC_ENTRY 34142781e1SThomas Gleixner bool 35142781e1SThomas Gleixner 36125e5645SMathieu Desnoyersconfig KPROBES 37125e5645SMathieu Desnoyers bool "Kprobes" 3805ed160eSMasami Hiramatsu depends on MODULES 39125e5645SMathieu Desnoyers depends on HAVE_KPROBES 4005ed160eSMasami Hiramatsu select KALLSYMS 41125e5645SMathieu Desnoyers help 42125e5645SMathieu Desnoyers Kprobes allows you to trap at almost any kernel address and 43125e5645SMathieu Desnoyers execute a callback function. register_kprobe() establishes 44125e5645SMathieu Desnoyers a probepoint and specifies the callback. Kprobes is useful 45125e5645SMathieu Desnoyers for kernel debugging, non-intrusive instrumentation and testing. 46125e5645SMathieu Desnoyers If in doubt, say "N". 47125e5645SMathieu Desnoyers 4845f81b1cSSteven Rostedtconfig JUMP_LABEL 49c5905afbSIngo Molnar bool "Optimize very unlikely/likely branches" 5045f81b1cSSteven Rostedt depends on HAVE_ARCH_JUMP_LABEL 51e9666d10SMasahiro Yamada depends on CC_HAS_ASM_GOTO 5245f81b1cSSteven Rostedt help 53c5905afbSIngo Molnar This option enables a transparent branch optimization that 54c5905afbSIngo Molnar makes certain almost-always-true or almost-always-false branch 55c5905afbSIngo Molnar conditions even cheaper to execute within the kernel. 5645f81b1cSSteven Rostedt 57c5905afbSIngo Molnar Certain performance-sensitive kernel code, such as trace points, 58c5905afbSIngo Molnar scheduler functionality, networking code and KVM have such 59c5905afbSIngo Molnar branches and include support for this optimization technique. 60c5905afbSIngo Molnar 61c5905afbSIngo Molnar If it is detected that the compiler has support for "asm goto", 62c5905afbSIngo Molnar the kernel will compile such branches with just a nop 63c5905afbSIngo Molnar instruction. When the condition flag is toggled to true, the 64c5905afbSIngo Molnar nop will be converted to a jump instruction to execute the 65c5905afbSIngo Molnar conditional block of instructions. 66c5905afbSIngo Molnar 67c5905afbSIngo Molnar This technique lowers overhead and stress on the branch prediction 68c5905afbSIngo Molnar of the processor and generally makes the kernel faster. The update 69c5905afbSIngo Molnar of the condition is slower, but those are always very rare. 70c5905afbSIngo Molnar 71c5905afbSIngo Molnar ( On 32-bit x86, the necessary options added to the compiler 72c5905afbSIngo Molnar flags may increase the size of the kernel slightly. ) 7345f81b1cSSteven Rostedt 741987c947SPeter Zijlstraconfig STATIC_KEYS_SELFTEST 751987c947SPeter Zijlstra bool "Static key selftest" 761987c947SPeter Zijlstra depends on JUMP_LABEL 771987c947SPeter Zijlstra help 781987c947SPeter Zijlstra Boot time self-test of the branch patching code. 791987c947SPeter Zijlstra 80f03c4129SPeter Zijlstraconfig STATIC_CALL_SELFTEST 81f03c4129SPeter Zijlstra bool "Static call selftest" 82f03c4129SPeter Zijlstra depends on HAVE_STATIC_CALL 83f03c4129SPeter Zijlstra help 84f03c4129SPeter Zijlstra Boot time self-test of the call patching code. 85f03c4129SPeter Zijlstra 86afd66255SMasami Hiramatsuconfig OPTPROBES 875cc718b9SMasami Hiramatsu def_bool y 885cc718b9SMasami Hiramatsu depends on KPROBES && HAVE_OPTPROBES 8901b1d88bSThomas Gleixner select TASKS_RCU if PREEMPTION 90afd66255SMasami Hiramatsu 91e7dbfe34SMasami Hiramatsuconfig KPROBES_ON_FTRACE 92e7dbfe34SMasami Hiramatsu def_bool y 93e7dbfe34SMasami Hiramatsu depends on KPROBES && HAVE_KPROBES_ON_FTRACE 94e7dbfe34SMasami Hiramatsu depends on DYNAMIC_FTRACE_WITH_REGS 95e7dbfe34SMasami Hiramatsu help 96e7dbfe34SMasami Hiramatsu If function tracer is enabled and the arch supports full 97e7dbfe34SMasami Hiramatsu passing of pt_regs to function tracing, then kprobes can 98e7dbfe34SMasami Hiramatsu optimize on top of function tracing. 99e7dbfe34SMasami Hiramatsu 1002b144498SSrikar Dronamrajuconfig UPROBES 10109294e31SDavid A. Long def_bool n 102e8f4aa60SAllen Pais depends on ARCH_SUPPORTS_UPROBES 1032b144498SSrikar Dronamraju help 1047b2d81d4SIngo Molnar Uprobes is the user-space counterpart to kprobes: they 1057b2d81d4SIngo Molnar enable instrumentation applications (such as 'perf probe') 1067b2d81d4SIngo Molnar to establish unintrusive probes in user-space binaries and 1077b2d81d4SIngo Molnar libraries, by executing handler functions when the probes 1087b2d81d4SIngo Molnar are hit by user-space applications. 1097b2d81d4SIngo Molnar 1107b2d81d4SIngo Molnar ( These probes come in the form of single-byte breakpoints, 1117b2d81d4SIngo Molnar managed by the kernel and kept transparent to the probed 1127b2d81d4SIngo Molnar application. ) 1132b144498SSrikar Dronamraju 114adab66b7SSteven Rostedt (VMware)config HAVE_64BIT_ALIGNED_ACCESS 115adab66b7SSteven Rostedt (VMware) def_bool 64BIT && !HAVE_EFFICIENT_UNALIGNED_ACCESS 116adab66b7SSteven Rostedt (VMware) help 117adab66b7SSteven Rostedt (VMware) Some architectures require 64 bit accesses to be 64 bit 118adab66b7SSteven Rostedt (VMware) aligned, which also requires structs containing 64 bit values 119adab66b7SSteven Rostedt (VMware) to be 64 bit aligned too. This includes some 32 bit 120adab66b7SSteven Rostedt (VMware) architectures which can do 64 bit accesses, as well as 64 bit 121adab66b7SSteven Rostedt (VMware) architectures without unaligned access. 122adab66b7SSteven Rostedt (VMware) 123adab66b7SSteven Rostedt (VMware) This symbol should be selected by an architecture if 64 bit 124adab66b7SSteven Rostedt (VMware) accesses are required to be 64 bit aligned in this way even 125adab66b7SSteven Rostedt (VMware) though it is not a 64 bit architecture. 126adab66b7SSteven Rostedt (VMware) 127ba1a297dSLukas Bulwahn See Documentation/core-api/unaligned-memory-access.rst for 128ba1a297dSLukas Bulwahn more information on the topic of unaligned memory accesses. 129adab66b7SSteven Rostedt (VMware) 13058340a07SJohannes Bergconfig HAVE_EFFICIENT_UNALIGNED_ACCESS 1319ba16087SJan Beulich bool 13258340a07SJohannes Berg help 13358340a07SJohannes Berg Some architectures are unable to perform unaligned accesses 13458340a07SJohannes Berg without the use of get_unaligned/put_unaligned. Others are 13558340a07SJohannes Berg unable to perform such accesses efficiently (e.g. trap on 13658340a07SJohannes Berg unaligned access and require fixing it up in the exception 13758340a07SJohannes Berg handler.) 13858340a07SJohannes Berg 13958340a07SJohannes Berg This symbol should be selected by an architecture if it can 14058340a07SJohannes Berg perform unaligned accesses efficiently to allow different 14158340a07SJohannes Berg code paths to be selected for these cases. Some network 14258340a07SJohannes Berg drivers, for example, could opt to not fix up alignment 14358340a07SJohannes Berg problems with received packets if doing so would not help 14458340a07SJohannes Berg much. 14558340a07SJohannes Berg 146c9b54d6fSMauro Carvalho Chehab See Documentation/core-api/unaligned-memory-access.rst for more 14758340a07SJohannes Berg information on the topic of unaligned memory accesses. 14858340a07SJohannes Berg 149cf66bb93SDavid Woodhouseconfig ARCH_USE_BUILTIN_BSWAP 150cf66bb93SDavid Woodhouse bool 151cf66bb93SDavid Woodhouse help 152cf66bb93SDavid Woodhouse Modern versions of GCC (since 4.4) have builtin functions 153cf66bb93SDavid Woodhouse for handling byte-swapping. Using these, instead of the old 154cf66bb93SDavid Woodhouse inline assembler that the architecture code provides in the 155cf66bb93SDavid Woodhouse __arch_bswapXX() macros, allows the compiler to see what's 156cf66bb93SDavid Woodhouse happening and offers more opportunity for optimisation. In 157cf66bb93SDavid Woodhouse particular, the compiler will be able to combine the byteswap 158cf66bb93SDavid Woodhouse with a nearby load or store and use load-and-swap or 159cf66bb93SDavid Woodhouse store-and-swap instructions if the architecture has them. It 160cf66bb93SDavid Woodhouse should almost *never* result in code which is worse than the 161cf66bb93SDavid Woodhouse hand-coded assembler in <asm/swab.h>. But just in case it 162cf66bb93SDavid Woodhouse does, the use of the builtins is optional. 163cf66bb93SDavid Woodhouse 164cf66bb93SDavid Woodhouse Any architecture with load-and-swap or store-and-swap 165cf66bb93SDavid Woodhouse instructions should set this. And it shouldn't hurt to set it 166cf66bb93SDavid Woodhouse on architectures that don't have such instructions. 