1b2441318SGreg Kroah-Hartman# SPDX-License-Identifier: GPL-2.0 2fb32e03fSMathieu Desnoyers# 3fb32e03fSMathieu Desnoyers# General architecture dependent options 4fb32e03fSMathieu Desnoyers# 5125e5645SMathieu Desnoyers 61572497cSChristoph Hellwig# 71572497cSChristoph Hellwig# Note: arch/$(SRCARCH)/Kconfig needs to be included first so that it can 81572497cSChristoph Hellwig# override the default values in this file. 91572497cSChristoph Hellwig# 101572497cSChristoph Hellwigsource "arch/$(SRCARCH)/Kconfig" 111572497cSChristoph Hellwig 1222471e13SRandy Dunlapmenu "General architecture-dependent options" 1322471e13SRandy Dunlap 14692f66f2SHari Bathiniconfig CRASH_CORE 15692f66f2SHari Bathini bool 16692f66f2SHari Bathini 172965faa5SDave Youngconfig KEXEC_CORE 18692f66f2SHari Bathini select CRASH_CORE 192965faa5SDave Young bool 202965faa5SDave Young 21175fca3bSSven Schnelleconfig KEXEC_ELF 22175fca3bSSven Schnelle bool 23175fca3bSSven Schnelle 24467d2782SThiago Jung Bauermannconfig HAVE_IMA_KEXEC 25467d2782SThiago Jung Bauermann bool 26467d2782SThiago Jung Bauermann 27da32b581SCatalin Marinasconfig ARCH_HAS_SUBPAGE_FAULTS 28da32b581SCatalin Marinas bool 29da32b581SCatalin Marinas help 30da32b581SCatalin Marinas Select if the architecture can check permissions at sub-page 31da32b581SCatalin Marinas granularity (e.g. arm64 MTE). The probe_user_*() functions 32da32b581SCatalin Marinas must be implemented. 33da32b581SCatalin Marinas 3405736e4aSThomas Gleixnerconfig HOTPLUG_SMT 3505736e4aSThomas Gleixner bool 3605736e4aSThomas Gleixner 37142781e1SThomas Gleixnerconfig GENERIC_ENTRY 38142781e1SThomas Gleixner bool 39142781e1SThomas Gleixner 40125e5645SMathieu Desnoyersconfig KPROBES 41125e5645SMathieu Desnoyers bool "Kprobes" 4205ed160eSMasami Hiramatsu depends on MODULES 43125e5645SMathieu Desnoyers depends on HAVE_KPROBES 4405ed160eSMasami Hiramatsu select KALLSYMS 45835f14edSPaul E. McKenney select TASKS_RCU if PREEMPTION 46125e5645SMathieu Desnoyers help 47125e5645SMathieu Desnoyers Kprobes allows you to trap at almost any kernel address and 48125e5645SMathieu Desnoyers execute a callback function. register_kprobe() establishes 49125e5645SMathieu Desnoyers a probepoint and specifies the callback. Kprobes is useful 50125e5645SMathieu Desnoyers for kernel debugging, non-intrusive instrumentation and testing. 51125e5645SMathieu Desnoyers If in doubt, say "N". 52125e5645SMathieu Desnoyers 5345f81b1cSSteven Rostedtconfig JUMP_LABEL 54c5905afbSIngo Molnar bool "Optimize very unlikely/likely branches" 5545f81b1cSSteven Rostedt depends on HAVE_ARCH_JUMP_LABEL 56e9666d10SMasahiro Yamada depends on CC_HAS_ASM_GOTO 574ab7674fSJosh Poimboeuf select OBJTOOL if HAVE_JUMP_LABEL_HACK 5845f81b1cSSteven Rostedt help 59c5905afbSIngo Molnar This option enables a transparent branch optimization that 60c5905afbSIngo Molnar makes certain almost-always-true or almost-always-false branch 61c5905afbSIngo Molnar conditions even cheaper to execute within the kernel. 6245f81b1cSSteven Rostedt 63c5905afbSIngo Molnar Certain performance-sensitive kernel code, such as trace points, 64c5905afbSIngo Molnar scheduler functionality, networking code and KVM have such 65c5905afbSIngo Molnar branches and include support for this optimization technique. 66c5905afbSIngo Molnar 67c5905afbSIngo Molnar If it is detected that the compiler has support for "asm goto", 68c5905afbSIngo Molnar the kernel will compile such branches with just a nop 69c5905afbSIngo Molnar instruction. When the condition flag is toggled to true, the 70c5905afbSIngo Molnar nop will be converted to a jump instruction to execute the 71c5905afbSIngo Molnar conditional block of instructions. 72c5905afbSIngo Molnar 73c5905afbSIngo Molnar This technique lowers overhead and stress on the branch prediction 74c5905afbSIngo Molnar of the processor and generally makes the kernel faster. The update 75c5905afbSIngo Molnar of the condition is slower, but those are always very rare. 76c5905afbSIngo Molnar 77c5905afbSIngo Molnar ( On 32-bit x86, the necessary options added to the compiler 78c5905afbSIngo Molnar flags may increase the size of the kernel slightly. ) 7945f81b1cSSteven Rostedt 801987c947SPeter Zijlstraconfig STATIC_KEYS_SELFTEST 811987c947SPeter Zijlstra bool "Static key selftest" 821987c947SPeter Zijlstra depends on JUMP_LABEL 831987c947SPeter Zijlstra help 841987c947SPeter Zijlstra Boot time self-test of the branch patching code. 851987c947SPeter Zijlstra 86f03c4129SPeter Zijlstraconfig STATIC_CALL_SELFTEST 87f03c4129SPeter Zijlstra bool "Static call selftest" 88f03c4129SPeter Zijlstra depends on HAVE_STATIC_CALL 89f03c4129SPeter Zijlstra help 90f03c4129SPeter Zijlstra Boot time self-test of the call patching code. 91f03c4129SPeter Zijlstra 92afd66255SMasami Hiramatsuconfig OPTPROBES 935cc718b9SMasami Hiramatsu def_bool y 945cc718b9SMasami Hiramatsu depends on KPROBES && HAVE_OPTPROBES 9501b1d88bSThomas Gleixner select TASKS_RCU if PREEMPTION 96afd66255SMasami Hiramatsu 97e7dbfe34SMasami Hiramatsuconfig KPROBES_ON_FTRACE 98e7dbfe34SMasami Hiramatsu def_bool y 99e7dbfe34SMasami Hiramatsu depends on KPROBES && HAVE_KPROBES_ON_FTRACE 100e7dbfe34SMasami Hiramatsu depends on DYNAMIC_FTRACE_WITH_REGS 101e7dbfe34SMasami Hiramatsu help 102e7dbfe34SMasami Hiramatsu If function tracer is enabled and the arch supports full 103e7dbfe34SMasami Hiramatsu passing of pt_regs to function tracing, then kprobes can 104e7dbfe34SMasami Hiramatsu optimize on top of function tracing. 105e7dbfe34SMasami Hiramatsu 1062b144498SSrikar Dronamrajuconfig UPROBES 10709294e31SDavid A. Long def_bool n 108e8f4aa60SAllen Pais depends on ARCH_SUPPORTS_UPROBES 1092b144498SSrikar Dronamraju help 1107b2d81d4SIngo Molnar Uprobes is the user-space counterpart to kprobes: they 1117b2d81d4SIngo Molnar enable instrumentation applications (such as 'perf probe') 1127b2d81d4SIngo Molnar to establish unintrusive probes in user-space binaries and 1137b2d81d4SIngo Molnar libraries, by executing handler functions when the probes 1147b2d81d4SIngo Molnar are hit by user-space applications. 1157b2d81d4SIngo Molnar 1167b2d81d4SIngo Molnar ( These probes come in the form of single-byte breakpoints, 1177b2d81d4SIngo Molnar managed by the kernel and kept transparent to the probed 1187b2d81d4SIngo Molnar application. ) 1192b144498SSrikar Dronamraju 120adab66b7SSteven Rostedt (VMware)config HAVE_64BIT_ALIGNED_ACCESS 121adab66b7SSteven Rostedt (VMware) def_bool 64BIT && !HAVE_EFFICIENT_UNALIGNED_ACCESS 122adab66b7SSteven Rostedt (VMware) help 123adab66b7SSteven Rostedt (VMware) Some architectures require 64 bit accesses to be 64 bit 124adab66b7SSteven Rostedt (VMware) aligned, which also requires structs containing 64 bit values 125adab66b7SSteven Rostedt (VMware) to be 64 bit aligned too. This includes some 32 bit 126adab66b7SSteven Rostedt (VMware) architectures which can do 64 bit accesses, as well as 64 bit 127adab66b7SSteven Rostedt (VMware) architectures without unaligned access. 128adab66b7SSteven Rostedt (VMware) 129adab66b7SSteven Rostedt (VMware) This symbol should be selected by an architecture if 64 bit 130adab66b7SSteven Rostedt (VMware) accesses are required to be 64 bit aligned in this way even 131adab66b7SSteven Rostedt (VMware) though it is not a 64 bit architecture. 132adab66b7SSteven Rostedt (VMware) 133ba1a297dSLukas Bulwahn See Documentation/core-api/unaligned-memory-access.rst for 134ba1a297dSLukas Bulwahn more information on the topic of unaligned memory accesses. 135adab66b7SSteven Rostedt (VMware) 13658340a07SJohannes Bergconfig HAVE_EFFICIENT_UNALIGNED_ACCESS 1379ba16087SJan Beulich bool 13858340a07SJohannes Berg help 13958340a07SJohannes Berg Some architectures are unable to perform unaligned accesses 14058340a07SJohannes Berg without the use of get_unaligned/put_unaligned. Others are 14158340a07SJohannes Berg unable to perform such accesses efficiently (e.g. trap on 14258340a07SJohannes Berg unaligned access and require fixing it up in the exception 14358340a07SJohannes Berg handler.) 14458340a07SJohannes Berg 14558340a07SJohannes Berg This symbol should be selected by an architecture if it can 14658340a07SJohannes Berg perform unaligned accesses efficiently to allow different 14758340a07SJohannes Berg code paths to be selected for these cases. Some network 14858340a07SJohannes Berg drivers, for example, could opt to not fix up alignment 14958340a07SJohannes Berg problems with received packets if doing so would not help 15058340a07SJohannes Berg much. 15158340a07SJohannes Berg 152c9b54d6fSMauro Carvalho Chehab See Documentation/core-api/unaligned-memory-access.rst for more 15358340a07SJohannes Berg information on the topic of unaligned memory accesses. 15458340a07SJohannes Berg 155cf66bb93SDavid Woodhouseconfig ARCH_USE_BUILTIN_BSWAP 156cf66bb93SDavid Woodhouse bool 157cf66bb93SDavid Woodhouse help 158cf66bb93SDavid Woodhouse Modern versions of GCC (since 4.4) have builtin functions 159cf66bb93SDavid Woodhouse for handling byte-swapping. Using these, instead of the old 160cf66bb93SDavid Woodhouse inline assembler that the architecture code provides in the 161cf66bb93SDavid Woodhouse __arch_bswapXX() macros, allows the compiler to see what's 162cf66bb93SDavid Woodhouse happening and offers more opportunity for optimisation. In 163cf66bb93SDavid Woodhouse particular, the compiler will be able to combine the byteswap 164cf66bb93SDavid Woodhouse with a nearby load or store and use load-and-swap or 165cf66bb93SDavid Woodhouse store-and-swap instructions if the architecture has them. It 166cf66bb93SDavid Woodhouse should almost *never* result in code which is worse than the 167cf66bb93SDavid Woodhouse hand-coded assembler in <asm/swab.h>. But just in case it 168cf66bb93SDavid Woodhouse does, the use of the builtins is optional. 