167cf66bb93SDavid Woodhouse 1689edddaa2SAnanth N Mavinakayanahalliconfig KRETPROBES 1699edddaa2SAnanth N Mavinakayanahalli def_bool y 1709edddaa2SAnanth N Mavinakayanahalli depends on KPROBES && HAVE_KRETPROBES 1719edddaa2SAnanth N Mavinakayanahalli 1727c68af6eSAvi Kivityconfig USER_RETURN_NOTIFIER 1737c68af6eSAvi Kivity bool 1747c68af6eSAvi Kivity depends on HAVE_USER_RETURN_NOTIFIER 1757c68af6eSAvi Kivity help 1767c68af6eSAvi Kivity Provide a kernel-internal notification when a cpu is about to 1777c68af6eSAvi Kivity switch to user mode. 1787c68af6eSAvi Kivity 17928b2ee20SRik van Rielconfig HAVE_IOREMAP_PROT 1809ba16087SJan Beulich bool 18128b2ee20SRik van Riel 182125e5645SMathieu Desnoyersconfig HAVE_KPROBES 1839ba16087SJan Beulich bool 1849edddaa2SAnanth N Mavinakayanahalli 1859edddaa2SAnanth N Mavinakayanahalliconfig HAVE_KRETPROBES 1869ba16087SJan Beulich bool 18774bc7ceeSArthur Kepner 188afd66255SMasami Hiramatsuconfig HAVE_OPTPROBES 189afd66255SMasami Hiramatsu bool 190d314d74cSCong Wang 191e7dbfe34SMasami Hiramatsuconfig HAVE_KPROBES_ON_FTRACE 192e7dbfe34SMasami Hiramatsu bool 193e7dbfe34SMasami Hiramatsu 194540adea3SMasami Hiramatsuconfig HAVE_FUNCTION_ERROR_INJECTION 1959802d865SJosef Bacik bool 1969802d865SJosef Bacik 19742a0bb3fSPetr Mladekconfig HAVE_NMI 19842a0bb3fSPetr Mladek bool 19942a0bb3fSPetr Mladek 2004aae683fSMasahiro Yamadaconfig TRACE_IRQFLAGS_SUPPORT 2014aae683fSMasahiro Yamada bool 2024aae683fSMasahiro Yamada 2031f5a4ad9SRoland McGrath# 2041f5a4ad9SRoland McGrath# An arch should select this if it provides all these things: 2051f5a4ad9SRoland McGrath# 2061f5a4ad9SRoland McGrath# task_pt_regs() in asm/processor.h or asm/ptrace.h 2071f5a4ad9SRoland McGrath# arch_has_single_step() if there is hardware single-step support 2081f5a4ad9SRoland McGrath# arch_has_block_step() if there is hardware block-step support 2091f5a4ad9SRoland McGrath# asm/syscall.h supplying asm-generic/syscall.h interface 2101f5a4ad9SRoland McGrath# linux/regset.h user_regset interfaces 2111f5a4ad9SRoland McGrath# CORE_DUMP_USE_REGSET #define'd in linux/elf.h 2121f5a4ad9SRoland McGrath# TIF_SYSCALL_TRACE calls tracehook_report_syscall_{entry,exit} 2131f5a4ad9SRoland McGrath# TIF_NOTIFY_RESUME calls tracehook_notify_resume() 2141f5a4ad9SRoland McGrath# signal delivery calls tracehook_signal_handler() 2151f5a4ad9SRoland McGrath# 2161f5a4ad9SRoland McGrathconfig HAVE_ARCH_TRACEHOOK 2179ba16087SJan Beulich bool 2181f5a4ad9SRoland McGrath 219c64be2bbSMarek Szyprowskiconfig HAVE_DMA_CONTIGUOUS 220c64be2bbSMarek Szyprowski bool 221c64be2bbSMarek Szyprowski 22229d5e047SThomas Gleixnerconfig GENERIC_SMP_IDLE_THREAD 22329d5e047SThomas Gleixner bool 22429d5e047SThomas Gleixner 225485cf5daSKevin Hilmanconfig GENERIC_IDLE_POLL_SETUP 226485cf5daSKevin Hilman bool 227485cf5daSKevin Hilman 2286974f0c4SDaniel Micayconfig ARCH_HAS_FORTIFY_SOURCE 2296974f0c4SDaniel Micay bool 2306974f0c4SDaniel Micay help 2316974f0c4SDaniel Micay An architecture should select this when it can successfully 2326974f0c4SDaniel Micay build and run with CONFIG_FORTIFY_SOURCE. 2336974f0c4SDaniel Micay 234d8ae8a37SChristoph Hellwig# 235d8ae8a37SChristoph Hellwig# Select if the arch provides a historic keepinit alias for the retain_initrd 236d8ae8a37SChristoph Hellwig# command line option 237d8ae8a37SChristoph Hellwig# 238d8ae8a37SChristoph Hellwigconfig ARCH_HAS_KEEPINITRD 239d8ae8a37SChristoph Hellwig bool 240d8ae8a37SChristoph Hellwig 241d2852a22SDaniel Borkmann# Select if arch has all set_memory_ro/rw/x/nx() functions in asm/cacheflush.h 242d2852a22SDaniel Borkmannconfig ARCH_HAS_SET_MEMORY 243d2852a22SDaniel Borkmann bool 244d2852a22SDaniel Borkmann 245d253ca0cSRick Edgecombe# Select if arch has all set_direct_map_invalid/default() functions 246d253ca0cSRick Edgecombeconfig ARCH_HAS_SET_DIRECT_MAP 247d253ca0cSRick Edgecombe bool 248d253ca0cSRick Edgecombe 249c30700dbSChristoph Hellwig# 250fa7e2247SChristoph Hellwig# Select if the architecture provides the arch_dma_set_uncached symbol to 251a86ecfa6SColin Ian King# either provide an uncached segment alias for a DMA allocation, or 252fa7e2247SChristoph Hellwig# to remap the page tables in place. 253c30700dbSChristoph Hellwig# 254fa7e2247SChristoph Hellwigconfig ARCH_HAS_DMA_SET_UNCACHED 255c30700dbSChristoph Hellwig bool 256c30700dbSChristoph Hellwig 257999a5d12SChristoph Hellwig# 258999a5d12SChristoph Hellwig# Select if the architectures provides the arch_dma_clear_uncached symbol 259999a5d12SChristoph Hellwig# to undo an in-place page table remap for uncached access. 260999a5d12SChristoph Hellwig# 261999a5d12SChristoph Hellwigconfig ARCH_HAS_DMA_CLEAR_UNCACHED 262f5e10287SThomas Gleixner bool 263f5e10287SThomas Gleixner 2645905429aSKees Cook# Select if arch init_task must go in the __init_task_data section 2655905429aSKees Cookconfig ARCH_TASK_STRUCT_ON_STACK 2665905429aSKees Cook bool 2675905429aSKees Cook 2685905429aSKees Cook# Select if arch has its private alloc_task_struct() function 2695905429aSKees Cookconfig ARCH_TASK_STRUCT_ALLOCATOR 2705905429aSKees Cook bool 2715905429aSKees Cook 2725905429aSKees Cookconfig HAVE_ARCH_THREAD_STRUCT_WHITELIST 2735905429aSKees Cook bool 2745905429aSKees Cook depends on !ARCH_TASK_STRUCT_ALLOCATOR 275b235beeaSLinus Torvalds help 276b235beeaSLinus Torvalds An architecture should select this to provide hardened usercopy 277f5e10287SThomas Gleixner knowledge about what region of the thread_struct should be 278f5e10287SThomas Gleixner whitelisted for copying to userspace. Normally this is only the 2795aaeb5c0SIngo Molnar FPU registers. Specifically, arch_thread_struct_whitelist() 2805aaeb5c0SIngo Molnar should be implemented. Without this, the entire thread_struct 2815aaeb5c0SIngo Molnar field in task_struct will be left whitelisted. 2825aaeb5c0SIngo Molnar 283942fa985SYury Norov# Select if arch has its private alloc_thread_stack() function 284942fa985SYury Norovconfig ARCH_THREAD_STACK_ALLOCATOR 285942fa985SYury Norov bool 286942fa985SYury Norov 287942fa985SYury Norov# Select if arch wants to size task_struct dynamically via arch_task_struct_size: 288942fa985SYury Norovconfig ARCH_WANTS_DYNAMIC_TASK_STRUCT 289942fa985SYury Norov bool 290942fa985SYury Norov 29151c2ee6dSNick Desaulniersconfig ARCH_WANTS_NO_INSTR 29251c2ee6dSNick Desaulniers bool 29351c2ee6dSNick Desaulniers help 29451c2ee6dSNick Desaulniers An architecture should select this if the noinstr macro is being used on 29551c2ee6dSNick Desaulniers functions to denote that the toolchain should avoid instrumenting such 29651c2ee6dSNick Desaulniers functions and is required for correctness. 29751c2ee6dSNick Desaulniers 298942fa985SYury Norovconfig ARCH_32BIT_OFF_T 299942fa985SYury Norov bool 300942fa985SYury Norov depends on !64BIT 301942fa985SYury Norov help 302942fa985SYury Norov All new 32-bit architectures should have 64-bit off_t type on 303942fa985SYury Norov userspace side which corresponds to the loff_t kernel type. This 304942fa985SYury Norov is the requirement for modern ABIs. Some existing architectures 305942fa985SYury Norov still support 32-bit off_t. This option is enabled for all such 306942fa985SYury Norov architectures explicitly. 307942fa985SYury Norov 30896c0a6a7SHeiko Carstens# Selected by 64 bit architectures which have a 32 bit f_tinode in struct ustat 30996c0a6a7SHeiko Carstensconfig ARCH_32BIT_USTAT_F_TINODE 31096c0a6a7SHeiko Carstens bool 31196c0a6a7SHeiko Carstens 3122ff2b7ecSMasahiro Yamadaconfig HAVE_ASM_MODVERSIONS 3132ff2b7ecSMasahiro Yamada bool 3142ff2b7ecSMasahiro Yamada help 315a86ecfa6SColin Ian King This symbol should be selected by an architecture if it provides 3162ff2b7ecSMasahiro Yamada <asm/asm-prototypes.h> to support the module versioning for symbols 3172ff2b7ecSMasahiro Yamada exported from assembly code. 3182ff2b7ecSMasahiro Yamada 319f850c30cSHeiko Carstensconfig HAVE_REGS_AND_STACK_ACCESS_API 320f850c30cSHeiko Carstens bool 321e01292b1SHeiko Carstens help 322a86ecfa6SColin Ian King This symbol should be selected by an architecture if it supports 323e01292b1SHeiko Carstens the API needed to access registers and stack entries from pt_regs, 324e01292b1SHeiko Carstens declared in asm/ptrace.h 325e01292b1SHeiko Carstens For example the kprobes-based event tracer needs this API. 326f850c30cSHeiko Carstens 327d7822b1eSMathieu Desnoyersconfig HAVE_RSEQ 328d7822b1eSMathieu Desnoyers bool 329d7822b1eSMathieu Desnoyers depends on HAVE_REGS_AND_STACK_ACCESS_API 330d7822b1eSMathieu Desnoyers help 331d7822b1eSMathieu Desnoyers This symbol should be selected by an architecture if it 332d7822b1eSMathieu Desnoyers supports an implementation of restartable sequences. 333d7822b1eSMathieu Desnoyers 3343c88ee19SMasami Hiramatsuconfig HAVE_FUNCTION_ARG_ACCESS_API 3353c88ee19SMasami Hiramatsu bool 3363c88ee19SMasami Hiramatsu help 337a86ecfa6SColin Ian King This symbol should be selected by an architecture if it supports 3383c88ee19SMasami Hiramatsu the API needed to access function arguments from pt_regs, 3393c88ee19SMasami Hiramatsu declared in asm/ptrace.h 3403c88ee19SMasami Hiramatsu 34162a038d3SK.Prasadconfig HAVE_HW_BREAKPOINT 34262a038d3SK.Prasad bool 34399e8c5a3SFrederic Weisbecker depends on PERF_EVENTS 34462a038d3SK.Prasad 3450102752eSFrederic Weisbeckerconfig HAVE_MIXED_BREAKPOINTS_REGS 3460102752eSFrederic Weisbecker bool 3470102752eSFrederic Weisbecker depends on HAVE_HW_BREAKPOINT 3480102752eSFrederic Weisbecker help 3490102752eSFrederic Weisbecker Depending on the arch implementation of hardware breakpoints, 3500102752eSFrederic Weisbecker some of them have separate registers for data and instruction 3510102752eSFrederic Weisbecker breakpoints addresses, others have mixed registers to store 3520102752eSFrederic Weisbecker them but define the access type in a control register. 