169cf66bb93SDavid Woodhouse 170cf66bb93SDavid Woodhouse Any architecture with load-and-swap or store-and-swap 171cf66bb93SDavid Woodhouse instructions should set this. And it shouldn't hurt to set it 172cf66bb93SDavid Woodhouse on architectures that don't have such instructions. 173cf66bb93SDavid Woodhouse 1749edddaa2SAnanth N Mavinakayanahalliconfig KRETPROBES 1759edddaa2SAnanth N Mavinakayanahalli def_bool y 17673f9b911SMasami Hiramatsu depends on KPROBES && (HAVE_KRETPROBES || HAVE_RETHOOK) 17773f9b911SMasami Hiramatsu 17873f9b911SMasami Hiramatsuconfig KRETPROBE_ON_RETHOOK 17973f9b911SMasami Hiramatsu def_bool y 18073f9b911SMasami Hiramatsu depends on HAVE_RETHOOK 18173f9b911SMasami Hiramatsu depends on KRETPROBES 18273f9b911SMasami Hiramatsu select RETHOOK 1839edddaa2SAnanth N Mavinakayanahalli 1847c68af6eSAvi Kivityconfig USER_RETURN_NOTIFIER 1857c68af6eSAvi Kivity bool 1867c68af6eSAvi Kivity depends on HAVE_USER_RETURN_NOTIFIER 1877c68af6eSAvi Kivity help 1887c68af6eSAvi Kivity Provide a kernel-internal notification when a cpu is about to 1897c68af6eSAvi Kivity switch to user mode. 1907c68af6eSAvi Kivity 19128b2ee20SRik van Rielconfig HAVE_IOREMAP_PROT 1929ba16087SJan Beulich bool 19328b2ee20SRik van Riel 194125e5645SMathieu Desnoyersconfig HAVE_KPROBES 1959ba16087SJan Beulich bool 1969edddaa2SAnanth N Mavinakayanahalli 1979edddaa2SAnanth N Mavinakayanahalliconfig HAVE_KRETPROBES 1989ba16087SJan Beulich bool 19974bc7ceeSArthur Kepner 200afd66255SMasami Hiramatsuconfig HAVE_OPTPROBES 201afd66255SMasami Hiramatsu bool 202d314d74cSCong Wang 203e7dbfe34SMasami Hiramatsuconfig HAVE_KPROBES_ON_FTRACE 204e7dbfe34SMasami Hiramatsu bool 205e7dbfe34SMasami Hiramatsu 2061f6d3a8fSMasami Hiramatsuconfig ARCH_CORRECT_STACKTRACE_ON_KRETPROBE 2071f6d3a8fSMasami Hiramatsu bool 2081f6d3a8fSMasami Hiramatsu help 2091f6d3a8fSMasami Hiramatsu Since kretprobes modifies return address on the stack, the 2101f6d3a8fSMasami Hiramatsu stacktrace may see the kretprobe trampoline address instead 2111f6d3a8fSMasami Hiramatsu of correct one. If the architecture stacktrace code and 2121f6d3a8fSMasami Hiramatsu unwinder can adjust such entries, select this configuration. 2131f6d3a8fSMasami Hiramatsu 214540adea3SMasami Hiramatsuconfig HAVE_FUNCTION_ERROR_INJECTION 2159802d865SJosef Bacik bool 2169802d865SJosef Bacik 21742a0bb3fSPetr Mladekconfig HAVE_NMI 21842a0bb3fSPetr Mladek bool 21942a0bb3fSPetr Mladek 220a257caccSChristophe Leroyconfig HAVE_FUNCTION_DESCRIPTORS 221a257caccSChristophe Leroy bool 222a257caccSChristophe Leroy 2234aae683fSMasahiro Yamadaconfig TRACE_IRQFLAGS_SUPPORT 2244aae683fSMasahiro Yamada bool 2254aae683fSMasahiro Yamada 2261f5a4ad9SRoland McGrath# 2271f5a4ad9SRoland McGrath# An arch should select this if it provides all these things: 2281f5a4ad9SRoland McGrath# 2291f5a4ad9SRoland McGrath# task_pt_regs() in asm/processor.h or asm/ptrace.h 2301f5a4ad9SRoland McGrath# arch_has_single_step() if there is hardware single-step support 2311f5a4ad9SRoland McGrath# arch_has_block_step() if there is hardware block-step support 2321f5a4ad9SRoland McGrath# asm/syscall.h supplying asm-generic/syscall.h interface 2331f5a4ad9SRoland McGrath# linux/regset.h user_regset interfaces 2341f5a4ad9SRoland McGrath# CORE_DUMP_USE_REGSET #define'd in linux/elf.h 235153474baSEric W. Biederman# TIF_SYSCALL_TRACE calls ptrace_report_syscall_{entry,exit} 23603248addSEric W. Biederman# TIF_NOTIFY_RESUME calls resume_user_mode_work() 2371f5a4ad9SRoland McGrath# 2381f5a4ad9SRoland McGrathconfig HAVE_ARCH_TRACEHOOK 2399ba16087SJan Beulich bool 2401f5a4ad9SRoland McGrath 241c64be2bbSMarek Szyprowskiconfig HAVE_DMA_CONTIGUOUS 242c64be2bbSMarek Szyprowski bool 243c64be2bbSMarek Szyprowski 24429d5e047SThomas Gleixnerconfig GENERIC_SMP_IDLE_THREAD 24529d5e047SThomas Gleixner bool 24629d5e047SThomas Gleixner 247485cf5daSKevin Hilmanconfig GENERIC_IDLE_POLL_SETUP 248485cf5daSKevin Hilman bool 249485cf5daSKevin Hilman 2506974f0c4SDaniel Micayconfig ARCH_HAS_FORTIFY_SOURCE 2516974f0c4SDaniel Micay bool 2526974f0c4SDaniel Micay help 2536974f0c4SDaniel Micay An architecture should select this when it can successfully 2546974f0c4SDaniel Micay build and run with CONFIG_FORTIFY_SOURCE. 2556974f0c4SDaniel Micay 256d8ae8a37SChristoph Hellwig# 257d8ae8a37SChristoph Hellwig# Select if the arch provides a historic keepinit alias for the retain_initrd 258d8ae8a37SChristoph Hellwig# command line option 259d8ae8a37SChristoph Hellwig# 260d8ae8a37SChristoph Hellwigconfig ARCH_HAS_KEEPINITRD 261d8ae8a37SChristoph Hellwig bool 262d8ae8a37SChristoph Hellwig 263d2852a22SDaniel Borkmann# Select if arch has all set_memory_ro/rw/x/nx() functions in asm/cacheflush.h 264d2852a22SDaniel Borkmannconfig ARCH_HAS_SET_MEMORY 265d2852a22SDaniel Borkmann bool 266d2852a22SDaniel Borkmann 267d253ca0cSRick Edgecombe# Select if arch has all set_direct_map_invalid/default() functions 268d253ca0cSRick Edgecombeconfig ARCH_HAS_SET_DIRECT_MAP 269d253ca0cSRick Edgecombe bool 270d253ca0cSRick Edgecombe 271c30700dbSChristoph Hellwig# 272fa7e2247SChristoph Hellwig# Select if the architecture provides the arch_dma_set_uncached symbol to 273a86ecfa6SColin Ian King# either provide an uncached segment alias for a DMA allocation, or 274fa7e2247SChristoph Hellwig# to remap the page tables in place. 275c30700dbSChristoph Hellwig# 276fa7e2247SChristoph Hellwigconfig ARCH_HAS_DMA_SET_UNCACHED 277c30700dbSChristoph Hellwig bool 278c30700dbSChristoph Hellwig 279999a5d12SChristoph Hellwig# 280999a5d12SChristoph Hellwig# Select if the architectures provides the arch_dma_clear_uncached symbol 281999a5d12SChristoph Hellwig# to undo an in-place page table remap for uncached access. 282999a5d12SChristoph Hellwig# 283999a5d12SChristoph Hellwigconfig ARCH_HAS_DMA_CLEAR_UNCACHED 284f5e10287SThomas Gleixner bool 285f5e10287SThomas Gleixner 2865905429aSKees Cook# Select if arch init_task must go in the __init_task_data section 2875905429aSKees Cookconfig ARCH_TASK_STRUCT_ON_STACK 2885905429aSKees Cook bool 2895905429aSKees Cook 2905905429aSKees Cook# Select if arch has its private alloc_task_struct() function 2915905429aSKees Cookconfig ARCH_TASK_STRUCT_ALLOCATOR 2925905429aSKees Cook bool 2935905429aSKees Cook 2945905429aSKees Cookconfig HAVE_ARCH_THREAD_STRUCT_WHITELIST 2955905429aSKees Cook bool 2965905429aSKees Cook depends on !ARCH_TASK_STRUCT_ALLOCATOR 297b235beeaSLinus Torvalds help 298b235beeaSLinus Torvalds An architecture should select this to provide hardened usercopy 299f5e10287SThomas Gleixner knowledge about what region of the thread_struct should be 300f5e10287SThomas Gleixner whitelisted for copying to userspace. Normally this is only the 3015aaeb5c0SIngo Molnar FPU registers. Specifically, arch_thread_struct_whitelist() 3025aaeb5c0SIngo Molnar should be implemented. Without this, the entire thread_struct 3035aaeb5c0SIngo Molnar field in task_struct will be left whitelisted. 3045aaeb5c0SIngo Molnar 305942fa985SYury Norov# Select if arch has its private alloc_thread_stack() function 306942fa985SYury Norovconfig ARCH_THREAD_STACK_ALLOCATOR 307942fa985SYury Norov bool 308942fa985SYury Norov 309942fa985SYury Norov# Select if arch wants to size task_struct dynamically via arch_task_struct_size: 310942fa985SYury Norovconfig ARCH_WANTS_DYNAMIC_TASK_STRUCT 311942fa985SYury Norov bool 312942fa985SYury Norov 31351c2ee6dSNick Desaulniersconfig ARCH_WANTS_NO_INSTR 31451c2ee6dSNick Desaulniers bool 31551c2ee6dSNick Desaulniers help 31651c2ee6dSNick Desaulniers An architecture should select this if the noinstr macro is being used on 31751c2ee6dSNick Desaulniers functions to denote that the toolchain should avoid instrumenting such 31851c2ee6dSNick Desaulniers functions and is required for correctness. 31951c2ee6dSNick Desaulniers 320942fa985SYury Norovconfig ARCH_32BIT_OFF_T 321942fa985SYury Norov bool 322942fa985SYury Norov depends on !64BIT 323942fa985SYury Norov help 324942fa985SYury Norov All new 32-bit architectures should have 64-bit off_t type on 325942fa985SYury Norov userspace side which corresponds to the loff_t kernel type. This 326942fa985SYury Norov is the requirement for modern ABIs. Some existing architectures 327942fa985SYury Norov still support 32-bit off_t. This option is enabled for all such 328942fa985SYury Norov architectures explicitly. 