3530102752eSFrederic Weisbecker Select this option if your arch implements breakpoints under the 3540102752eSFrederic Weisbecker latter fashion. 3550102752eSFrederic Weisbecker 3567c68af6eSAvi Kivityconfig HAVE_USER_RETURN_NOTIFIER 3577c68af6eSAvi Kivity bool 358a1922ed6SIngo Molnar 359c01d4323SFrederic Weisbeckerconfig HAVE_PERF_EVENTS_NMI 360c01d4323SFrederic Weisbecker bool 36123637d47SFrederic Weisbecker help 36223637d47SFrederic Weisbecker System hardware can generate an NMI using the perf event 36323637d47SFrederic Weisbecker subsystem. Also has support for calculating CPU cycle events 36423637d47SFrederic Weisbecker to determine how many clock cycles in a given period. 365c01d4323SFrederic Weisbecker 36605a4a952SNicholas Pigginconfig HAVE_HARDLOCKUP_DETECTOR_PERF 36705a4a952SNicholas Piggin bool 36805a4a952SNicholas Piggin depends on HAVE_PERF_EVENTS_NMI 36905a4a952SNicholas Piggin help 37005a4a952SNicholas Piggin The arch chooses to use the generic perf-NMI-based hardlockup 37105a4a952SNicholas Piggin detector. Must define HAVE_PERF_EVENTS_NMI. 37205a4a952SNicholas Piggin 37305a4a952SNicholas Pigginconfig HAVE_NMI_WATCHDOG 37405a4a952SNicholas Piggin depends on HAVE_NMI 37505a4a952SNicholas Piggin bool 37605a4a952SNicholas Piggin help 37705a4a952SNicholas Piggin The arch provides a low level NMI watchdog. It provides 37805a4a952SNicholas Piggin asm/nmi.h, and defines its own arch_touch_nmi_watchdog(). 37905a4a952SNicholas Piggin 38005a4a952SNicholas Pigginconfig HAVE_HARDLOCKUP_DETECTOR_ARCH 38105a4a952SNicholas Piggin bool 38205a4a952SNicholas Piggin select HAVE_NMI_WATCHDOG 38305a4a952SNicholas Piggin help 38405a4a952SNicholas Piggin The arch chooses to provide its own hardlockup detector, which is 38505a4a952SNicholas Piggin a superset of the HAVE_NMI_WATCHDOG. It also conforms to config 38605a4a952SNicholas Piggin interfaces and parameters provided by hardlockup detector subsystem. 38705a4a952SNicholas Piggin 388c5e63197SJiri Olsaconfig HAVE_PERF_REGS 389c5e63197SJiri Olsa bool 390c5e63197SJiri Olsa help 391c5e63197SJiri Olsa Support selective register dumps for perf events. This includes 392c5e63197SJiri Olsa bit-mapping of each registers and a unique architecture id. 393c5e63197SJiri Olsa 394c5ebcedbSJiri Olsaconfig HAVE_PERF_USER_STACK_DUMP 395c5ebcedbSJiri Olsa bool 396c5ebcedbSJiri Olsa help 397c5ebcedbSJiri Olsa Support user stack dumps for perf event samples. This needs 398c5ebcedbSJiri Olsa access to the user stack pointer which is not unified across 399c5ebcedbSJiri Olsa architectures. 400c5ebcedbSJiri Olsa 401bf5438fcSJason Baronconfig HAVE_ARCH_JUMP_LABEL 402bf5438fcSJason Baron bool 403bf5438fcSJason Baron 40450ff18abSArd Biesheuvelconfig HAVE_ARCH_JUMP_LABEL_RELATIVE 40550ff18abSArd Biesheuvel bool 40650ff18abSArd Biesheuvel 4070d6e24d4SPeter Zijlstraconfig MMU_GATHER_TABLE_FREE 4080d6e24d4SPeter Zijlstra bool 4090d6e24d4SPeter Zijlstra 410ff2e6d72SPeter Zijlstraconfig MMU_GATHER_RCU_TABLE_FREE 41126723911SPeter Zijlstra bool 4120d6e24d4SPeter Zijlstra select MMU_GATHER_TABLE_FREE 41326723911SPeter Zijlstra 4143af4bd03SPeter Zijlstraconfig MMU_GATHER_PAGE_SIZE 415ed6a7935SPeter Zijlstra bool 416ed6a7935SPeter Zijlstra 41727796d03SPeter Zijlstraconfig MMU_GATHER_NO_RANGE 41827796d03SPeter Zijlstra bool 41927796d03SPeter Zijlstra 420580a586cSPeter Zijlstraconfig MMU_GATHER_NO_GATHER 421952a31c9SMartin Schwidefsky bool 4220d6e24d4SPeter Zijlstra depends on MMU_GATHER_TABLE_FREE 423952a31c9SMartin Schwidefsky 424d53c3dfbSNicholas Pigginconfig ARCH_WANT_IRQS_OFF_ACTIVATE_MM 425d53c3dfbSNicholas Piggin bool 426d53c3dfbSNicholas Piggin help 427d53c3dfbSNicholas Piggin Temporary select until all architectures can be converted to have 428d53c3dfbSNicholas Piggin irqs disabled over activate_mm. Architectures that do IPI based TLB 429d53c3dfbSNicholas Piggin shootdowns should enable this. 430d53c3dfbSNicholas Piggin 431df013ffbSHuang Yingconfig ARCH_HAVE_NMI_SAFE_CMPXCHG 432df013ffbSHuang Ying bool 433df013ffbSHuang Ying 43443570fd2SHeiko Carstensconfig HAVE_ALIGNED_STRUCT_PAGE 43543570fd2SHeiko Carstens bool 43643570fd2SHeiko Carstens help 43743570fd2SHeiko Carstens This makes sure that struct pages are double word aligned and that 43843570fd2SHeiko Carstens e.g. the SLUB allocator can perform double word atomic operations 43943570fd2SHeiko Carstens on a struct page for better performance. However selecting this 44043570fd2SHeiko Carstens might increase the size of a struct page by a word. 44143570fd2SHeiko Carstens 4424156153cSHeiko Carstensconfig HAVE_CMPXCHG_LOCAL 4434156153cSHeiko Carstens bool 4444156153cSHeiko Carstens 4452565409fSHeiko Carstensconfig HAVE_CMPXCHG_DOUBLE 4462565409fSHeiko Carstens bool 4472565409fSHeiko Carstens 44877e58496SPaul E. McKenneyconfig ARCH_WEAK_RELEASE_ACQUIRE 44977e58496SPaul E. McKenney bool 45077e58496SPaul E. McKenney 451c1d7e01dSWill Deaconconfig ARCH_WANT_IPC_PARSE_VERSION 452c1d7e01dSWill Deacon bool 453c1d7e01dSWill Deacon 454c1d7e01dSWill Deaconconfig ARCH_WANT_COMPAT_IPC_PARSE_VERSION 455c1d7e01dSWill Deacon bool 456c1d7e01dSWill Deacon 45748b25c43SChris Metcalfconfig ARCH_WANT_OLD_COMPAT_IPC 458c1d7e01dSWill Deacon select ARCH_WANT_COMPAT_IPC_PARSE_VERSION 45948b25c43SChris Metcalf bool 46048b25c43SChris Metcalf 461282a181bSYiFei Zhuconfig HAVE_ARCH_SECCOMP 462e2cfabdfSWill Drewry bool 463e2cfabdfSWill Drewry help 464282a181bSYiFei Zhu An arch should select this symbol to support seccomp mode 1 (the fixed 465282a181bSYiFei Zhu syscall policy), and must provide an overrides for __NR_seccomp_sigreturn, 466282a181bSYiFei Zhu and compat syscalls if the asm-generic/seccomp.h defaults need adjustment: 467282a181bSYiFei Zhu - __NR_seccomp_read_32 468282a181bSYiFei Zhu - __NR_seccomp_write_32 469282a181bSYiFei Zhu - __NR_seccomp_exit_32 470282a181bSYiFei Zhu - __NR_seccomp_sigreturn_32 471282a181bSYiFei Zhu 472282a181bSYiFei Zhuconfig HAVE_ARCH_SECCOMP_FILTER 473282a181bSYiFei Zhu bool 474282a181bSYiFei Zhu select HAVE_ARCH_SECCOMP 475282a181bSYiFei Zhu help 476fb0fadf9SWill Drewry An arch should select this symbol if it provides all of these things: 477282a181bSYiFei Zhu - all the requirements for HAVE_ARCH_SECCOMP 478bb6ea430SWill Drewry - syscall_get_arch() 479bb6ea430SWill Drewry - syscall_get_arguments() 480bb6ea430SWill Drewry - syscall_rollback() 481bb6ea430SWill Drewry - syscall_set_return_value() 482fb0fadf9SWill Drewry - SIGSYS siginfo_t support 483fb0fadf9SWill Drewry - secure_computing is called from a ptrace_event()-safe context 484fb0fadf9SWill Drewry - secure_computing return value is checked and a return value of -1 485fb0fadf9SWill Drewry results in the system call being skipped immediately. 48648dc92b9SKees Cook - seccomp syscall wired up 4870d8315ddSYiFei Zhu - if !HAVE_SPARSE_SYSCALL_NR, have SECCOMP_ARCH_NATIVE, 4880d8315ddSYiFei Zhu SECCOMP_ARCH_NATIVE_NR, SECCOMP_ARCH_NATIVE_NAME defined. If 4890d8315ddSYiFei Zhu COMPAT is supported, have the SECCOMP_ARCH_COMPAT* defines too. 490e2cfabdfSWill Drewry 491282a181bSYiFei Zhuconfig SECCOMP 492282a181bSYiFei Zhu prompt "Enable seccomp to safely execute untrusted bytecode" 493282a181bSYiFei Zhu def_bool y 494282a181bSYiFei Zhu depends on HAVE_ARCH_SECCOMP 495282a181bSYiFei Zhu help 496282a181bSYiFei Zhu This kernel feature is useful for number crunching applications 497282a181bSYiFei Zhu that may need to handle untrusted bytecode during their 498282a181bSYiFei Zhu execution. By using pipes or other transports made available 499282a181bSYiFei Zhu to the process as file descriptors supporting the read/write 500282a181bSYiFei Zhu syscalls, it's possible to isolate those applications in their 501282a181bSYiFei Zhu own address space using seccomp. Once seccomp is enabled via 502282a181bSYiFei Zhu prctl(PR_SET_SECCOMP) or the seccomp() syscall, it cannot be 503282a181bSYiFei Zhu disabled and the task is only allowed to execute a few safe 504282a181bSYiFei Zhu syscalls defined by each seccomp mode. 505282a181bSYiFei Zhu 506282a181bSYiFei Zhu If unsure, say Y. 507282a181bSYiFei Zhu 508e2cfabdfSWill Drewryconfig SECCOMP_FILTER 509e2cfabdfSWill Drewry def_bool y 510e2cfabdfSWill Drewry depends on HAVE_ARCH_SECCOMP_FILTER && SECCOMP && NET 511e2cfabdfSWill Drewry help 512e2cfabdfSWill Drewry Enable tasks to build secure computing environments defined 513e2cfabdfSWill Drewry in terms of Berkeley Packet Filter programs which implement 514e2cfabdfSWill Drewry task-defined system call filtering polices. 