329942fa985SYury Norov 33096c0a6a7SHeiko Carstens# Selected by 64 bit architectures which have a 32 bit f_tinode in struct ustat 33196c0a6a7SHeiko Carstensconfig ARCH_32BIT_USTAT_F_TINODE 33296c0a6a7SHeiko Carstens bool 33396c0a6a7SHeiko Carstens 3342ff2b7ecSMasahiro Yamadaconfig HAVE_ASM_MODVERSIONS 3352ff2b7ecSMasahiro Yamada bool 3362ff2b7ecSMasahiro Yamada help 337a86ecfa6SColin Ian King This symbol should be selected by an architecture if it provides 3382ff2b7ecSMasahiro Yamada <asm/asm-prototypes.h> to support the module versioning for symbols 3392ff2b7ecSMasahiro Yamada exported from assembly code. 3402ff2b7ecSMasahiro Yamada 341f850c30cSHeiko Carstensconfig HAVE_REGS_AND_STACK_ACCESS_API 342f850c30cSHeiko Carstens bool 343e01292b1SHeiko Carstens help 344a86ecfa6SColin Ian King This symbol should be selected by an architecture if it supports 345e01292b1SHeiko Carstens the API needed to access registers and stack entries from pt_regs, 346e01292b1SHeiko Carstens declared in asm/ptrace.h 347e01292b1SHeiko Carstens For example the kprobes-based event tracer needs this API. 348f850c30cSHeiko Carstens 349d7822b1eSMathieu Desnoyersconfig HAVE_RSEQ 350d7822b1eSMathieu Desnoyers bool 351d7822b1eSMathieu Desnoyers depends on HAVE_REGS_AND_STACK_ACCESS_API 352d7822b1eSMathieu Desnoyers help 353d7822b1eSMathieu Desnoyers This symbol should be selected by an architecture if it 354d7822b1eSMathieu Desnoyers supports an implementation of restartable sequences. 355d7822b1eSMathieu Desnoyers 3563c88ee19SMasami Hiramatsuconfig HAVE_FUNCTION_ARG_ACCESS_API 3573c88ee19SMasami Hiramatsu bool 3583c88ee19SMasami Hiramatsu help 359a86ecfa6SColin Ian King This symbol should be selected by an architecture if it supports 3603c88ee19SMasami Hiramatsu the API needed to access function arguments from pt_regs, 3613c88ee19SMasami Hiramatsu declared in asm/ptrace.h 3623c88ee19SMasami Hiramatsu 36362a038d3SK.Prasadconfig HAVE_HW_BREAKPOINT 36462a038d3SK.Prasad bool 36599e8c5a3SFrederic Weisbecker depends on PERF_EVENTS 36662a038d3SK.Prasad 3670102752eSFrederic Weisbeckerconfig HAVE_MIXED_BREAKPOINTS_REGS 3680102752eSFrederic Weisbecker bool 3690102752eSFrederic Weisbecker depends on HAVE_HW_BREAKPOINT 3700102752eSFrederic Weisbecker help 3710102752eSFrederic Weisbecker Depending on the arch implementation of hardware breakpoints, 3720102752eSFrederic Weisbecker some of them have separate registers for data and instruction 3730102752eSFrederic Weisbecker breakpoints addresses, others have mixed registers to store 3740102752eSFrederic Weisbecker them but define the access type in a control register. 3750102752eSFrederic Weisbecker Select this option if your arch implements breakpoints under the 3760102752eSFrederic Weisbecker latter fashion. 3770102752eSFrederic Weisbecker 3787c68af6eSAvi Kivityconfig HAVE_USER_RETURN_NOTIFIER 3797c68af6eSAvi Kivity bool 380a1922ed6SIngo Molnar 381c01d4323SFrederic Weisbeckerconfig HAVE_PERF_EVENTS_NMI 382c01d4323SFrederic Weisbecker bool 38323637d47SFrederic Weisbecker help 38423637d47SFrederic Weisbecker System hardware can generate an NMI using the perf event 38523637d47SFrederic Weisbecker subsystem. Also has support for calculating CPU cycle events 38623637d47SFrederic Weisbecker to determine how many clock cycles in a given period. 387c01d4323SFrederic Weisbecker 38805a4a952SNicholas Pigginconfig HAVE_HARDLOCKUP_DETECTOR_PERF 38905a4a952SNicholas Piggin bool 39005a4a952SNicholas Piggin depends on HAVE_PERF_EVENTS_NMI 39105a4a952SNicholas Piggin help 39205a4a952SNicholas Piggin The arch chooses to use the generic perf-NMI-based hardlockup 39305a4a952SNicholas Piggin detector. Must define HAVE_PERF_EVENTS_NMI. 39405a4a952SNicholas Piggin 39505a4a952SNicholas Pigginconfig HAVE_NMI_WATCHDOG 39605a4a952SNicholas Piggin depends on HAVE_NMI 39705a4a952SNicholas Piggin bool 39805a4a952SNicholas Piggin help 39905a4a952SNicholas Piggin The arch provides a low level NMI watchdog. It provides 40005a4a952SNicholas Piggin asm/nmi.h, and defines its own arch_touch_nmi_watchdog(). 40105a4a952SNicholas Piggin 40205a4a952SNicholas Pigginconfig HAVE_HARDLOCKUP_DETECTOR_ARCH 40305a4a952SNicholas Piggin bool 40405a4a952SNicholas Piggin select HAVE_NMI_WATCHDOG 40505a4a952SNicholas Piggin help 40605a4a952SNicholas Piggin The arch chooses to provide its own hardlockup detector, which is 40705a4a952SNicholas Piggin a superset of the HAVE_NMI_WATCHDOG. It also conforms to config 40805a4a952SNicholas Piggin interfaces and parameters provided by hardlockup detector subsystem. 40905a4a952SNicholas Piggin 410c5e63197SJiri Olsaconfig HAVE_PERF_REGS 411c5e63197SJiri Olsa bool 412c5e63197SJiri Olsa help 413c5e63197SJiri Olsa Support selective register dumps for perf events. This includes 414c5e63197SJiri Olsa bit-mapping of each registers and a unique architecture id. 415c5e63197SJiri Olsa 416c5ebcedbSJiri Olsaconfig HAVE_PERF_USER_STACK_DUMP 417c5ebcedbSJiri Olsa bool 418c5ebcedbSJiri Olsa help 419c5ebcedbSJiri Olsa Support user stack dumps for perf event samples. This needs 420c5ebcedbSJiri Olsa access to the user stack pointer which is not unified across 421c5ebcedbSJiri Olsa architectures. 422c5ebcedbSJiri Olsa 423bf5438fcSJason Baronconfig HAVE_ARCH_JUMP_LABEL 424bf5438fcSJason Baron bool 425bf5438fcSJason Baron 42650ff18abSArd Biesheuvelconfig HAVE_ARCH_JUMP_LABEL_RELATIVE 42750ff18abSArd Biesheuvel bool 42850ff18abSArd Biesheuvel 4290d6e24d4SPeter Zijlstraconfig MMU_GATHER_TABLE_FREE 4300d6e24d4SPeter Zijlstra bool 4310d6e24d4SPeter Zijlstra 432ff2e6d72SPeter Zijlstraconfig MMU_GATHER_RCU_TABLE_FREE 43326723911SPeter Zijlstra bool 4340d6e24d4SPeter Zijlstra select MMU_GATHER_TABLE_FREE 43526723911SPeter Zijlstra 4363af4bd03SPeter Zijlstraconfig MMU_GATHER_PAGE_SIZE 437ed6a7935SPeter Zijlstra bool 438ed6a7935SPeter Zijlstra 43927796d03SPeter Zijlstraconfig MMU_GATHER_NO_RANGE 44027796d03SPeter Zijlstra bool 441*1e9fdf21SPeter Zijlstra select MMU_GATHER_MERGE_VMAS 442*1e9fdf21SPeter Zijlstra 443*1e9fdf21SPeter Zijlstraconfig MMU_GATHER_NO_FLUSH_CACHE 444*1e9fdf21SPeter Zijlstra bool 445*1e9fdf21SPeter Zijlstra 446*1e9fdf21SPeter Zijlstraconfig MMU_GATHER_MERGE_VMAS 447*1e9fdf21SPeter Zijlstra bool 44827796d03SPeter Zijlstra 449580a586cSPeter Zijlstraconfig MMU_GATHER_NO_GATHER 450952a31c9SMartin Schwidefsky bool 4510d6e24d4SPeter Zijlstra depends on MMU_GATHER_TABLE_FREE 452952a31c9SMartin Schwidefsky 453d53c3dfbSNicholas Pigginconfig ARCH_WANT_IRQS_OFF_ACTIVATE_MM 454d53c3dfbSNicholas Piggin bool 455d53c3dfbSNicholas Piggin help 456d53c3dfbSNicholas Piggin Temporary select until all architectures can be converted to have 457d53c3dfbSNicholas Piggin irqs disabled over activate_mm. Architectures that do IPI based TLB 458d53c3dfbSNicholas Piggin shootdowns should enable this. 459d53c3dfbSNicholas Piggin 460df013ffbSHuang Yingconfig ARCH_HAVE_NMI_SAFE_CMPXCHG 461df013ffbSHuang Ying bool 462df013ffbSHuang Ying 46343570fd2SHeiko Carstensconfig HAVE_ALIGNED_STRUCT_PAGE 46443570fd2SHeiko Carstens bool 46543570fd2SHeiko Carstens help 46643570fd2SHeiko Carstens This makes sure that struct pages are double word aligned and that 46743570fd2SHeiko Carstens e.g. the SLUB allocator can perform double word atomic operations 46843570fd2SHeiko Carstens on a struct page for better performance. However selecting this 46943570fd2SHeiko Carstens might increase the size of a struct page by a word. 47043570fd2SHeiko Carstens 4714156153cSHeiko Carstensconfig HAVE_CMPXCHG_LOCAL 4724156153cSHeiko Carstens bool 4734156153cSHeiko Carstens 4742565409fSHeiko Carstensconfig HAVE_CMPXCHG_DOUBLE 4752565409fSHeiko Carstens bool 4762565409fSHeiko Carstens 47777e58496SPaul E. McKenneyconfig ARCH_WEAK_RELEASE_ACQUIRE 47877e58496SPaul E. McKenney bool 47977e58496SPaul E. McKenney 480c1d7e01dSWill Deaconconfig ARCH_WANT_IPC_PARSE_VERSION 481c1d7e01dSWill Deacon bool 482c1d7e01dSWill Deacon 483c1d7e01dSWill Deaconconfig ARCH_WANT_COMPAT_IPC_PARSE_VERSION 484c1d7e01dSWill Deacon bool 485c1d7e01dSWill Deacon 48648b25c43SChris Metcalfconfig ARCH_WANT_OLD_COMPAT_IPC 487c1d7e01dSWill Deacon select ARCH_WANT_COMPAT_IPC_PARSE_VERSION 48848b25c43SChris Metcalf bool 48948b25c43SChris Metcalf 490282a181bSYiFei Zhuconfig HAVE_ARCH_SECCOMP 491e2cfabdfSWill Drewry bool 492e2cfabdfSWill Drewry help 493282a181bSYiFei Zhu An arch should select this symbol to support seccomp mode 1 (the fixed 494282a181bSYiFei Zhu syscall policy), and must provide an overrides for __NR_seccomp_sigreturn, 495282a181bSYiFei Zhu and compat syscalls if the asm-generic/seccomp.h defaults need adjustment: 496282a181bSYiFei Zhu - __NR_seccomp_read_32 497282a181bSYiFei Zhu - __NR_seccomp_write_32 498282a181bSYiFei Zhu - __NR_seccomp_exit_32 499282a181bSYiFei Zhu - __NR_seccomp_sigreturn_32 500282a181bSYiFei Zhu 501282a181bSYiFei Zhuconfig HAVE_ARCH_SECCOMP_FILTER 502282a181bSYiFei Zhu bool 503282a181bSYiFei Zhu select HAVE_ARCH_SECCOMP 504282a181bSYiFei Zhu help 505fb0fadf9SWill Drewry An arch should select this symbol if it provides all of these things: 506282a181bSYiFei Zhu - all the requirements for HAVE_ARCH_SECCOMP 507bb6ea430SWill Drewry - syscall_get_arch() 508bb6ea430SWill Drewry - syscall_get_arguments() 509bb6ea430SWill Drewry - syscall_rollback() 510bb6ea430SWill Drewry - syscall_set_return_value() 511fb0fadf9SWill Drewry - SIGSYS siginfo_t support 512fb0fadf9SWill Drewry - secure_computing is called from a ptrace_event()-safe context 513fb0fadf9SWill Drewry - secure_computing return value is checked and a return value of -1 514fb0fadf9SWill Drewry results in the system call being skipped immediately. 51548dc92b9SKees Cook - seccomp syscall wired up 5160d8315ddSYiFei Zhu - if !HAVE_SPARSE_SYSCALL_NR, have SECCOMP_ARCH_NATIVE, 5170d8315ddSYiFei Zhu SECCOMP_ARCH_NATIVE_NR, SECCOMP_ARCH_NATIVE_NAME defined. If 5180d8315ddSYiFei Zhu COMPAT is supported, have the SECCOMP_ARCH_COMPAT* defines too. 519e2cfabdfSWill Drewry 520282a181bSYiFei Zhuconfig SECCOMP 521282a181bSYiFei Zhu prompt "Enable seccomp to safely execute untrusted bytecode" 522282a181bSYiFei Zhu def_bool y 523282a181bSYiFei Zhu depends on HAVE_ARCH_SECCOMP 524282a181bSYiFei Zhu help 525282a181bSYiFei Zhu This kernel feature is useful for number crunching applications 526282a181bSYiFei Zhu that may need to handle untrusted bytecode during their 527282a181bSYiFei Zhu execution. By using pipes or other transports made available 528282a181bSYiFei Zhu to the process as file descriptors supporting the read/write 529282a181bSYiFei Zhu syscalls, it's possible to isolate those applications in their 530282a181bSYiFei Zhu own address space using seccomp. Once seccomp is enabled via 531282a181bSYiFei Zhu prctl(PR_SET_SECCOMP) or the seccomp() syscall, it cannot be 532282a181bSYiFei Zhu disabled and the task is only allowed to execute a few safe 533282a181bSYiFei Zhu syscalls defined by each seccomp mode. 534282a181bSYiFei Zhu 535282a181bSYiFei Zhu If unsure, say Y. 536282a181bSYiFei Zhu 537e2cfabdfSWill Drewryconfig SECCOMP_FILTER 538e2cfabdfSWill Drewry def_bool y 539e2cfabdfSWill Drewry depends on HAVE_ARCH_SECCOMP_FILTER && SECCOMP && NET 540e2cfabdfSWill Drewry help 541e2cfabdfSWill Drewry Enable tasks to build secure computing environments defined 542e2cfabdfSWill Drewry in terms of Berkeley Packet Filter programs which implement 543e2cfabdfSWill Drewry task-defined system call filtering polices. 544e2cfabdfSWill Drewry 5455fb94e9cSMauro Carvalho Chehab See Documentation/userspace-api/seccomp_filter.rst for details. 546e2cfabdfSWill Drewry 5470d8315ddSYiFei Zhuconfig SECCOMP_CACHE_DEBUG 5480d8315ddSYiFei Zhu bool "Show seccomp filter cache status in /proc/pid/seccomp_cache" 5490d8315ddSYiFei Zhu depends on SECCOMP_FILTER && !HAVE_SPARSE_SYSCALL_NR 5500d8315ddSYiFei Zhu depends on PROC_FS 5510d8315ddSYiFei Zhu help 5520d8315ddSYiFei Zhu This enables the /proc/pid/seccomp_cache interface to monitor 5530d8315ddSYiFei Zhu seccomp cache data. The file format is subject to change. Reading 5540d8315ddSYiFei Zhu the file requires CAP_SYS_ADMIN. 5550d8315ddSYiFei Zhu 5560d8315ddSYiFei Zhu This option is for debugging only. Enabling presents the risk that 5570d8315ddSYiFei Zhu an adversary may be able to infer the seccomp filter logic. 5580d8315ddSYiFei Zhu 5590d8315ddSYiFei Zhu If unsure, say N. 5600d8315ddSYiFei Zhu 561afaef01cSAlexander Popovconfig HAVE_ARCH_STACKLEAK 562afaef01cSAlexander Popov bool 563afaef01cSAlexander Popov help 564afaef01cSAlexander Popov An architecture should select this if it has the code which 565afaef01cSAlexander Popov fills the used part of the kernel stack with the STACKLEAK_POISON 566afaef01cSAlexander Popov value before returning from system calls. 567afaef01cSAlexander Popov 568d148eac0SMasahiro Yamadaconfig HAVE_STACKPROTECTOR 56919952a92SKees Cook bool 57019952a92SKees Cook help 57119952a92SKees Cook An arch should select this symbol if: 57219952a92SKees Cook - it has implemented a stack canary (e.g. __stack_chk_guard) 57319952a92SKees Cook 574050e9baaSLinus Torvaldsconfig STACKPROTECTOR 5752a61f474SMasahiro Yamada bool "Stack Protector buffer overflow detection" 576d148eac0SMasahiro Yamada depends on HAVE_STACKPROTECTOR 5772a61f474SMasahiro Yamada depends on $(cc-option,-fstack-protector) 5782a61f474SMasahiro Yamada default y 5798779657dSKees Cook help 5808779657dSKees Cook This option turns on the "stack-protector" GCC feature. This 58119952a92SKees Cook feature puts, at the beginning of functions, a canary value on 58219952a92SKees Cook the stack just before the return address, and validates 58319952a92SKees Cook the value just before actually returning. Stack based buffer 58419952a92SKees Cook overflows (that need to overwrite this return address) now also 58519952a92SKees Cook overwrite the canary, which gets detected and the attack is then 58619952a92SKees Cook neutralized via a kernel panic. 58719952a92SKees Cook 5888779657dSKees Cook Functions will have the stack-protector canary logic added if they 5898779657dSKees Cook have an 8-byte or larger character array on the stack. 5908779657dSKees Cook 59119952a92SKees Cook This feature requires gcc version 4.2 or above, or a distribution 5928779657dSKees Cook gcc with the feature backported ("-fstack-protector"). 5938779657dSKees Cook 5948779657dSKees Cook On an x86 "defconfig" build, this feature adds canary checks to 5958779657dSKees Cook about 3% of all kernel functions, which increases kernel code size 5968779657dSKees Cook by about 0.3%. 5978779657dSKees Cook 598050e9baaSLinus Torvaldsconfig STACKPROTECTOR_STRONG 5992a61f474SMasahiro Yamada bool "Strong Stack Protector" 600050e9baaSLinus Torvalds depends on STACKPROTECTOR 6012a61f474SMasahiro Yamada depends on $(cc-option,-fstack-protector-strong) 6022a61f474SMasahiro Yamada default y 6038779657dSKees Cook help 6048779657dSKees Cook Functions will have the stack-protector canary logic added in any 6058779657dSKees Cook of the following conditions: 6068779657dSKees Cook 6078779657dSKees Cook - local variable's address used as part of the right hand side of an 6088779657dSKees Cook assignment or function argument 6098779657dSKees Cook - local variable is an array (or union containing an array), 6108779657dSKees Cook regardless of array type or length 6118779657dSKees Cook - uses register local variables 6128779657dSKees Cook 6138779657dSKees Cook This feature requires gcc version 4.9 or above, or a distribution 6148779657dSKees Cook gcc with the feature backported ("-fstack-protector-strong"). 6158779657dSKees Cook 6168779657dSKees Cook On an x86 "defconfig" build, this feature adds canary checks to 6178779657dSKees Cook about 20% of all kernel functions, which increases the kernel code 6188779657dSKees Cook size by about 2%. 6198779657dSKees Cook 620d08b9f0cSSami Tolvanenconfig ARCH_SUPPORTS_SHADOW_CALL_STACK 621d08b9f0cSSami Tolvanen bool 622d08b9f0cSSami Tolvanen help 623afcf5441SDan Li An architecture should select this if it supports the compiler's 624afcf5441SDan Li Shadow Call Stack and implements runtime support for shadow stack 625aa7a65aeSWill Deacon switching. 626d08b9f0cSSami Tolvanen 627d08b9f0cSSami Tolvanenconfig SHADOW_CALL_STACK 628afcf5441SDan Li bool "Shadow Call Stack" 629afcf5441SDan Li depends on ARCH_SUPPORTS_SHADOW_CALL_STACK 630ddc9863eSSami Tolvanen depends on DYNAMIC_FTRACE_WITH_REGS || !FUNCTION_GRAPH_TRACER 631d08b9f0cSSami Tolvanen help 632afcf5441SDan Li This option enables the compiler's Shadow Call Stack, which 633afcf5441SDan Li uses a shadow stack to protect function return addresses from 634afcf5441SDan Li being overwritten by an attacker. More information can be found 635afcf5441SDan Li in the compiler's documentation: 636d08b9f0cSSami Tolvanen 637afcf5441SDan Li - Clang: https://clang.llvm.org/docs/ShadowCallStack.html 638afcf5441SDan Li - GCC: https://gcc.gnu.org/onlinedocs/gcc/Instrumentation-Options.html#Instrumentation-Options 639d08b9f0cSSami Tolvanen 640d08b9f0cSSami Tolvanen Note that security guarantees in the kernel differ from the 641d08b9f0cSSami Tolvanen ones documented for user space. The kernel must store addresses 642d08b9f0cSSami Tolvanen of shadow stacks in memory, which means an attacker capable of 643d08b9f0cSSami Tolvanen reading and writing arbitrary memory may be able to locate them 644d08b9f0cSSami Tolvanen and hijack control flow by modifying the stacks. 645d08b9f0cSSami Tolvanen 646dc5723b0SSami Tolvanenconfig LTO 647dc5723b0SSami Tolvanen bool 648dc5723b0SSami Tolvanen help 649dc5723b0SSami Tolvanen Selected if the kernel will be built using the compiler's LTO feature. 650dc5723b0SSami Tolvanen 651dc5723b0SSami Tolvanenconfig LTO_CLANG 652dc5723b0SSami Tolvanen bool 653dc5723b0SSami Tolvanen select LTO 654dc5723b0SSami Tolvanen help 655dc5723b0SSami Tolvanen Selected if the kernel will be built using Clang's LTO feature. 656dc5723b0SSami Tolvanen 657dc5723b0SSami Tolvanenconfig ARCH_SUPPORTS_LTO_CLANG 658dc5723b0SSami Tolvanen bool 659dc5723b0SSami Tolvanen help 660dc5723b0SSami Tolvanen An architecture should select this option if it supports: 661dc5723b0SSami Tolvanen - compiling with Clang, 662dc5723b0SSami Tolvanen - compiling inline assembly with Clang's integrated assembler, 663dc5723b0SSami Tolvanen - and linking with LLD. 664dc5723b0SSami Tolvanen 665dc5723b0SSami Tolvanenconfig ARCH_SUPPORTS_LTO_CLANG_THIN 666dc5723b0SSami Tolvanen bool 667dc5723b0SSami Tolvanen help 668dc5723b0SSami Tolvanen An architecture should select this option if it can support Clang's 669dc5723b0SSami Tolvanen ThinLTO mode. 670dc5723b0SSami Tolvanen 671dc5723b0SSami Tolvanenconfig HAS_LTO_CLANG 672dc5723b0SSami Tolvanen def_bool y 6731e68a8afSNathan Chancellor depends on CC_IS_CLANG && LD_IS_LLD && AS_IS_LLVM 674dc5723b0SSami Tolvanen depends on $(success,$(NM) --help | head -n 1 | grep -qi llvm) 675dc5723b0SSami Tolvanen depends on $(success,$(AR) --help | head -n 1 | grep -qi llvm) 676dc5723b0SSami Tolvanen depends on ARCH_SUPPORTS_LTO_CLANG 677dc5723b0SSami Tolvanen depends on !FTRACE_MCOUNT_USE_RECORDMCOUNT 678bf3c2551SSami Tolvanen depends on !KASAN || KASAN_HW_TAGS 679dc5723b0SSami Tolvanen depends on !GCOV_KERNEL 680dc5723b0SSami Tolvanen help 681dc5723b0SSami Tolvanen The compiler and Kconfig options support building with Clang's 682dc5723b0SSami Tolvanen LTO. 683dc5723b0SSami Tolvanen 684dc5723b0SSami Tolvanenchoice 685dc5723b0SSami Tolvanen prompt "Link Time Optimization (LTO)" 686dc5723b0SSami Tolvanen default LTO_NONE 687dc5723b0SSami Tolvanen help 688dc5723b0SSami Tolvanen This option enables Link Time Optimization (LTO), which allows the 689dc5723b0SSami Tolvanen compiler to optimize binaries globally. 