515e2cfabdfSWill Drewry 5165fb94e9cSMauro Carvalho Chehab See Documentation/userspace-api/seccomp_filter.rst for details. 517e2cfabdfSWill Drewry 5180d8315ddSYiFei Zhuconfig SECCOMP_CACHE_DEBUG 5190d8315ddSYiFei Zhu bool "Show seccomp filter cache status in /proc/pid/seccomp_cache" 5200d8315ddSYiFei Zhu depends on SECCOMP_FILTER && !HAVE_SPARSE_SYSCALL_NR 5210d8315ddSYiFei Zhu depends on PROC_FS 5220d8315ddSYiFei Zhu help 5230d8315ddSYiFei Zhu This enables the /proc/pid/seccomp_cache interface to monitor 5240d8315ddSYiFei Zhu seccomp cache data. The file format is subject to change. Reading 5250d8315ddSYiFei Zhu the file requires CAP_SYS_ADMIN. 5260d8315ddSYiFei Zhu 5270d8315ddSYiFei Zhu This option is for debugging only. Enabling presents the risk that 5280d8315ddSYiFei Zhu an adversary may be able to infer the seccomp filter logic. 5290d8315ddSYiFei Zhu 5300d8315ddSYiFei Zhu If unsure, say N. 5310d8315ddSYiFei Zhu 532afaef01cSAlexander Popovconfig HAVE_ARCH_STACKLEAK 533afaef01cSAlexander Popov bool 534afaef01cSAlexander Popov help 535afaef01cSAlexander Popov An architecture should select this if it has the code which 536afaef01cSAlexander Popov fills the used part of the kernel stack with the STACKLEAK_POISON 537afaef01cSAlexander Popov value before returning from system calls. 538afaef01cSAlexander Popov 539d148eac0SMasahiro Yamadaconfig HAVE_STACKPROTECTOR 54019952a92SKees Cook bool 54119952a92SKees Cook help 54219952a92SKees Cook An arch should select this symbol if: 54319952a92SKees Cook - it has implemented a stack canary (e.g. __stack_chk_guard) 54419952a92SKees Cook 545050e9baaSLinus Torvaldsconfig STACKPROTECTOR 5462a61f474SMasahiro Yamada bool "Stack Protector buffer overflow detection" 547d148eac0SMasahiro Yamada depends on HAVE_STACKPROTECTOR 5482a61f474SMasahiro Yamada depends on $(cc-option,-fstack-protector) 5492a61f474SMasahiro Yamada default y 5508779657dSKees Cook help 5518779657dSKees Cook This option turns on the "stack-protector" GCC feature. This 55219952a92SKees Cook feature puts, at the beginning of functions, a canary value on 55319952a92SKees Cook the stack just before the return address, and validates 55419952a92SKees Cook the value just before actually returning. Stack based buffer 55519952a92SKees Cook overflows (that need to overwrite this return address) now also 55619952a92SKees Cook overwrite the canary, which gets detected and the attack is then 55719952a92SKees Cook neutralized via a kernel panic. 55819952a92SKees Cook 5598779657dSKees Cook Functions will have the stack-protector canary logic added if they 5608779657dSKees Cook have an 8-byte or larger character array on the stack. 5618779657dSKees Cook 56219952a92SKees Cook This feature requires gcc version 4.2 or above, or a distribution 5638779657dSKees Cook gcc with the feature backported ("-fstack-protector"). 5648779657dSKees Cook 5658779657dSKees Cook On an x86 "defconfig" build, this feature adds canary checks to 5668779657dSKees Cook about 3% of all kernel functions, which increases kernel code size 5678779657dSKees Cook by about 0.3%. 5688779657dSKees Cook 569050e9baaSLinus Torvaldsconfig STACKPROTECTOR_STRONG 5702a61f474SMasahiro Yamada bool "Strong Stack Protector" 571050e9baaSLinus Torvalds depends on STACKPROTECTOR 5722a61f474SMasahiro Yamada depends on $(cc-option,-fstack-protector-strong) 5732a61f474SMasahiro Yamada default y 5748779657dSKees Cook help 5758779657dSKees Cook Functions will have the stack-protector canary logic added in any 5768779657dSKees Cook of the following conditions: 5778779657dSKees Cook 5788779657dSKees Cook - local variable's address used as part of the right hand side of an 5798779657dSKees Cook assignment or function argument 5808779657dSKees Cook - local variable is an array (or union containing an array), 5818779657dSKees Cook regardless of array type or length 5828779657dSKees Cook - uses register local variables 5838779657dSKees Cook 5848779657dSKees Cook This feature requires gcc version 4.9 or above, or a distribution 5858779657dSKees Cook gcc with the feature backported ("-fstack-protector-strong"). 5868779657dSKees Cook 5878779657dSKees Cook On an x86 "defconfig" build, this feature adds canary checks to 5888779657dSKees Cook about 20% of all kernel functions, which increases the kernel code 5898779657dSKees Cook size by about 2%. 5908779657dSKees Cook 591d08b9f0cSSami Tolvanenconfig ARCH_SUPPORTS_SHADOW_CALL_STACK 592d08b9f0cSSami Tolvanen bool 593d08b9f0cSSami Tolvanen help 594d08b9f0cSSami Tolvanen An architecture should select this if it supports Clang's Shadow 595aa7a65aeSWill Deacon Call Stack and implements runtime support for shadow stack 596aa7a65aeSWill Deacon switching. 597d08b9f0cSSami Tolvanen 598d08b9f0cSSami Tolvanenconfig SHADOW_CALL_STACK 599d08b9f0cSSami Tolvanen bool "Clang Shadow Call Stack" 600d08b9f0cSSami Tolvanen depends on CC_IS_CLANG && ARCH_SUPPORTS_SHADOW_CALL_STACK 601ddc9863eSSami Tolvanen depends on DYNAMIC_FTRACE_WITH_REGS || !FUNCTION_GRAPH_TRACER 602d08b9f0cSSami Tolvanen help 603d08b9f0cSSami Tolvanen This option enables Clang's Shadow Call Stack, which uses a 604d08b9f0cSSami Tolvanen shadow stack to protect function return addresses from being 605d08b9f0cSSami Tolvanen overwritten by an attacker. More information can be found in 606d08b9f0cSSami Tolvanen Clang's documentation: 607d08b9f0cSSami Tolvanen 608d08b9f0cSSami Tolvanen https://clang.llvm.org/docs/ShadowCallStack.html 609d08b9f0cSSami Tolvanen 610d08b9f0cSSami Tolvanen Note that security guarantees in the kernel differ from the 611d08b9f0cSSami Tolvanen ones documented for user space. The kernel must store addresses 612d08b9f0cSSami Tolvanen of shadow stacks in memory, which means an attacker capable of 613d08b9f0cSSami Tolvanen reading and writing arbitrary memory may be able to locate them 614d08b9f0cSSami Tolvanen and hijack control flow by modifying the stacks. 615d08b9f0cSSami Tolvanen 616dc5723b0SSami Tolvanenconfig LTO 617dc5723b0SSami Tolvanen bool 618dc5723b0SSami Tolvanen help 619dc5723b0SSami Tolvanen Selected if the kernel will be built using the compiler's LTO feature. 620dc5723b0SSami Tolvanen 621dc5723b0SSami Tolvanenconfig LTO_CLANG 622dc5723b0SSami Tolvanen bool 623dc5723b0SSami Tolvanen select LTO 624dc5723b0SSami Tolvanen help 625dc5723b0SSami Tolvanen Selected if the kernel will be built using Clang's LTO feature. 626dc5723b0SSami Tolvanen 627dc5723b0SSami Tolvanenconfig ARCH_SUPPORTS_LTO_CLANG 628dc5723b0SSami Tolvanen bool 629dc5723b0SSami Tolvanen help 630dc5723b0SSami Tolvanen An architecture should select this option if it supports: 631dc5723b0SSami Tolvanen - compiling with Clang, 632dc5723b0SSami Tolvanen - compiling inline assembly with Clang's integrated assembler, 633dc5723b0SSami Tolvanen - and linking with LLD. 634dc5723b0SSami Tolvanen 635dc5723b0SSami Tolvanenconfig ARCH_SUPPORTS_LTO_CLANG_THIN 636dc5723b0SSami Tolvanen bool 637dc5723b0SSami Tolvanen help 638dc5723b0SSami Tolvanen An architecture should select this option if it can support Clang's 639dc5723b0SSami Tolvanen ThinLTO mode. 640dc5723b0SSami Tolvanen 641dc5723b0SSami Tolvanenconfig HAS_LTO_CLANG 642dc5723b0SSami Tolvanen def_bool y 643dc5723b0SSami Tolvanen # Clang >= 11: https://github.com/ClangBuiltLinux/linux/issues/510 644ba64beb1SMasahiro Yamada depends on CC_IS_CLANG && CLANG_VERSION >= 110000 && LD_IS_LLD && AS_IS_LLVM 645dc5723b0SSami Tolvanen depends on $(success,$(NM) --help | head -n 1 | grep -qi llvm) 646dc5723b0SSami Tolvanen depends on $(success,$(AR) --help | head -n 1 | grep -qi llvm) 647dc5723b0SSami Tolvanen depends on ARCH_SUPPORTS_LTO_CLANG 648dc5723b0SSami Tolvanen depends on !FTRACE_MCOUNT_USE_RECORDMCOUNT 649bf3c2551SSami Tolvanen depends on !KASAN || KASAN_HW_TAGS 650dc5723b0SSami Tolvanen depends on !GCOV_KERNEL 651dc5723b0SSami Tolvanen help 652dc5723b0SSami Tolvanen The compiler and Kconfig options support building with Clang's 653dc5723b0SSami Tolvanen LTO. 654dc5723b0SSami Tolvanen 655dc5723b0SSami Tolvanenchoice 656dc5723b0SSami Tolvanen prompt "Link Time Optimization (LTO)" 657dc5723b0SSami Tolvanen default LTO_NONE 658dc5723b0SSami Tolvanen help 659dc5723b0SSami Tolvanen This option enables Link Time Optimization (LTO), which allows the 660dc5723b0SSami Tolvanen compiler to optimize binaries globally. 661dc5723b0SSami Tolvanen 662dc5723b0SSami Tolvanen If unsure, select LTO_NONE. Note that LTO is very resource-intensive 663dc5723b0SSami Tolvanen so it's disabled by default. 664dc5723b0SSami Tolvanen 665dc5723b0SSami Tolvanenconfig LTO_NONE 666dc5723b0SSami Tolvanen bool "None" 667dc5723b0SSami Tolvanen help 668dc5723b0SSami Tolvanen Build the kernel normally, without Link Time Optimization (LTO). 