690dc5723b0SSami Tolvanen 691dc5723b0SSami Tolvanen If unsure, select LTO_NONE. Note that LTO is very resource-intensive 692dc5723b0SSami Tolvanen so it's disabled by default. 693dc5723b0SSami Tolvanen 694dc5723b0SSami Tolvanenconfig LTO_NONE 695dc5723b0SSami Tolvanen bool "None" 696dc5723b0SSami Tolvanen help 697dc5723b0SSami Tolvanen Build the kernel normally, without Link Time Optimization (LTO). 698dc5723b0SSami Tolvanen 699dc5723b0SSami Tolvanenconfig LTO_CLANG_FULL 700dc5723b0SSami Tolvanen bool "Clang Full LTO (EXPERIMENTAL)" 701dc5723b0SSami Tolvanen depends on HAS_LTO_CLANG 702dc5723b0SSami Tolvanen depends on !COMPILE_TEST 703dc5723b0SSami Tolvanen select LTO_CLANG 704dc5723b0SSami Tolvanen help 705dc5723b0SSami Tolvanen This option enables Clang's full Link Time Optimization (LTO), which 706dc5723b0SSami Tolvanen allows the compiler to optimize the kernel globally. If you enable 707dc5723b0SSami Tolvanen this option, the compiler generates LLVM bitcode instead of ELF 708dc5723b0SSami Tolvanen object files, and the actual compilation from bitcode happens at 709dc5723b0SSami Tolvanen the LTO link step, which may take several minutes depending on the 710dc5723b0SSami Tolvanen kernel configuration. More information can be found from LLVM's 711dc5723b0SSami Tolvanen documentation: 712dc5723b0SSami Tolvanen 713dc5723b0SSami Tolvanen https://llvm.org/docs/LinkTimeOptimization.html 714dc5723b0SSami Tolvanen 715dc5723b0SSami Tolvanen During link time, this option can use a large amount of RAM, and 716dc5723b0SSami Tolvanen may take much longer than the ThinLTO option. 717dc5723b0SSami Tolvanen 718dc5723b0SSami Tolvanenconfig LTO_CLANG_THIN 719dc5723b0SSami Tolvanen bool "Clang ThinLTO (EXPERIMENTAL)" 720dc5723b0SSami Tolvanen depends on HAS_LTO_CLANG && ARCH_SUPPORTS_LTO_CLANG_THIN 721dc5723b0SSami Tolvanen select LTO_CLANG 722dc5723b0SSami Tolvanen help 723dc5723b0SSami Tolvanen This option enables Clang's ThinLTO, which allows for parallel 724dc5723b0SSami Tolvanen optimization and faster incremental compiles compared to the 725dc5723b0SSami Tolvanen CONFIG_LTO_CLANG_FULL option. More information can be found 726dc5723b0SSami Tolvanen from Clang's documentation: 727dc5723b0SSami Tolvanen 728dc5723b0SSami Tolvanen https://clang.llvm.org/docs/ThinLTO.html 729dc5723b0SSami Tolvanen 730dc5723b0SSami Tolvanen If unsure, say Y. 731dc5723b0SSami Tolvanenendchoice 732dc5723b0SSami Tolvanen 733cf68fffbSSami Tolvanenconfig ARCH_SUPPORTS_CFI_CLANG 734cf68fffbSSami Tolvanen bool 735cf68fffbSSami Tolvanen help 736cf68fffbSSami Tolvanen An architecture should select this option if it can support Clang's 737cf68fffbSSami Tolvanen Control-Flow Integrity (CFI) checking. 738cf68fffbSSami Tolvanen 739cf68fffbSSami Tolvanenconfig CFI_CLANG 740cf68fffbSSami Tolvanen bool "Use Clang's Control Flow Integrity (CFI)" 741cf68fffbSSami Tolvanen depends on LTO_CLANG && ARCH_SUPPORTS_CFI_CLANG 742e6f3b3c9SSami Tolvanen depends on CLANG_VERSION >= 140000 743cf68fffbSSami Tolvanen select KALLSYMS 744cf68fffbSSami Tolvanen help 745cf68fffbSSami Tolvanen This option enables Clang’s forward-edge Control Flow Integrity 746cf68fffbSSami Tolvanen (CFI) checking, where the compiler injects a runtime check to each 747cf68fffbSSami Tolvanen indirect function call to ensure the target is a valid function with 748cf68fffbSSami Tolvanen the correct static type. This restricts possible call targets and 749cf68fffbSSami Tolvanen makes it more difficult for an attacker to exploit bugs that allow 750cf68fffbSSami Tolvanen the modification of stored function pointers. More information can be 751cf68fffbSSami Tolvanen found from Clang's documentation: 752cf68fffbSSami Tolvanen 753cf68fffbSSami Tolvanen https://clang.llvm.org/docs/ControlFlowIntegrity.html 754cf68fffbSSami Tolvanen 755cf68fffbSSami Tolvanenconfig CFI_CLANG_SHADOW 756cf68fffbSSami Tolvanen bool "Use CFI shadow to speed up cross-module checks" 757cf68fffbSSami Tolvanen default y 758cf68fffbSSami Tolvanen depends on CFI_CLANG && MODULES 759cf68fffbSSami Tolvanen help 760cf68fffbSSami Tolvanen If you select this option, the kernel builds a fast look-up table of 761cf68fffbSSami Tolvanen CFI check functions in loaded modules to reduce performance overhead. 762cf68fffbSSami Tolvanen 763cf68fffbSSami Tolvanen If unsure, say Y. 764cf68fffbSSami Tolvanen 765cf68fffbSSami Tolvanenconfig CFI_PERMISSIVE 766cf68fffbSSami Tolvanen bool "Use CFI in permissive mode" 767cf68fffbSSami Tolvanen depends on CFI_CLANG 768cf68fffbSSami Tolvanen help 769cf68fffbSSami Tolvanen When selected, Control Flow Integrity (CFI) violations result in a 770cf68fffbSSami Tolvanen warning instead of a kernel panic. This option should only be used 771cf68fffbSSami Tolvanen for finding indirect call type mismatches during development. 772cf68fffbSSami Tolvanen 773cf68fffbSSami Tolvanen If unsure, say N. 774cf68fffbSSami Tolvanen 7750f60a8efSKees Cookconfig HAVE_ARCH_WITHIN_STACK_FRAMES 7760f60a8efSKees Cook bool 7770f60a8efSKees Cook help 7780f60a8efSKees Cook An architecture should select this if it can walk the kernel stack 7790f60a8efSKees Cook frames to determine if an object is part of either the arguments 7800f60a8efSKees Cook or local variables (i.e. that it excludes saved return addresses, 7810f60a8efSKees Cook and similar) by implementing an inline arch_within_stack_frames(), 7820f60a8efSKees Cook which is used by CONFIG_HARDENED_USERCOPY. 7830f60a8efSKees Cook 78491d1aa43SFrederic Weisbeckerconfig HAVE_CONTEXT_TRACKING 7852b1d5024SFrederic Weisbecker bool 7862b1d5024SFrederic Weisbecker help 78791d1aa43SFrederic Weisbecker Provide kernel/user boundaries probes necessary for subsystems 78891d1aa43SFrederic Weisbecker that need it, such as userspace RCU extended quiescent state. 789490f561bSFrederic Weisbecker Syscalls need to be wrapped inside user_exit()-user_enter(), either 790490f561bSFrederic Weisbecker optimized behind static key or through the slow path using TIF_NOHZ 791490f561bSFrederic Weisbecker flag. Exceptions handlers must be wrapped as well. Irqs are already 792490f561bSFrederic Weisbecker protected inside rcu_irq_enter/rcu_irq_exit() but preemption or signal 793490f561bSFrederic Weisbecker handling on irq exit still need to be protected. 794490f561bSFrederic Weisbecker 79583c2da2eSFrederic Weisbeckerconfig HAVE_CONTEXT_TRACKING_OFFSTACK 79683c2da2eSFrederic Weisbecker bool 79783c2da2eSFrederic Weisbecker help 79883c2da2eSFrederic Weisbecker Architecture neither relies on exception_enter()/exception_exit() 79983c2da2eSFrederic Weisbecker nor on schedule_user(). Also preempt_schedule_notrace() and 80083c2da2eSFrederic Weisbecker preempt_schedule_irq() can't be called in a preemptible section 80183c2da2eSFrederic Weisbecker while context tracking is CONTEXT_USER. This feature reflects a sane 80283c2da2eSFrederic Weisbecker entry implementation where the following requirements are met on 80383c2da2eSFrederic Weisbecker critical entry code, ie: before user_exit() or after user_enter(): 80483c2da2eSFrederic Weisbecker 80583c2da2eSFrederic Weisbecker - Critical entry code isn't preemptible (or better yet: 80683c2da2eSFrederic Weisbecker not interruptible). 80783c2da2eSFrederic Weisbecker - No use of RCU read side critical sections, unless rcu_nmi_enter() 80883c2da2eSFrederic Weisbecker got called. 80983c2da2eSFrederic Weisbecker - No use of instrumentation, unless instrumentation_begin() got 81083c2da2eSFrederic Weisbecker called. 81183c2da2eSFrederic Weisbecker 812490f561bSFrederic Weisbeckerconfig HAVE_TIF_NOHZ 813490f561bSFrederic Weisbecker bool 814490f561bSFrederic Weisbecker help 815490f561bSFrederic Weisbecker Arch relies on TIF_NOHZ and syscall slow path to implement context 816490f561bSFrederic Weisbecker tracking calls to user_enter()/user_exit(). 8172b1d5024SFrederic Weisbecker 818b952741cSFrederic Weisbeckerconfig HAVE_VIRT_CPU_ACCOUNTING 819b952741cSFrederic Weisbecker bool 820b952741cSFrederic Weisbecker 8212b91ec9fSFrederic Weisbeckerconfig HAVE_VIRT_CPU_ACCOUNTING_IDLE 8222b91ec9fSFrederic Weisbecker bool 8232b91ec9fSFrederic Weisbecker help 8242b91ec9fSFrederic Weisbecker Architecture has its own way to account idle CPU time and therefore 8252b91ec9fSFrederic Weisbecker doesn't implement vtime_account_idle(). 8262b91ec9fSFrederic Weisbecker 82740565b5aSStanislaw Gruszkaconfig ARCH_HAS_SCALED_CPUTIME 82840565b5aSStanislaw Gruszka bool 82940565b5aSStanislaw Gruszka 830554b0004SKevin Hilmanconfig HAVE_VIRT_CPU_ACCOUNTING_GEN 831554b0004SKevin Hilman bool 832554b0004SKevin Hilman default y if 64BIT 833554b0004SKevin Hilman help 834554b0004SKevin Hilman With VIRT_CPU_ACCOUNTING_GEN, cputime_t becomes 64-bit. 835554b0004SKevin Hilman Before enabling this option, arch code must be audited 836554b0004SKevin Hilman to ensure there are no races in concurrent read/write of 837554b0004SKevin Hilman cputime_t. For example, reading/writing 64-bit cputime_t on 838554b0004SKevin Hilman some 32-bit arches may require multiple accesses, so proper 839554b0004SKevin Hilman locking is needed to protect against concurrent accesses. 840554b0004SKevin Hilman 841fdf9c356SFrederic Weisbeckerconfig HAVE_IRQ_TIME_ACCOUNTING 842fdf9c356SFrederic Weisbecker bool 843fdf9c356SFrederic Weisbecker help 844fdf9c356SFrederic Weisbecker Archs need to ensure they use a high enough resolution clock to 845fdf9c356SFrederic Weisbecker support irq time accounting and then call enable_sched_clock_irqtime(). 846fdf9c356SFrederic Weisbecker 847c49dd340SKalesh Singhconfig HAVE_MOVE_PUD 848c49dd340SKalesh Singh bool 849c49dd340SKalesh Singh help 850c49dd340SKalesh Singh Architectures that select this are able to move page tables at the 851c49dd340SKalesh Singh PUD level. If there are only 3 page table levels, the move effectively 852c49dd340SKalesh Singh happens at the PGD level. 853c49dd340SKalesh Singh 8542c91bd4aSJoel Fernandes (Google)config HAVE_MOVE_PMD 8552c91bd4aSJoel Fernandes (Google) bool 8562c91bd4aSJoel Fernandes (Google) help 8572c91bd4aSJoel Fernandes (Google) Archs that select this are able to move page tables at the PMD level. 8582c91bd4aSJoel Fernandes (Google) 85915626062SGerald Schaeferconfig HAVE_ARCH_TRANSPARENT_HUGEPAGE 86015626062SGerald Schaefer bool 86115626062SGerald Schaefer 862a00cc7d9SMatthew Wilcoxconfig HAVE_ARCH_TRANSPARENT_HUGEPAGE_PUD 863a00cc7d9SMatthew Wilcox bool 864a00cc7d9SMatthew Wilcox 8650ddab1d2SToshi Kaniconfig HAVE_ARCH_HUGE_VMAP 8660ddab1d2SToshi Kani bool 8670ddab1d2SToshi Kani 868121e6f32SNicholas Piggin# 869121e6f32SNicholas Piggin# Archs that select this would be capable of PMD-sized vmaps (i.e., 870559089e0SSong Liu# arch_vmap_pmd_supported() returns true). The VM_ALLOW_HUGE_VMAP flag 871559089e0SSong Liu# must be used to enable allocations to use hugepages. 872121e6f32SNicholas Piggin# 873121e6f32SNicholas Pigginconfig HAVE_ARCH_HUGE_VMALLOC 874121e6f32SNicholas Piggin depends on HAVE_ARCH_HUGE_VMAP 875121e6f32SNicholas Piggin bool 876121e6f32SNicholas Piggin 8773876d4a3SAlexandre Ghiticonfig ARCH_WANT_HUGE_PMD_SHARE 8783876d4a3SAlexandre Ghiti bool 8793876d4a3SAlexandre Ghiti 8800f8975ecSPavel Emelyanovconfig HAVE_ARCH_SOFT_DIRTY 8810f8975ecSPavel Emelyanov bool 8820f8975ecSPavel Emelyanov 883786d35d4SDavid Howellsconfig HAVE_MOD_ARCH_SPECIFIC 884786d35d4SDavid Howells bool 885786d35d4SDavid Howells help 886786d35d4SDavid Howells The arch uses struct mod_arch_specific to store data. Many arches 887786d35d4SDavid Howells just need a simple module loader without arch specific data - those 888786d35d4SDavid Howells should not enable this. 889786d35d4SDavid Howells 890786d35d4SDavid Howellsconfig MODULES_USE_ELF_RELA 891786d35d4SDavid Howells bool 892786d35d4SDavid Howells help 893786d35d4SDavid Howells Modules only use ELF RELA relocations. Modules with ELF REL 894786d35d4SDavid Howells relocations will give an error. 895786d35d4SDavid Howells 896786d35d4SDavid Howellsconfig MODULES_USE_ELF_REL 897786d35d4SDavid Howells bool 898786d35d4SDavid Howells help 899786d35d4SDavid Howells Modules only use ELF REL relocations. Modules with ELF RELA 900786d35d4SDavid Howells relocations will give an error. 901786d35d4SDavid Howells 90201dc0386SChristophe Leroyconfig ARCH_WANTS_MODULES_DATA_IN_VMALLOC 90301dc0386SChristophe Leroy bool 90401dc0386SChristophe Leroy help 90501dc0386SChristophe Leroy For architectures like powerpc/32 which have constraints on module 90601dc0386SChristophe Leroy allocation and need to allocate module data outside of module area. 90701dc0386SChristophe Leroy 908cc1f0274SFrederic Weisbeckerconfig HAVE_IRQ_EXIT_ON_IRQ_STACK 909cc1f0274SFrederic Weisbecker bool 910cc1f0274SFrederic Weisbecker help 911cc1f0274SFrederic Weisbecker Architecture doesn't only execute the irq handler on the irq stack 912cc1f0274SFrederic Weisbecker but also irq_exit(). This way we can process softirqs on this irq 913cc1f0274SFrederic Weisbecker stack instead of switching to a new one when we call __do_softirq() 914cc1f0274SFrederic Weisbecker in the end of an hardirq. 915cc1f0274SFrederic Weisbecker This spares a stack switch and improves cache usage on softirq 916cc1f0274SFrederic Weisbecker processing. 917cc1f0274SFrederic Weisbecker 918cd1a41ceSThomas Gleixnerconfig HAVE_SOFTIRQ_ON_OWN_STACK 919cd1a41ceSThomas Gleixner bool 920cd1a41ceSThomas Gleixner help 921cd1a41ceSThomas Gleixner Architecture provides a function to run __do_softirq() on a 922c226bc3cSColin Ian King separate stack. 923cd1a41ceSThomas Gleixner 92412700c17SArnd Bergmannconfig ALTERNATE_USER_ADDRESS_SPACE 92512700c17SArnd Bergmann bool 92612700c17SArnd Bergmann help 92712700c17SArnd Bergmann Architectures set this when the CPU uses separate address 92812700c17SArnd Bergmann spaces for kernel and user space pointers. In this case, the 92912700c17SArnd Bergmann access_ok() check on a __user pointer is skipped. 93012700c17SArnd Bergmann 931235a8f02SKirill A. Shutemovconfig PGTABLE_LEVELS 932235a8f02SKirill A. Shutemov int 933235a8f02SKirill A. Shutemov default 2 934235a8f02SKirill A. Shutemov 9352b68f6caSKees Cookconfig ARCH_HAS_ELF_RANDOMIZE 9362b68f6caSKees Cook bool 9372b68f6caSKees Cook help 9382b68f6caSKees Cook An architecture supports choosing randomized locations for 9392b68f6caSKees Cook stack, mmap, brk, and ET_DYN. Defined functions: 9402b68f6caSKees Cook - arch_mmap_rnd() 941204db6edSKees Cook - arch_randomize_brk() 9422b68f6caSKees Cook 943d07e2259SDaniel Cashmanconfig HAVE_ARCH_MMAP_RND_BITS 944d07e2259SDaniel Cashman bool 945d07e2259SDaniel Cashman help 946d07e2259SDaniel Cashman An arch should select this symbol if it supports setting a variable 947d07e2259SDaniel Cashman number of bits for use in establishing the base address for mmap 948d07e2259SDaniel Cashman allocations, has MMU enabled and provides values for both: 949d07e2259SDaniel Cashman - ARCH_MMAP_RND_BITS_MIN 950d07e2259SDaniel Cashman - ARCH_MMAP_RND_BITS_MAX 951d07e2259SDaniel Cashman 9525f56a5dfSJiri Slabyconfig HAVE_EXIT_THREAD 9535f56a5dfSJiri Slaby bool 9545f56a5dfSJiri Slaby help 9555f56a5dfSJiri Slaby An architecture implements exit_thread. 9565f56a5dfSJiri Slaby 957d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_BITS_MIN 958d07e2259SDaniel Cashman int 959d07e2259SDaniel Cashman 960d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_BITS_MAX 961d07e2259SDaniel Cashman int 962d07e2259SDaniel Cashman 963d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_BITS_DEFAULT 964d07e2259SDaniel Cashman int 965d07e2259SDaniel Cashman 966d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_BITS 967d07e2259SDaniel Cashman int "Number of bits to use for ASLR of mmap base address" if EXPERT 968d07e2259SDaniel Cashman range ARCH_MMAP_RND_BITS_MIN ARCH_MMAP_RND_BITS_MAX 969d07e2259SDaniel Cashman default ARCH_MMAP_RND_BITS_DEFAULT if ARCH_MMAP_RND_BITS_DEFAULT 970d07e2259SDaniel Cashman default ARCH_MMAP_RND_BITS_MIN 971d07e2259SDaniel Cashman depends on HAVE_ARCH_MMAP_RND_BITS 972d07e2259SDaniel Cashman help 973d07e2259SDaniel Cashman This value can be used to select the number of bits to use to 974d07e2259SDaniel Cashman determine the random offset to the base address of vma regions 975d07e2259SDaniel Cashman resulting from mmap allocations. This value will be bounded 976d07e2259SDaniel Cashman by the architecture's minimum and maximum supported values. 977d07e2259SDaniel Cashman 978d07e2259SDaniel Cashman This value can be changed after boot using the 979d07e2259SDaniel Cashman /proc/sys/vm/mmap_rnd_bits tunable 980d07e2259SDaniel Cashman 981d07e2259SDaniel Cashmanconfig HAVE_ARCH_MMAP_RND_COMPAT_BITS 982d07e2259SDaniel Cashman bool 983d07e2259SDaniel Cashman help 984d07e2259SDaniel Cashman An arch should select this symbol if it supports running applications 985d07e2259SDaniel Cashman in compatibility mode, supports setting a variable number of bits for 986d07e2259SDaniel Cashman use in establishing the base address for mmap allocations, has MMU 987d07e2259SDaniel Cashman enabled and provides values for both: 988d07e2259SDaniel Cashman - ARCH_MMAP_RND_COMPAT_BITS_MIN 989d07e2259SDaniel Cashman - ARCH_MMAP_RND_COMPAT_BITS_MAX 990d07e2259SDaniel Cashman 991d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_COMPAT_BITS_MIN 992d07e2259SDaniel Cashman int 993d07e2259SDaniel Cashman 994d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_COMPAT_BITS_MAX 995d07e2259SDaniel Cashman int 996d07e2259SDaniel Cashman 997d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_COMPAT_BITS_DEFAULT 998d07e2259SDaniel Cashman int 999d07e2259SDaniel Cashman 1000d07e2259SDaniel Cashmanconfig ARCH_MMAP_RND_COMPAT_BITS 1001d07e2259SDaniel Cashman int "Number of bits to use for ASLR of mmap base address for compatible applications" if EXPERT 1002d07e2259SDaniel Cashman range ARCH_MMAP_RND_COMPAT_BITS_MIN ARCH_MMAP_RND_COMPAT_BITS_MAX 1003d07e2259SDaniel Cashman default ARCH_MMAP_RND_COMPAT_BITS_DEFAULT if ARCH_MMAP_RND_COMPAT_BITS_DEFAULT 1004d07e2259SDaniel Cashman default ARCH_MMAP_RND_COMPAT_BITS_MIN 1005d07e2259SDaniel Cashman depends on HAVE_ARCH_MMAP_RND_COMPAT_BITS 1006d07e2259SDaniel Cashman help 1007d07e2259SDaniel Cashman This value can be used to select the number of bits to use to 1008d07e2259SDaniel Cashman determine the random offset to the base address of vma regions 1009d07e2259SDaniel Cashman resulting from mmap allocations for compatible applications This 1010d07e2259SDaniel Cashman value will be bounded by the architecture's minimum and maximum 1011d07e2259SDaniel Cashman supported values. 