669dc5723b0SSami Tolvanen 670dc5723b0SSami Tolvanenconfig LTO_CLANG_FULL 671dc5723b0SSami Tolvanen bool "Clang Full LTO (EXPERIMENTAL)" 672dc5723b0SSami Tolvanen depends on HAS_LTO_CLANG 673dc5723b0SSami Tolvanen depends on !COMPILE_TEST 674dc5723b0SSami Tolvanen select LTO_CLANG 675dc5723b0SSami Tolvanen help 676dc5723b0SSami Tolvanen This option enables Clang's full Link Time Optimization (LTO), which 677dc5723b0SSami Tolvanen allows the compiler to optimize the kernel globally. If you enable 678dc5723b0SSami Tolvanen this option, the compiler generates LLVM bitcode instead of ELF 679dc5723b0SSami Tolvanen object files, and the actual compilation from bitcode happens at 680dc5723b0SSami Tolvanen the LTO link step, which may take several minutes depending on the 681dc5723b0SSami Tolvanen kernel configuration. More information can be found from LLVM's 682dc5723b0SSami Tolvanen documentation: 683dc5723b0SSami Tolvanen 684dc5723b0SSami Tolvanen https://llvm.org/docs/LinkTimeOptimization.html 685dc5723b0SSami Tolvanen 686dc5723b0SSami Tolvanen During link time, this option can use a large amount of RAM, and 687dc5723b0SSami Tolvanen may take much longer than the ThinLTO option. 688dc5723b0SSami Tolvanen 689dc5723b0SSami Tolvanenconfig LTO_CLANG_THIN 690dc5723b0SSami Tolvanen bool "Clang ThinLTO (EXPERIMENTAL)" 691dc5723b0SSami Tolvanen depends on HAS_LTO_CLANG && ARCH_SUPPORTS_LTO_CLANG_THIN 692dc5723b0SSami Tolvanen select LTO_CLANG 693dc5723b0SSami Tolvanen help 694dc5723b0SSami Tolvanen This option enables Clang's ThinLTO, which allows for parallel 695dc5723b0SSami Tolvanen optimization and faster incremental compiles compared to the 696dc5723b0SSami Tolvanen CONFIG_LTO_CLANG_FULL option. More information can be found 697dc5723b0SSami Tolvanen from Clang's documentation: 698dc5723b0SSami Tolvanen 699dc5723b0SSami Tolvanen https://clang.llvm.org/docs/ThinLTO.html 700dc5723b0SSami Tolvanen 701dc5723b0SSami Tolvanen If unsure, say Y. 702dc5723b0SSami Tolvanenendchoice 703dc5723b0SSami Tolvanen 704cf68fffbSSami Tolvanenconfig ARCH_SUPPORTS_CFI_CLANG 705cf68fffbSSami Tolvanen bool 706cf68fffbSSami Tolvanen help 707cf68fffbSSami Tolvanen An architecture should select this option if it can support Clang's 708cf68fffbSSami Tolvanen Control-Flow Integrity (CFI) checking. 709cf68fffbSSami Tolvanen 710cf68fffbSSami Tolvanenconfig CFI_CLANG 711cf68fffbSSami Tolvanen bool "Use Clang's Control Flow Integrity (CFI)" 712cf68fffbSSami Tolvanen depends on LTO_CLANG && ARCH_SUPPORTS_CFI_CLANG 713cf68fffbSSami Tolvanen # Clang >= 12: 714cf68fffbSSami Tolvanen # - https://bugs.llvm.org/show_bug.cgi?id=46258 715cf68fffbSSami Tolvanen # - https://bugs.llvm.org/show_bug.cgi?id=47479 716cf68fffbSSami Tolvanen depends on CLANG_VERSION >= 120000 717cf68fffbSSami Tolvanen select KALLSYMS 718cf68fffbSSami Tolvanen help 719cf68fffbSSami Tolvanen This option enables Clang’s forward-edge Control Flow Integrity 720cf68fffbSSami Tolvanen (CFI) checking, where the compiler injects a runtime check to each 721cf68fffbSSami Tolvanen indirect function call to ensure the target is a valid function with 722cf68fffbSSami Tolvanen the correct static type. This restricts possible call targets and 723cf68fffbSSami Tolvanen makes it more difficult for an attacker to exploit bugs that allow 724cf68fffbSSami Tolvanen the modification of stored function pointers. More information can be 725cf68fffbSSami Tolvanen found from Clang's documentation: 726cf68fffbSSami Tolvanen 727cf68fffbSSami Tolvanen https://clang.llvm.org/docs/ControlFlowIntegrity.html 728cf68fffbSSami Tolvanen 729cf68fffbSSami Tolvanenconfig CFI_CLANG_SHADOW 730cf68fffbSSami Tolvanen bool "Use CFI shadow to speed up cross-module checks" 731cf68fffbSSami Tolvanen default y 732cf68fffbSSami Tolvanen depends on CFI_CLANG && MODULES 733cf68fffbSSami Tolvanen help 734cf68fffbSSami Tolvanen If you select this option, the kernel builds a fast look-up table of 735cf68fffbSSami Tolvanen CFI check functions in loaded modules to reduce performance overhead. 736cf68fffbSSami Tolvanen 737cf68fffbSSami Tolvanen If unsure, say Y. 738cf68fffbSSami Tolvanen 739cf68fffbSSami Tolvanenconfig CFI_PERMISSIVE 740cf68fffbSSami Tolvanen bool "Use CFI in permissive mode" 741cf68fffbSSami Tolvanen depends on CFI_CLANG 742cf68fffbSSami Tolvanen help 743cf68fffbSSami Tolvanen When selected, Control Flow Integrity (CFI) violations result in a 744cf68fffbSSami Tolvanen warning instead of a kernel panic. This option should only be used 745cf68fffbSSami Tolvanen for finding indirect call type mismatches during development. 746cf68fffbSSami Tolvanen 747cf68fffbSSami Tolvanen If unsure, say N. 748cf68fffbSSami Tolvanen 7490f60a8efSKees Cookconfig HAVE_ARCH_WITHIN_STACK_FRAMES 7500f60a8efSKees Cook bool 7510f60a8efSKees Cook help 7520f60a8efSKees Cook An architecture should select this if it can walk the kernel stack 7530f60a8efSKees Cook frames to determine if an object is part of either the arguments 7540f60a8efSKees Cook or local variables (i.e. that it excludes saved return addresses, 7550f60a8efSKees Cook and similar) by implementing an inline arch_within_stack_frames(), 7560f60a8efSKees Cook which is used by CONFIG_HARDENED_USERCOPY. 7570f60a8efSKees Cook 75891d1aa43SFrederic Weisbeckerconfig HAVE_CONTEXT_TRACKING 7592b1d5024SFrederic Weisbecker bool 7602b1d5024SFrederic Weisbecker help 76191d1aa43SFrederic Weisbecker Provide kernel/user boundaries probes necessary for subsystems 76291d1aa43SFrederic Weisbecker that need it, such as userspace RCU extended quiescent state. 763490f561bSFrederic Weisbecker Syscalls need to be wrapped inside user_exit()-user_enter(), either 764490f561bSFrederic Weisbecker optimized behind static key or through the slow path using TIF_NOHZ 765490f561bSFrederic Weisbecker flag. Exceptions handlers must be wrapped as well. Irqs are already 766490f561bSFrederic Weisbecker protected inside rcu_irq_enter/rcu_irq_exit() but preemption or signal 767490f561bSFrederic Weisbecker handling on irq exit still need to be protected. 768490f561bSFrederic Weisbecker 76983c2da2eSFrederic Weisbeckerconfig HAVE_CONTEXT_TRACKING_OFFSTACK 77083c2da2eSFrederic Weisbecker bool 77183c2da2eSFrederic Weisbecker help 77283c2da2eSFrederic Weisbecker Architecture neither relies on exception_enter()/exception_exit() 77383c2da2eSFrederic Weisbecker nor on schedule_user(). Also preempt_schedule_notrace() and 77483c2da2eSFrederic Weisbecker preempt_schedule_irq() can't be called in a preemptible section 77583c2da2eSFrederic Weisbecker while context tracking is CONTEXT_USER. This feature reflects a sane 77683c2da2eSFrederic Weisbecker entry implementation where the following requirements are met on 77783c2da2eSFrederic Weisbecker critical entry code, ie: before user_exit() or after user_enter(): 77883c2da2eSFrederic Weisbecker 77983c2da2eSFrederic Weisbecker - Critical entry code isn't preemptible (or better yet: 78083c2da2eSFrederic Weisbecker not interruptible). 78183c2da2eSFrederic Weisbecker - No use of RCU read side critical sections, unless rcu_nmi_enter() 78283c2da2eSFrederic Weisbecker got called. 78383c2da2eSFrederic Weisbecker - No use of instrumentation, unless instrumentation_begin() got 78483c2da2eSFrederic Weisbecker called. 78583c2da2eSFrederic Weisbecker 786490f561bSFrederic Weisbeckerconfig HAVE_TIF_NOHZ 787490f561bSFrederic Weisbecker bool 788490f561bSFrederic Weisbecker help 789490f561bSFrederic Weisbecker Arch relies on TIF_NOHZ and syscall slow path to implement context 790490f561bSFrederic Weisbecker tracking calls to user_enter()/user_exit(). 7912b1d5024SFrederic Weisbecker 792b952741cSFrederic Weisbeckerconfig HAVE_VIRT_CPU_ACCOUNTING 793b952741cSFrederic Weisbecker bool 794b952741cSFrederic Weisbecker 7952b91ec9fSFrederic Weisbeckerconfig HAVE_VIRT_CPU_ACCOUNTING_IDLE 7962b91ec9fSFrederic Weisbecker bool 7972b91ec9fSFrederic Weisbecker help 7982b91ec9fSFrederic Weisbecker Architecture has its own way to account idle CPU time and therefore 7992b91ec9fSFrederic Weisbecker doesn't implement vtime_account_idle(). 8002b91ec9fSFrederic Weisbecker 80140565b5aSStanislaw Gruszkaconfig ARCH_HAS_SCALED_CPUTIME 80240565b5aSStanislaw Gruszka bool 80340565b5aSStanislaw Gruszka 804554b0004SKevin Hilmanconfig HAVE_VIRT_CPU_ACCOUNTING_GEN 805554b0004SKevin Hilman bool 806554b0004SKevin Hilman default y if 64BIT 807554b0004SKevin Hilman help 808554b0004SKevin Hilman With VIRT_CPU_ACCOUNTING_GEN, cputime_t becomes 64-bit. 809554b0004SKevin Hilman Before enabling this option, arch code must be audited 810554b0004SKevin Hilman to ensure there are no races in concurrent read/write of 811554b0004SKevin Hilman cputime_t. For example, reading/writing 64-bit cputime_t on 812554b0004SKevin Hilman some 32-bit arches may require multiple accesses, so proper 813554b0004SKevin Hilman locking is needed to protect against concurrent accesses. 