1012d07e2259SDaniel Cashman 1013d07e2259SDaniel Cashman This value can be changed after boot using the 1014d07e2259SDaniel Cashman /proc/sys/vm/mmap_rnd_compat_bits tunable 1015d07e2259SDaniel Cashman 10161b028f78SDmitry Safonovconfig HAVE_ARCH_COMPAT_MMAP_BASES 10171b028f78SDmitry Safonov bool 10181b028f78SDmitry Safonov help 10191b028f78SDmitry Safonov This allows 64bit applications to invoke 32-bit mmap() syscall 10201b028f78SDmitry Safonov and vice-versa 32-bit applications to call 64-bit mmap(). 10211b028f78SDmitry Safonov Required for applications doing different bitness syscalls. 10221b028f78SDmitry Safonov 10231f0e290cSGuenter Roeckconfig PAGE_SIZE_LESS_THAN_64KB 10241f0e290cSGuenter Roeck def_bool y 10251f0e290cSGuenter Roeck depends on !ARM64_64K_PAGES 10261f0e290cSGuenter Roeck depends on !IA64_PAGE_SIZE_64KB 10271f0e290cSGuenter Roeck depends on !PAGE_SIZE_64KB 10281f0e290cSGuenter Roeck depends on !PARISC_PAGE_SIZE_64KB 1029e4bbd20dSNathan Chancellor depends on PAGE_SIZE_LESS_THAN_256KB 1030e4bbd20dSNathan Chancellor 1031e4bbd20dSNathan Chancellorconfig PAGE_SIZE_LESS_THAN_256KB 1032e4bbd20dSNathan Chancellor def_bool y 10331f0e290cSGuenter Roeck depends on !PAGE_SIZE_256KB 10341f0e290cSGuenter Roeck 103567f3977fSAlexandre Ghiti# This allows to use a set of generic functions to determine mmap base 103667f3977fSAlexandre Ghiti# address by giving priority to top-down scheme only if the process 103767f3977fSAlexandre Ghiti# is not in legacy mode (compat task, unlimited stack size or 103867f3977fSAlexandre Ghiti# sysctl_legacy_va_layout). 103967f3977fSAlexandre Ghiti# Architecture that selects this option can provide its own version of: 104067f3977fSAlexandre Ghiti# - STACK_RND_MASK 104167f3977fSAlexandre Ghiticonfig ARCH_WANT_DEFAULT_TOPDOWN_MMAP_LAYOUT 104267f3977fSAlexandre Ghiti bool 104367f3977fSAlexandre Ghiti depends on MMU 1044e7142bf5SAlexandre Ghiti select ARCH_HAS_ELF_RANDOMIZE 104567f3977fSAlexandre Ghiti 104603f16cd0SJosh Poimboeufconfig HAVE_OBJTOOL 104703f16cd0SJosh Poimboeuf bool 104803f16cd0SJosh Poimboeuf 10494ab7674fSJosh Poimboeufconfig HAVE_JUMP_LABEL_HACK 10504ab7674fSJosh Poimboeuf bool 10514ab7674fSJosh Poimboeuf 105222102f45SJosh Poimboeufconfig HAVE_NOINSTR_HACK 105322102f45SJosh Poimboeuf bool 105422102f45SJosh Poimboeuf 1055489e355bSJosh Poimboeufconfig HAVE_NOINSTR_VALIDATION 1056489e355bSJosh Poimboeuf bool 1057489e355bSJosh Poimboeuf 10585f3da8c0SJosh Poimboeufconfig HAVE_UACCESS_VALIDATION 10595f3da8c0SJosh Poimboeuf bool 10605f3da8c0SJosh Poimboeuf select OBJTOOL 10615f3da8c0SJosh Poimboeuf 1062b9ab5ebbSJosh Poimboeufconfig HAVE_STACK_VALIDATION 1063b9ab5ebbSJosh Poimboeuf bool 1064b9ab5ebbSJosh Poimboeuf help 106503f16cd0SJosh Poimboeuf Architecture supports objtool compile-time frame pointer rule 106603f16cd0SJosh Poimboeuf validation. 1067b9ab5ebbSJosh Poimboeuf 1068af085d90SJosh Poimboeufconfig HAVE_RELIABLE_STACKTRACE 1069af085d90SJosh Poimboeuf bool 1070af085d90SJosh Poimboeuf help 1071140d7e88SMiroslav Benes Architecture has either save_stack_trace_tsk_reliable() or 1072140d7e88SMiroslav Benes arch_stack_walk_reliable() function which only returns a stack trace 1073140d7e88SMiroslav Benes if it can guarantee the trace is reliable. 1074af085d90SJosh Poimboeuf 1075468a9428SGeorge Spelvinconfig HAVE_ARCH_HASH 1076468a9428SGeorge Spelvin bool 1077468a9428SGeorge Spelvin default n 1078468a9428SGeorge Spelvin help 1079468a9428SGeorge Spelvin If this is set, the architecture provides an <asm/hash.h> 1080468a9428SGeorge Spelvin file which provides platform-specific implementations of some 1081468a9428SGeorge Spelvin functions in <linux/hash.h> or fs/namei.c. 1082468a9428SGeorge Spelvin 1083666047feSFinn Thainconfig HAVE_ARCH_NVRAM_OPS 1084666047feSFinn Thain bool 1085666047feSFinn Thain 10863a495511SWilliam Breathitt Grayconfig ISA_BUS_API 10873a495511SWilliam Breathitt Gray def_bool ISA 10883a495511SWilliam Breathitt Gray 1089d2125043SAl Viro# 1090d2125043SAl Viro# ABI hall of shame 1091d2125043SAl Viro# 1092d2125043SAl Viroconfig CLONE_BACKWARDS 1093d2125043SAl Viro bool 1094d2125043SAl Viro help 1095d2125043SAl Viro Architecture has tls passed as the 4th argument of clone(2), 1096d2125043SAl Viro not the 5th one. 1097d2125043SAl Viro 1098d2125043SAl Viroconfig CLONE_BACKWARDS2 1099d2125043SAl Viro bool 1100d2125043SAl Viro help 1101d2125043SAl Viro Architecture has the first two arguments of clone(2) swapped. 1102d2125043SAl Viro 1103dfa9771aSMichal Simekconfig CLONE_BACKWARDS3 1104dfa9771aSMichal Simek bool 1105dfa9771aSMichal Simek help 1106dfa9771aSMichal Simek Architecture has tls passed as the 3rd argument of clone(2), 1107dfa9771aSMichal Simek not the 5th one. 1108dfa9771aSMichal Simek 1109eaca6eaeSAl Viroconfig ODD_RT_SIGACTION 1110eaca6eaeSAl Viro bool 1111eaca6eaeSAl Viro help 1112eaca6eaeSAl Viro Architecture has unusual rt_sigaction(2) arguments 1113eaca6eaeSAl Viro 11140a0e8cdfSAl Viroconfig OLD_SIGSUSPEND 11150a0e8cdfSAl Viro bool 11160a0e8cdfSAl Viro help 11170a0e8cdfSAl Viro Architecture has old sigsuspend(2) syscall, of one-argument variety 11180a0e8cdfSAl Viro 11190a0e8cdfSAl Viroconfig OLD_SIGSUSPEND3 11200a0e8cdfSAl Viro bool 11210a0e8cdfSAl Viro help 11220a0e8cdfSAl Viro Even weirder antique ABI - three-argument sigsuspend(2) 11230a0e8cdfSAl Viro 1124495dfbf7SAl Viroconfig OLD_SIGACTION 1125495dfbf7SAl Viro bool 1126495dfbf7SAl Viro help 1127495dfbf7SAl Viro Architecture has old sigaction(2) syscall. Nope, not the same 1128495dfbf7SAl Viro as OLD_SIGSUSPEND | OLD_SIGSUSPEND3 - alpha has sigsuspend(2), 1129495dfbf7SAl Viro but fairly different variant of sigaction(2), thanks to OSF/1 1130495dfbf7SAl Viro compatibility... 1131495dfbf7SAl Viro 1132495dfbf7SAl Viroconfig COMPAT_OLD_SIGACTION 1133495dfbf7SAl Viro bool 1134495dfbf7SAl Viro 113517435e5fSDeepa Dinamaniconfig COMPAT_32BIT_TIME 1136942437c9SArnd Bergmann bool "Provide system calls for 32-bit time_t" 1137942437c9SArnd Bergmann default !64BIT || COMPAT 113817435e5fSDeepa Dinamani help 113917435e5fSDeepa Dinamani This enables 32 bit time_t support in addition to 64 bit time_t support. 114017435e5fSDeepa Dinamani This is relevant on all 32-bit architectures, and 64-bit architectures 114117435e5fSDeepa Dinamani as part of compat syscall handling. 114217435e5fSDeepa Dinamani 114387a4c375SChristoph Hellwigconfig ARCH_NO_PREEMPT 114487a4c375SChristoph Hellwig bool 114587a4c375SChristoph Hellwig 1146cb2c7d1aSMickaël Salaünconfig ARCH_EPHEMERAL_INODES 1147cb2c7d1aSMickaël Salaün def_bool n 1148cb2c7d1aSMickaël Salaün help 1149cb2c7d1aSMickaël Salaün An arch should select this symbol if it doesn't keep track of inode 1150cb2c7d1aSMickaël Salaün instances on its own, but instead relies on something else (e.g. the 1151cb2c7d1aSMickaël Salaün host kernel for an UML kernel). 1152cb2c7d1aSMickaël Salaün 1153a50a3f4bSThomas Gleixnerconfig ARCH_SUPPORTS_RT 1154a50a3f4bSThomas Gleixner bool 1155a50a3f4bSThomas Gleixner 1156fff7fb0bSZhaoxiu Zengconfig CPU_NO_EFFICIENT_FFS 1157fff7fb0bSZhaoxiu Zeng def_bool n 1158fff7fb0bSZhaoxiu Zeng 1159ba14a194SAndy Lutomirskiconfig HAVE_ARCH_VMAP_STACK 1160ba14a194SAndy Lutomirski def_bool n 1161ba14a194SAndy Lutomirski help 1162ba14a194SAndy Lutomirski An arch should select this symbol if it can support kernel stacks 1163ba14a194SAndy Lutomirski in vmalloc space. This means: 1164ba14a194SAndy Lutomirski 1165ba14a194SAndy Lutomirski - vmalloc space must be large enough to hold many kernel stacks. 1166ba14a194SAndy Lutomirski This may rule out many 32-bit architectures. 1167ba14a194SAndy Lutomirski 1168ba14a194SAndy Lutomirski - Stacks in vmalloc space need to work reliably. For example, if 1169ba14a194SAndy Lutomirski vmap page tables are created on demand, either this mechanism 1170ba14a194SAndy Lutomirski needs to work while the stack points to a virtual address with 1171ba14a194SAndy Lutomirski unpopulated page tables or arch code (switch_to() and switch_mm(), 1172ba14a194SAndy Lutomirski most likely) needs to ensure that the stack's page table entries 1173ba14a194SAndy Lutomirski are populated before running on a possibly unpopulated stack. 1174ba14a194SAndy Lutomirski 1175ba14a194SAndy Lutomirski - If the stack overflows into a guard page, something reasonable 1176ba14a194SAndy Lutomirski should happen. The definition of "reasonable" is flexible, but 1177ba14a194SAndy Lutomirski instantly rebooting without logging anything would be unfriendly. 1178ba14a194SAndy Lutomirski 1179ba14a194SAndy Lutomirskiconfig VMAP_STACK 1180ba14a194SAndy Lutomirski default y 1181ba14a194SAndy Lutomirski bool "Use a virtually-mapped stack" 1182eafb149eSDaniel Axtens depends on HAVE_ARCH_VMAP_STACK 118338dd767dSAndrey Konovalov depends on !KASAN || KASAN_HW_TAGS || KASAN_VMALLOC 1184a7f7f624SMasahiro Yamada help 1185ba14a194SAndy Lutomirski Enable this if you want the use virtually-mapped kernel stacks 1186ba14a194SAndy Lutomirski with guard pages. This causes kernel stack overflows to be 1187ba14a194SAndy Lutomirski caught immediately rather than causing difficult-to-diagnose 1188ba14a194SAndy Lutomirski corruption. 1189ba14a194SAndy Lutomirski 119038dd767dSAndrey Konovalov To use this with software KASAN modes, the architecture must support 119138dd767dSAndrey Konovalov backing virtual mappings with real shadow memory, and KASAN_VMALLOC 119238dd767dSAndrey Konovalov must be enabled. 