814554b0004SKevin Hilman 815fdf9c356SFrederic Weisbeckerconfig HAVE_IRQ_TIME_ACCOUNTING 816fdf9c356SFrederic Weisbecker bool 817fdf9c356SFrederic Weisbecker help 818fdf9c356SFrederic Weisbecker Archs need to ensure they use a high enough resolution clock to 819fdf9c356SFrederic Weisbecker support irq time accounting and then call enable_sched_clock_irqtime(). 820fdf9c356SFrederic Weisbecker 821c49dd340SKalesh Singhconfig HAVE_MOVE_PUD 822c49dd340SKalesh Singh bool 823c49dd340SKalesh Singh help 824c49dd340SKalesh Singh Architectures that select this are able to move page tables at the 825c49dd340SKalesh Singh PUD level. If there are only 3 page table levels, the move effectively 826c49dd340SKalesh Singh happens at the PGD level. 827c49dd340SKalesh Singh 8282c91bd4aSJoel Fernandes (Google)config HAVE_MOVE_PMD 8292c91bd4aSJoel Fernandes (Google) bool 8302c91bd4aSJoel Fernandes (Google) help 8312c91bd4aSJoel Fernandes (Google) Archs that select this are able to move page tables at the PMD level. 8322c91bd4aSJoel Fernandes (Google) 83315626062SGerald Schaeferconfig HAVE_ARCH_TRANSPARENT_HUGEPAGE 83415626062SGerald Schaefer bool 83515626062SGerald Schaefer 836a00cc7d9SMatthew Wilcoxconfig HAVE_ARCH_TRANSPARENT_HUGEPAGE_PUD 837a00cc7d9SMatthew Wilcox bool 838a00cc7d9SMatthew Wilcox 8390ddab1d2SToshi Kaniconfig HAVE_ARCH_HUGE_VMAP 8400ddab1d2SToshi Kani bool 8410ddab1d2SToshi Kani 842121e6f32SNicholas Piggin# 843121e6f32SNicholas Piggin# Archs that select this would be capable of PMD-sized vmaps (i.e., 844121e6f32SNicholas Piggin# arch_vmap_pmd_supported() returns true), and they must make no assumptions 845121e6f32SNicholas Piggin# that vmalloc memory is mapped with PAGE_SIZE ptes. The VM_NO_HUGE_VMAP flag 846121e6f32SNicholas Piggin# can be used to prohibit arch-specific allocations from using hugepages to 847121e6f32SNicholas Piggin# help with this (e.g., modules may require it). 848121e6f32SNicholas Piggin# 849121e6f32SNicholas Pigginconfig HAVE_ARCH_HUGE_VMALLOC 850121e6f32SNicholas Piggin depends on HAVE_ARCH_HUGE_VMAP 851121e6f32SNicholas Piggin bool 852121e6f32SNicholas Piggin 8533876d4a3SAlexandre Ghiticonfig ARCH_WANT_HUGE_PMD_SHARE 8543876d4a3SAlexandre Ghiti bool 8553876d4a3SAlexandre Ghiti 8560f8975ecSPavel Emelyanovconfig HAVE_ARCH_SOFT_DIRTY 8570f8975ecSPavel Emelyanov bool 8580f8975ecSPavel Emelyanov 859786d35d4SDavid Howellsconfig HAVE_MOD_ARCH_SPECIFIC 860786d35d4SDavid Howells bool 861786d35d4SDavid Howells help 862786d35d4SDavid Howells The arch uses struct mod_arch_specific to store data. Many arches 863786d35d4SDavid Howells just need a simple module loader without arch specific data - those 864786d35d4SDavid Howells should not enable this. 865786d35d4SDavid Howells 866786d35d4SDavid Howellsconfig MODULES_USE_ELF_RELA 867786d35d4SDavid Howells bool 868786d35d4SDavid Howells help 869786d35d4SDavid Howells Modules only use ELF RELA relocations. Modules with ELF REL 870786d35d4SDavid Howells relocations will give an error. 871786d35d4SDavid Howells 872786d35d4SDavid Howellsconfig MODULES_USE_ELF_REL 873786d35d4SDavid Howells bool 874786d35d4SDavid Howells help 875786d35d4SDavid Howells Modules only use ELF REL relocations. Modules with ELF RELA 876786d35d4SDavid Howells relocations will give an error. 877786d35d4SDavid Howells 878cc1f0274SFrederic Weisbeckerconfig HAVE_IRQ_EXIT_ON_IRQ_STACK 879cc1f0274SFrederic Weisbecker bool 880cc1f0274SFrederic Weisbecker help 881cc1f0274SFrederic Weisbecker Architecture doesn't only execute the irq handler on the irq stack 882cc1f0274SFrederic Weisbecker but also irq_exit(). This way we can process softirqs on this irq 883cc1f0274SFrederic Weisbecker stack instead of switching to a new one when we call __do_softirq() 884cc1f0274SFrederic Weisbecker in the end of an hardirq. 885cc1f0274SFrederic Weisbecker This spares a stack switch and improves cache usage on softirq 886cc1f0274SFrederic Weisbecker processing. 887cc1f0274SFrederic Weisbecker 888cd1a41ceSThomas Gleixnerconfig HAVE_SOFTIRQ_ON_OWN_STACK 889cd1a41ceSThomas Gleixner bool 890cd1a41ceSThomas Gleixner help 891cd1a41ceSThomas Gleixner Architecture provides a function to run __do_softirq() on a 892c226bc3cSColin Ian King separate stack. 893cd1a41ceSThomas Gleixner 894235a8f02SKirill A. Shutemovconfig PGTABLE_LEVELS 895235a8f02SKirill A. Shutemov int 896235a8f02SKirill A. Shutemov default 2 897235a8f02SKirill A. Shutemov 8982b68f6caSKees Cookconfig ARCH_HAS_ELF_RANDOMIZE 8992b68f6caSKees Cook bool 9002b68f6caSKees Cook help 9012b68f6caSKees Cook An architecture supports choosing randomized locations for 9022b68f6caSKees Cook stack, mmap, brk, and ET_DYN. Defined functions: 9032b68f6caSKees Cook - arch_mmap_rnd() 904204db6edSKees Cook - arch_randomize_brk() 9052b68f6caSKees Cook 906d07e2259SDaniel Cashmanconfig HAVE_ARCH_MMAP_RND_BITS 907d07e2259SDaniel Cashman bool 908d07e2259SDaniel Cashman help 909d07e2259SDaniel Cashman An arch should select this symbol if it supports setting a variable 910d07e2259SDaniel Cashman number of bits for use in establishing the base address for mmap 911d07e2259SDaniel Cashman allocations, has MMU enabled and provides values for both: 912d07e2259SDaniel Cashman - ARCH_MMAP_RND_BITS_MIN 913d07e2259SDaniel Cashman - ARCH_MMAP_RND_BITS_MAX 914d07e2259SDaniel Cashman 9155f56a5dfSJiri Slabyconfig HAVE_EXIT_THREAD 9165f56a5dfSJiri Slaby bool 9175f56a5dfSJiri Slaby help 9185f56a5dfSJiri Slaby An architecture implements exit_thread. 9195f56a5dfSJiri Slaby 920d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_BITS_MIN 921d07e2259SDaniel Cashman int 922d07e2259SDaniel Cashman 923d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_BITS_MAX 924d07e2259SDaniel Cashman int 925d07e2259SDaniel Cashman 926d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_BITS_DEFAULT 927d07e2259SDaniel Cashman int 928d07e2259SDaniel Cashman 929d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_BITS 930d07e2259SDaniel Cashman int "Number of bits to use for ASLR of mmap base address" if EXPERT 931d07e2259SDaniel Cashman range ARCH_MMAP_RND_BITS_MIN ARCH_MMAP_RND_BITS_MAX 932d07e2259SDaniel Cashman default ARCH_MMAP_RND_BITS_DEFAULT if ARCH_MMAP_RND_BITS_DEFAULT 933d07e2259SDaniel Cashman default ARCH_MMAP_RND_BITS_MIN 934d07e2259SDaniel Cashman depends on HAVE_ARCH_MMAP_RND_BITS 935d07e2259SDaniel Cashman help 936d07e2259SDaniel Cashman This value can be used to select the number of bits to use to 937d07e2259SDaniel Cashman determine the random offset to the base address of vma regions 938d07e2259SDaniel Cashman resulting from mmap allocations. This value will be bounded 939d07e2259SDaniel Cashman by the architecture's minimum and maximum supported values. 940d07e2259SDaniel Cashman 941d07e2259SDaniel Cashman This value can be changed after boot using the 942d07e2259SDaniel Cashman /proc/sys/vm/mmap_rnd_bits tunable 943d07e2259SDaniel Cashman 944d07e2259SDaniel Cashmanconfig HAVE_ARCH_MMAP_RND_COMPAT_BITS 945d07e2259SDaniel Cashman bool 946d07e2259SDaniel Cashman help 947d07e2259SDaniel Cashman An arch should select this symbol if it supports running applications 948d07e2259SDaniel Cashman in compatibility mode, supports setting a variable number of bits for 949d07e2259SDaniel Cashman use in establishing the base address for mmap allocations, has MMU 950d07e2259SDaniel Cashman enabled and provides values for both: 951d07e2259SDaniel Cashman - ARCH_MMAP_RND_COMPAT_BITS_MIN 952d07e2259SDaniel Cashman - ARCH_MMAP_RND_COMPAT_BITS_MAX 953d07e2259SDaniel Cashman 954d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_COMPAT_BITS_MIN 955d07e2259SDaniel Cashman int 956d07e2259SDaniel Cashman 957d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_COMPAT_BITS_MAX 958d07e2259SDaniel Cashman int 959d07e2259SDaniel Cashman 960d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_COMPAT_BITS_DEFAULT 961d07e2259SDaniel Cashman int 962d07e2259SDaniel Cashman 963d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_COMPAT_BITS 964d07e2259SDaniel Cashman int "Number of bits to use for ASLR of mmap base address for compatible applications" if EXPERT 965d07e2259SDaniel Cashman range ARCH_MMAP_RND_COMPAT_BITS_MIN ARCH_MMAP_RND_COMPAT_BITS_MAX 966d07e2259SDaniel Cashman default ARCH_MMAP_RND_COMPAT_BITS_DEFAULT if ARCH_MMAP_RND_COMPAT_BITS_DEFAULT 967d07e2259SDaniel Cashman default ARCH_MMAP_RND_COMPAT_BITS_MIN 968d07e2259SDaniel Cashman depends on HAVE_ARCH_MMAP_RND_COMPAT_BITS 969d07e2259SDaniel Cashman help 970d07e2259SDaniel Cashman This value can be used to select the number of bits to use to 971d07e2259SDaniel Cashman determine the random offset to the base address of vma regions 972d07e2259SDaniel Cashman resulting from mmap allocations for compatible applications This 973d07e2259SDaniel Cashman value will be bounded by the architecture's minimum and maximum 974d07e2259SDaniel Cashman supported values. 975d07e2259SDaniel Cashman 976d07e2259SDaniel Cashman This value can be changed after boot using the 977d07e2259SDaniel Cashman /proc/sys/vm/mmap_rnd_compat_bits tunable 978d07e2259SDaniel Cashman 9791b028f78SDmitry Safonovconfig HAVE_ARCH_COMPAT_MMAP_BASES 9801b028f78SDmitry Safonov bool 9811b028f78SDmitry Safonov help 9821b028f78SDmitry Safonov This allows 64bit applications to invoke 32-bit mmap() syscall 9831b028f78SDmitry Safonov and vice-versa 32-bit applications to call 64-bit mmap(). 9841b028f78SDmitry Safonov Required for applications doing different bitness syscalls. 9851b028f78SDmitry Safonov 98667f3977fSAlexandre Ghiti# This allows to use a set of generic functions to determine mmap base 98767f3977fSAlexandre Ghiti# address by giving priority to top-down scheme only if the process 98867f3977fSAlexandre Ghiti# is not in legacy mode (compat task, unlimited stack size or 98967f3977fSAlexandre Ghiti# sysctl_legacy_va_layout). 99067f3977fSAlexandre Ghiti# Architecture that selects this option can provide its own version of: 99167f3977fSAlexandre Ghiti# - STACK_RND_MASK 99267f3977fSAlexandre Ghiticonfig ARCH_WANT_DEFAULT_TOPDOWN_MMAP_LAYOUT 99367f3977fSAlexandre Ghiti bool 99467f3977fSAlexandre Ghiti depends on MMU 995e7142bf5SAlexandre Ghiti select ARCH_HAS_ELF_RANDOMIZE 99667f3977fSAlexandre Ghiti 997b9ab5ebbSJosh Poimboeufconfig HAVE_STACK_VALIDATION 998b9ab5ebbSJosh Poimboeuf bool 999b9ab5ebbSJosh Poimboeuf help 1000b9ab5ebbSJosh Poimboeuf Architecture supports the 'objtool check' host tool command, which 1001b9ab5ebbSJosh Poimboeuf performs compile-time stack metadata validation. 1002b9ab5ebbSJosh Poimboeuf 1003af085d90SJosh Poimboeufconfig HAVE_RELIABLE_STACKTRACE 1004af085d90SJosh Poimboeuf bool 1005af085d90SJosh Poimboeuf help 1006140d7e88SMiroslav Benes Architecture has either save_stack_trace_tsk_reliable() or 1007140d7e88SMiroslav Benes arch_stack_walk_reliable() function which only returns a stack trace 1008140d7e88SMiroslav Benes if it can guarantee the trace is reliable. 1009af085d90SJosh Poimboeuf 1010468a9428SGeorge Spelvinconfig HAVE_ARCH_HASH 1011468a9428SGeorge Spelvin bool 1012468a9428SGeorge Spelvin default n 1013468a9428SGeorge Spelvin help 1014468a9428SGeorge Spelvin If this is set, the architecture provides an <asm/hash.h> 1015468a9428SGeorge Spelvin file which provides platform-specific implementations of some 1016468a9428SGeorge Spelvin functions in <linux/hash.h> or fs/namei.c. 1017468a9428SGeorge Spelvin 1018666047feSFinn Thainconfig HAVE_ARCH_NVRAM_OPS 1019666047feSFinn Thain bool 1020666047feSFinn Thain 10213a495511SWilliam Breathitt Grayconfig ISA_BUS_API 10223a495511SWilliam Breathitt Gray def_bool ISA 10233a495511SWilliam Breathitt Gray 1024d2125043SAl Viro# 1025d2125043SAl Viro# ABI hall of shame 1026d2125043SAl Viro# 1027d2125043SAl Viroconfig CLONE_BACKWARDS 1028d2125043SAl Viro bool 1029d2125043SAl Viro help 1030d2125043SAl Viro Architecture has tls passed as the 4th argument of clone(2), 1031d2125043SAl Viro not the 5th one. 1032d2125043SAl Viro 1033d2125043SAl Viroconfig CLONE_BACKWARDS2 1034d2125043SAl Viro bool 1035d2125043SAl Viro help 1036d2125043SAl Viro Architecture has the first two arguments of clone(2) swapped. 1037d2125043SAl Viro 1038dfa9771aSMichal Simekconfig CLONE_BACKWARDS3 1039dfa9771aSMichal Simek bool 1040dfa9771aSMichal Simek help 1041dfa9771aSMichal Simek Architecture has tls passed as the 3rd argument of clone(2), 1042dfa9771aSMichal Simek not the 5th one. 1043dfa9771aSMichal Simek 1044eaca6eaeSAl Viroconfig ODD_RT_SIGACTION 1045eaca6eaeSAl Viro bool 1046eaca6eaeSAl Viro help 1047eaca6eaeSAl Viro Architecture has unusual rt_sigaction(2) arguments 1048eaca6eaeSAl Viro 10490a0e8cdfSAl Viroconfig OLD_SIGSUSPEND 10500a0e8cdfSAl Viro bool 10510a0e8cdfSAl Viro help 10520a0e8cdfSAl Viro Architecture has old sigsuspend(2) syscall, of one-argument variety 10530a0e8cdfSAl Viro 10540a0e8cdfSAl Viroconfig OLD_SIGSUSPEND3 10550a0e8cdfSAl Viro bool 10560a0e8cdfSAl Viro help 10570a0e8cdfSAl Viro Even weirder antique ABI - three-argument sigsuspend(2) 10580a0e8cdfSAl Viro 1059495dfbf7SAl Viroconfig OLD_SIGACTION 1060495dfbf7SAl Viro bool 1061495dfbf7SAl Viro help 1062495dfbf7SAl Viro Architecture has old sigaction(2) syscall. Nope, not the same 1063495dfbf7SAl Viro as OLD_SIGSUSPEND | OLD_SIGSUSPEND3 - alpha has sigsuspend(2), 1064495dfbf7SAl Viro but fairly different variant of sigaction(2), thanks to OSF/1 1065495dfbf7SAl Viro compatibility... 1066495dfbf7SAl Viro 1067495dfbf7SAl Viroconfig COMPAT_OLD_SIGACTION 1068495dfbf7SAl Viro bool 1069495dfbf7SAl Viro 107017435e5fSDeepa Dinamaniconfig COMPAT_32BIT_TIME 1071942437c9SArnd Bergmann bool "Provide system calls for 32-bit time_t" 1072942437c9SArnd Bergmann default !64BIT || COMPAT 107317435e5fSDeepa Dinamani help 107417435e5fSDeepa Dinamani This enables 32 bit time_t support in addition to 64 bit time_t support. 107517435e5fSDeepa Dinamani This is relevant on all 32-bit architectures, and 64-bit architectures 107617435e5fSDeepa Dinamani as part of compat syscall handling. 107717435e5fSDeepa Dinamani 107887a4c375SChristoph Hellwigconfig ARCH_NO_PREEMPT 107987a4c375SChristoph Hellwig bool 108087a4c375SChristoph Hellwig 1081cb2c7d1aSMickaël Salaünconfig ARCH_EPHEMERAL_INODES 1082cb2c7d1aSMickaël Salaün def_bool n 1083cb2c7d1aSMickaël Salaün help 1084cb2c7d1aSMickaël Salaün An arch should select this symbol if it doesn't keep track of inode 1085cb2c7d1aSMickaël Salaün instances on its own, but instead relies on something else (e.g. the 1086cb2c7d1aSMickaël Salaün host kernel for an UML kernel). 1087cb2c7d1aSMickaël Salaün 1088a50a3f4bSThomas Gleixnerconfig ARCH_SUPPORTS_RT 1089a50a3f4bSThomas Gleixner bool 1090a50a3f4bSThomas Gleixner 1091fff7fb0bSZhaoxiu Zengconfig CPU_NO_EFFICIENT_FFS 1092fff7fb0bSZhaoxiu Zeng def_bool n 1093fff7fb0bSZhaoxiu Zeng 1094ba14a194SAndy Lutomirskiconfig HAVE_ARCH_VMAP_STACK 1095ba14a194SAndy Lutomirski def_bool n 1096ba14a194SAndy Lutomirski help 1097ba14a194SAndy Lutomirski An arch should select this symbol if it can support kernel stacks 1098ba14a194SAndy Lutomirski in vmalloc space. This means: 1099ba14a194SAndy Lutomirski 1100ba14a194SAndy Lutomirski - vmalloc space must be large enough to hold many kernel stacks. 1101ba14a194SAndy Lutomirski This may rule out many 32-bit architectures. 1102ba14a194SAndy Lutomirski 1103ba14a194SAndy Lutomirski - Stacks in vmalloc space need to work reliably. For example, if 1104ba14a194SAndy Lutomirski vmap page tables are created on demand, either this mechanism 1105ba14a194SAndy Lutomirski needs to work while the stack points to a virtual address with 1106ba14a194SAndy Lutomirski unpopulated page tables or arch code (switch_to() and switch_mm(), 1107ba14a194SAndy Lutomirski most likely) needs to ensure that the stack's page table entries 1108ba14a194SAndy Lutomirski are populated before running on a possibly unpopulated stack. 1109ba14a194SAndy Lutomirski 1110ba14a194SAndy Lutomirski - If the stack overflows into a guard page, something reasonable 1111ba14a194SAndy Lutomirski should happen. The definition of "reasonable" is flexible, but 1112ba14a194SAndy Lutomirski instantly rebooting without logging anything would be unfriendly. 1113ba14a194SAndy Lutomirski 1114ba14a194SAndy Lutomirskiconfig VMAP_STACK 1115ba14a194SAndy Lutomirski default y 1116ba14a194SAndy Lutomirski bool "Use a virtually-mapped stack" 1117eafb149eSDaniel Axtens depends on HAVE_ARCH_VMAP_STACK 111838dd767dSAndrey Konovalov depends on !KASAN || KASAN_HW_TAGS || KASAN_VMALLOC 1119a7f7f624SMasahiro Yamada help 1120ba14a194SAndy Lutomirski Enable this if you want the use virtually-mapped kernel stacks 1121ba14a194SAndy Lutomirski with guard pages. This causes kernel stack overflows to be 1122ba14a194SAndy Lutomirski caught immediately rather than causing difficult-to-diagnose 1123ba14a194SAndy Lutomirski corruption. 1124ba14a194SAndy Lutomirski 112538dd767dSAndrey Konovalov To use this with software KASAN modes, the architecture must support 112638dd767dSAndrey Konovalov backing virtual mappings with real shadow memory, and KASAN_VMALLOC 112738dd767dSAndrey Konovalov must be enabled. 1128ba14a194SAndy Lutomirski 112939218ff4SKees Cookconfig HAVE_ARCH_RANDOMIZE_KSTACK_OFFSET 113039218ff4SKees Cook def_bool n 113139218ff4SKees Cook help 113239218ff4SKees Cook An arch should select this symbol if it can support kernel stack 113339218ff4SKees Cook offset randomization with calls to add_random_kstack_offset() 113439218ff4SKees Cook during syscall entry and choose_random_kstack_offset() during 113539218ff4SKees Cook syscall exit. Careful removal of -fstack-protector-strong and 113639218ff4SKees Cook -fstack-protector should also be applied to the entry code and 113739218ff4SKees Cook closely examined, as the artificial stack bump looks like an array 113839218ff4SKees Cook to the compiler, so it will attempt to add canary checks regardless 113939218ff4SKees Cook of the static branch state. 114039218ff4SKees Cook 114139218ff4SKees Cookconfig RANDOMIZE_KSTACK_OFFSET_DEFAULT 114239218ff4SKees Cook bool "Randomize kernel stack offset on syscall entry" 114339218ff4SKees Cook depends on HAVE_ARCH_RANDOMIZE_KSTACK_OFFSET 114439218ff4SKees Cook help 114539218ff4SKees Cook The kernel stack offset can be randomized (after pt_regs) by 114639218ff4SKees Cook roughly 5 bits of entropy, frustrating memory corruption 114739218ff4SKees Cook attacks that depend on stack address determinism or 114839218ff4SKees Cook cross-syscall address exposures. This feature is controlled 114939218ff4SKees Cook by kernel boot param "randomize_kstack_offset=on/off", and this 115039218ff4SKees Cook config chooses the default boot state. 115139218ff4SKees Cook 1152ad21fc4fSLaura Abbottconfig ARCH_OPTIONAL_KERNEL_RWX 1153ad21fc4fSLaura Abbott def_bool n 1154ad21fc4fSLaura Abbott 1155ad21fc4fSLaura Abbottconfig ARCH_OPTIONAL_KERNEL_RWX_DEFAULT 1156ad21fc4fSLaura Abbott def_bool n 1157ad21fc4fSLaura Abbott 1158ad21fc4fSLaura Abbottconfig ARCH_HAS_STRICT_KERNEL_RWX 1159ad21fc4fSLaura Abbott def_bool n 1160ad21fc4fSLaura Abbott 11610f5bf6d0SLaura Abbottconfig STRICT_KERNEL_RWX 1162ad21fc4fSLaura Abbott bool "Make kernel text and rodata read-only" if ARCH_OPTIONAL_KERNEL_RWX 1163ad21fc4fSLaura Abbott depends on ARCH_HAS_STRICT_KERNEL_RWX 1164ad21fc4fSLaura Abbott default !ARCH_OPTIONAL_KERNEL_RWX || ARCH_OPTIONAL_KERNEL_RWX_DEFAULT 1165ad21fc4fSLaura Abbott help 1166ad21fc4fSLaura Abbott If this is set, kernel text and rodata memory will be made read-only, 1167ad21fc4fSLaura Abbott and non-text memory will be made non-executable. This provides 1168ad21fc4fSLaura Abbott protection against certain security exploits (e.g. executing the heap 1169ad21fc4fSLaura Abbott or modifying text) 1170ad21fc4fSLaura Abbott 1171ad21fc4fSLaura Abbott These features are considered standard security practice these days. 1172ad21fc4fSLaura Abbott You should say Y here in almost all cases. 1173ad21fc4fSLaura Abbott 1174ad21fc4fSLaura Abbottconfig ARCH_HAS_STRICT_MODULE_RWX 1175ad21fc4fSLaura Abbott def_bool n 1176ad21fc4fSLaura Abbott 11770f5bf6d0SLaura Abbottconfig STRICT_MODULE_RWX 1178ad21fc4fSLaura Abbott bool "Set loadable kernel module data as NX and text as RO" if ARCH_OPTIONAL_KERNEL_RWX 1179ad21fc4fSLaura Abbott depends on ARCH_HAS_STRICT_MODULE_RWX && MODULES 1180ad21fc4fSLaura Abbott default !ARCH_OPTIONAL_KERNEL_RWX || ARCH_OPTIONAL_KERNEL_RWX_DEFAULT 1181ad21fc4fSLaura Abbott help 1182ad21fc4fSLaura Abbott If this is set, module text and rodata memory will be made read-only, 1183ad21fc4fSLaura Abbott and non-text memory will be made non-executable. This provides 1184ad21fc4fSLaura Abbott protection against certain security exploits (e.g. writing to text) 1185ad21fc4fSLaura Abbott 1186ea8c64acSChristoph Hellwig# select if the architecture provides an asm/dma-direct.h header 1187ea8c64acSChristoph Hellwigconfig ARCH_HAS_PHYS_TO_DMA 1188ea8c64acSChristoph Hellwig bool 1189ea8c64acSChristoph Hellwig 119004f264d3SPaul Burtonconfig HAVE_ARCH_COMPILER_H 119104f264d3SPaul Burton bool 119204f264d3SPaul Burton help 119304f264d3SPaul Burton An architecture can select this if it provides an 119404f264d3SPaul Burton asm/compiler.h header that should be included after 119504f264d3SPaul Burton linux/compiler-*.h in order to override macro definitions that those 119604f264d3SPaul Burton headers generally provide. 119704f264d3SPaul Burton 1198271ca788SArd Biesheuvelconfig HAVE_ARCH_PREL32_RELOCATIONS 1199271ca788SArd Biesheuvel bool 1200271ca788SArd Biesheuvel help 1201271ca788SArd Biesheuvel May be selected by an architecture if it supports place-relative 1202271ca788SArd Biesheuvel 32-bit relocations, both in the toolchain and in the module loader, 1203271ca788SArd Biesheuvel in which case relative references can be used in special sections 1204271ca788SArd Biesheuvel for PCI fixup, initcalls etc which are only half the size on 64 bit 1205271ca788SArd Biesheuvel architectures, and don't require runtime relocation on relocatable 1206271ca788SArd Biesheuvel kernels. 1207271ca788SArd Biesheuvel 1208ce9084baSArd Biesheuvelconfig ARCH_USE_MEMREMAP_PROT 1209ce9084baSArd Biesheuvel bool 1210ce9084baSArd Biesheuvel 1211fb346fd9SWaiman Longconfig LOCK_EVENT_COUNTS 1212fb346fd9SWaiman Long bool "Locking event counts collection" 1213fb346fd9SWaiman Long depends on DEBUG_FS 1214a7f7f624SMasahiro Yamada help 1215fb346fd9SWaiman Long Enable light-weight counting of various locking related events 1216fb346fd9SWaiman Long in the system with minimal performance impact. This reduces 1217fb346fd9SWaiman Long the chance of application behavior change because of timing 1218fb346fd9SWaiman Long differences. The counts are reported via debugfs. 1219fb346fd9SWaiman Long 12205cf896fbSPeter Collingbourne# Select if the architecture has support for applying RELR relocations. 12215cf896fbSPeter Collingbourneconfig ARCH_HAS_RELR 12225cf896fbSPeter Collingbourne bool 12235cf896fbSPeter Collingbourne 12245cf896fbSPeter Collingbourneconfig RELR 12255cf896fbSPeter Collingbourne bool "Use RELR relocation packing" 12265cf896fbSPeter Collingbourne depends on ARCH_HAS_RELR && TOOLS_SUPPORT_RELR 12275cf896fbSPeter Collingbourne default y 12285cf896fbSPeter Collingbourne help 12295cf896fbSPeter Collingbourne Store the kernel's dynamic relocations in the RELR relocation packing 12305cf896fbSPeter Collingbourne format. Requires a compatible linker (LLD supports this feature), as 12315cf896fbSPeter Collingbourne well as compatible NM and OBJCOPY utilities (llvm-nm and llvm-objcopy 12325cf896fbSPeter Collingbourne are compatible). 12335cf896fbSPeter Collingbourne 12340c9c1d56SThiago Jung Bauermannconfig ARCH_HAS_MEM_ENCRYPT 12350c9c1d56SThiago Jung Bauermann bool 12360c9c1d56SThiago Jung Bauermann 12370e242208SHassan Naveedconfig HAVE_SPARSE_SYSCALL_NR 12380e242208SHassan Naveed bool 12390e242208SHassan Naveed help 12400e242208SHassan Naveed An architecture should select this if its syscall numbering is sparse 12410e242208SHassan Naveed to save space. For example, MIPS architecture has a syscall array with 12420e242208SHassan Naveed entries at 4000, 5000 and 6000 locations. This option turns on syscall 12430e242208SHassan Naveed related optimizations for a given architecture. 12440e242208SHassan Naveed 1245d60d7de3SSven Schnelleconfig ARCH_HAS_VDSO_DATA 1246d60d7de3SSven Schnelle bool 1247d60d7de3SSven Schnelle 1248115284d8SJosh Poimboeufconfig HAVE_STATIC_CALL 1249115284d8SJosh Poimboeuf bool 1250115284d8SJosh Poimboeuf 12519183c3f9SJosh Poimboeufconfig HAVE_STATIC_CALL_INLINE 12529183c3f9SJosh Poimboeuf bool 12539183c3f9SJosh Poimboeuf depends on HAVE_STATIC_CALL 12549183c3f9SJosh Poimboeuf 12556ef869e0SMichal Hockoconfig HAVE_PREEMPT_DYNAMIC 12566ef869e0SMichal Hocko bool 12576ef869e0SMichal Hocko depends on HAVE_STATIC_CALL 12586ef869e0SMichal Hocko depends on GENERIC_ENTRY 12596ef869e0SMichal Hocko help 12606ef869e0SMichal Hocko Select this if the architecture support boot time preempt setting 12616ef869e0SMichal Hocko on top of static calls. It is strongly advised to support inline 12626ef869e0SMichal Hocko static call to avoid any overhead. 12636ef869e0SMichal Hocko 126459612b24SNathan Chancellorconfig ARCH_WANT_LD_ORPHAN_WARN 126559612b24SNathan Chancellor bool 126659612b24SNathan Chancellor help 126759612b24SNathan Chancellor An arch should select this symbol once all linker sections are explicitly 126859612b24SNathan Chancellor included, size-asserted, or discarded in the linker scripts. This is 126959612b24SNathan Chancellor important because we never want expected sections to be placed heuristically 127059612b24SNathan Chancellor by the linker, since the locations of such sections can change between linker 127159612b24SNathan Chancellor versions. 127259612b24SNathan Chancellor 12734f5b0c17SMike Rapoportconfig HAVE_ARCH_PFN_VALID 12744f5b0c17SMike Rapoport bool 12754f5b0c17SMike Rapoport 12765d6ad668SMike Rapoportconfig ARCH_SUPPORTS_DEBUG_PAGEALLOC 12775d6ad668SMike Rapoport bool 12785d6ad668SMike Rapoport 12792ca408d9SBrian Gerstconfig ARCH_SPLIT_ARG64 12802ca408d9SBrian Gerst bool 12812ca408d9SBrian Gerst help 12822ca408d9SBrian Gerst If a 32-bit architecture requires 64-bit arguments to be split into 12832ca408d9SBrian Gerst pairs of 32-bit arguments, select this option. 12842ca408d9SBrian Gerst 12857facdc42SAl Viroconfig ARCH_HAS_ELFCORE_COMPAT 12867facdc42SAl Viro bool 12877facdc42SAl Viro 128858e106e7SBalbir Singhconfig ARCH_HAS_PARANOID_L1D_FLUSH 128958e106e7SBalbir Singh bool 129058e106e7SBalbir Singh 1291*1bdda24cSThomas Gleixnerconfig DYNAMIC_SIGFRAME 1292*1bdda24cSThomas Gleixner bool 1293*1bdda24cSThomas Gleixner 12942521f2c2SPeter Oberparleitersource "kernel/gcov/Kconfig" 129545332b1bSMasahiro Yamada 129645332b1bSMasahiro Yamadasource "scripts/gcc-plugins/Kconfig" 1297fa1b5d09SLinus Torvalds 129822471e13SRandy Dunlapendmenu 1299