1193ba14a194SAndy Lutomirski 119439218ff4SKees Cookconfig HAVE_ARCH_RANDOMIZE_KSTACK_OFFSET 119539218ff4SKees Cook def_bool n 119639218ff4SKees Cook help 119739218ff4SKees Cook An arch should select this symbol if it can support kernel stack 119839218ff4SKees Cook offset randomization with calls to add_random_kstack_offset() 119939218ff4SKees Cook during syscall entry and choose_random_kstack_offset() during 120039218ff4SKees Cook syscall exit. Careful removal of -fstack-protector-strong and 120139218ff4SKees Cook -fstack-protector should also be applied to the entry code and 120239218ff4SKees Cook closely examined, as the artificial stack bump looks like an array 120339218ff4SKees Cook to the compiler, so it will attempt to add canary checks regardless 120439218ff4SKees Cook of the static branch state. 120539218ff4SKees Cook 12068cb37a59SMarco Elverconfig RANDOMIZE_KSTACK_OFFSET 12078cb37a59SMarco Elver bool "Support for randomizing kernel stack offset on syscall entry" if EXPERT 12088cb37a59SMarco Elver default y 120939218ff4SKees Cook depends on HAVE_ARCH_RANDOMIZE_KSTACK_OFFSET 1210efa90c11SMarco Elver depends on INIT_STACK_NONE || !CC_IS_CLANG || CLANG_VERSION >= 140000 121139218ff4SKees Cook help 121239218ff4SKees Cook The kernel stack offset can be randomized (after pt_regs) by 121339218ff4SKees Cook roughly 5 bits of entropy, frustrating memory corruption 121439218ff4SKees Cook attacks that depend on stack address determinism or 12158cb37a59SMarco Elver cross-syscall address exposures. 12168cb37a59SMarco Elver 12178cb37a59SMarco Elver The feature is controlled via the "randomize_kstack_offset=on/off" 12188cb37a59SMarco Elver kernel boot param, and if turned off has zero overhead due to its use 12198cb37a59SMarco Elver of static branches (see JUMP_LABEL). 12208cb37a59SMarco Elver 12218cb37a59SMarco Elver If unsure, say Y. 12228cb37a59SMarco Elver 12238cb37a59SMarco Elverconfig RANDOMIZE_KSTACK_OFFSET_DEFAULT 12248cb37a59SMarco Elver bool "Default state of kernel stack offset randomization" 12258cb37a59SMarco Elver depends on RANDOMIZE_KSTACK_OFFSET 12268cb37a59SMarco Elver help 12278cb37a59SMarco Elver Kernel stack offset randomization is controlled by kernel boot param 12288cb37a59SMarco Elver "randomize_kstack_offset=on/off", and this config chooses the default 12298cb37a59SMarco Elver boot state. 123039218ff4SKees Cook 1231ad21fc4fSLaura Abbottconfig ARCH_OPTIONAL_KERNEL_RWX 1232ad21fc4fSLaura Abbott def_bool n 1233ad21fc4fSLaura Abbott 1234ad21fc4fSLaura Abbottconfig ARCH_OPTIONAL_KERNEL_RWX_DEFAULT 1235ad21fc4fSLaura Abbott def_bool n 1236ad21fc4fSLaura Abbott 1237ad21fc4fSLaura Abbottconfig ARCH_HAS_STRICT_KERNEL_RWX 1238ad21fc4fSLaura Abbott def_bool n 1239ad21fc4fSLaura Abbott 12400f5bf6d0SLaura Abbottconfig STRICT_KERNEL_RWX 1241ad21fc4fSLaura Abbott bool "Make kernel text and rodata read-only" if ARCH_OPTIONAL_KERNEL_RWX 1242ad21fc4fSLaura Abbott depends on ARCH_HAS_STRICT_KERNEL_RWX 1243ad21fc4fSLaura Abbott default !ARCH_OPTIONAL_KERNEL_RWX || ARCH_OPTIONAL_KERNEL_RWX_DEFAULT 1244ad21fc4fSLaura Abbott help 1245ad21fc4fSLaura Abbott If this is set, kernel text and rodata memory will be made read-only, 1246ad21fc4fSLaura Abbott and non-text memory will be made non-executable. This provides 1247ad21fc4fSLaura Abbott protection against certain security exploits (e.g. executing the heap 1248ad21fc4fSLaura Abbott or modifying text) 1249ad21fc4fSLaura Abbott 1250ad21fc4fSLaura Abbott These features are considered standard security practice these days. 1251ad21fc4fSLaura Abbott You should say Y here in almost all cases. 1252ad21fc4fSLaura Abbott 1253ad21fc4fSLaura Abbottconfig ARCH_HAS_STRICT_MODULE_RWX 1254ad21fc4fSLaura Abbott def_bool n 1255ad21fc4fSLaura Abbott 12560f5bf6d0SLaura Abbottconfig STRICT_MODULE_RWX 1257ad21fc4fSLaura Abbott bool "Set loadable kernel module data as NX and text as RO" if ARCH_OPTIONAL_KERNEL_RWX 1258ad21fc4fSLaura Abbott depends on ARCH_HAS_STRICT_MODULE_RWX && MODULES 1259ad21fc4fSLaura Abbott default !ARCH_OPTIONAL_KERNEL_RWX || ARCH_OPTIONAL_KERNEL_RWX_DEFAULT 1260ad21fc4fSLaura Abbott help 1261ad21fc4fSLaura Abbott If this is set, module text and rodata memory will be made read-only, 1262ad21fc4fSLaura Abbott and non-text memory will be made non-executable. This provides 1263ad21fc4fSLaura Abbott protection against certain security exploits (e.g. writing to text) 1264ad21fc4fSLaura Abbott 1265ea8c64acSChristoph Hellwig# select if the architecture provides an asm/dma-direct.h header 1266ea8c64acSChristoph Hellwigconfig ARCH_HAS_PHYS_TO_DMA 1267ea8c64acSChristoph Hellwig bool 1268ea8c64acSChristoph Hellwig 126904f264d3SPaul Burtonconfig HAVE_ARCH_COMPILER_H 127004f264d3SPaul Burton bool 127104f264d3SPaul Burton help 127204f264d3SPaul Burton An architecture can select this if it provides an 127304f264d3SPaul Burton asm/compiler.h header that should be included after 127404f264d3SPaul Burton linux/compiler-*.h in order to override macro definitions that those 127504f264d3SPaul Burton headers generally provide. 127604f264d3SPaul Burton 1277271ca788SArd Biesheuvelconfig HAVE_ARCH_PREL32_RELOCATIONS 1278271ca788SArd Biesheuvel bool 1279271ca788SArd Biesheuvel help 1280271ca788SArd Biesheuvel May be selected by an architecture if it supports place-relative 1281271ca788SArd Biesheuvel 32-bit relocations, both in the toolchain and in the module loader, 1282271ca788SArd Biesheuvel in which case relative references can be used in special sections 1283271ca788SArd Biesheuvel for PCI fixup, initcalls etc which are only half the size on 64 bit 1284271ca788SArd Biesheuvel architectures, and don't require runtime relocation on relocatable 1285271ca788SArd Biesheuvel kernels. 1286271ca788SArd Biesheuvel 1287ce9084baSArd Biesheuvelconfig ARCH_USE_MEMREMAP_PROT 1288ce9084baSArd Biesheuvel bool 1289ce9084baSArd Biesheuvel 1290fb346fd9SWaiman Longconfig LOCK_EVENT_COUNTS 1291fb346fd9SWaiman Long bool "Locking event counts collection" 1292fb346fd9SWaiman Long depends on DEBUG_FS 1293a7f7f624SMasahiro Yamada help 1294fb346fd9SWaiman Long Enable light-weight counting of various locking related events 1295fb346fd9SWaiman Long in the system with minimal performance impact. This reduces 1296fb346fd9SWaiman Long the chance of application behavior change because of timing 1297fb346fd9SWaiman Long differences. The counts are reported via debugfs. 1298fb346fd9SWaiman Long 12995cf896fbSPeter Collingbourne# Select if the architecture has support for applying RELR relocations. 13005cf896fbSPeter Collingbourneconfig ARCH_HAS_RELR 13015cf896fbSPeter Collingbourne bool 13025cf896fbSPeter Collingbourne 13035cf896fbSPeter Collingbourneconfig RELR 13045cf896fbSPeter Collingbourne bool "Use RELR relocation packing" 13055cf896fbSPeter Collingbourne depends on ARCH_HAS_RELR && TOOLS_SUPPORT_RELR 13065cf896fbSPeter Collingbourne default y 13075cf896fbSPeter Collingbourne help 13085cf896fbSPeter Collingbourne Store the kernel's dynamic relocations in the RELR relocation packing 13095cf896fbSPeter Collingbourne format. Requires a compatible linker (LLD supports this feature), as 13105cf896fbSPeter Collingbourne well as compatible NM and OBJCOPY utilities (llvm-nm and llvm-objcopy 13115cf896fbSPeter Collingbourne are compatible). 13125cf896fbSPeter Collingbourne 13130c9c1d56SThiago Jung Bauermannconfig ARCH_HAS_MEM_ENCRYPT 13140c9c1d56SThiago Jung Bauermann bool 13150c9c1d56SThiago Jung Bauermann 131646b49b12STom Lendackyconfig ARCH_HAS_CC_PLATFORM 131746b49b12STom Lendacky bool 131846b49b12STom Lendacky 13190e242208SHassan Naveedconfig HAVE_SPARSE_SYSCALL_NR 13200e242208SHassan Naveed bool 13210e242208SHassan Naveed help 13220e242208SHassan Naveed An architecture should select this if its syscall numbering is sparse 13230e242208SHassan Naveed to save space. For example, MIPS architecture has a syscall array with 13240e242208SHassan Naveed entries at 4000, 5000 and 6000 locations. This option turns on syscall 13250e242208SHassan Naveed related optimizations for a given architecture. 13260e242208SHassan Naveed 1327d60d7de3SSven Schnelleconfig ARCH_HAS_VDSO_DATA 1328d60d7de3SSven Schnelle bool 1329d60d7de3SSven Schnelle 1330115284d8SJosh Poimboeufconfig HAVE_STATIC_CALL 1331115284d8SJosh Poimboeuf bool 1332115284d8SJosh Poimboeuf 13339183c3f9SJosh Poimboeufconfig HAVE_STATIC_CALL_INLINE 13349183c3f9SJosh Poimboeuf bool 13359183c3f9SJosh Poimboeuf depends on HAVE_STATIC_CALL 133603f16cd0SJosh Poimboeuf select OBJTOOL 13379183c3f9SJosh Poimboeuf 13386ef869e0SMichal Hockoconfig HAVE_PREEMPT_DYNAMIC 13396ef869e0SMichal Hocko bool 134099cf983cSMark Rutland 134199cf983cSMark Rutlandconfig HAVE_PREEMPT_DYNAMIC_CALL 134299cf983cSMark Rutland bool 13436ef869e0SMichal Hocko depends on HAVE_STATIC_CALL 134499cf983cSMark Rutland select HAVE_PREEMPT_DYNAMIC 13456ef869e0SMichal Hocko help 134699cf983cSMark Rutland An architecture should select this if it can handle the preemption 134799cf983cSMark Rutland model being selected at boot time using static calls. 134899cf983cSMark Rutland 134999cf983cSMark Rutland Where an architecture selects HAVE_STATIC_CALL_INLINE, any call to a 135099cf983cSMark Rutland preemption function will be patched directly. 135199cf983cSMark Rutland 135299cf983cSMark Rutland Where an architecture does not select HAVE_STATIC_CALL_INLINE, any 135399cf983cSMark Rutland call to a preemption function will go through a trampoline, and the 135499cf983cSMark Rutland trampoline will be patched. 135599cf983cSMark Rutland 135699cf983cSMark Rutland It is strongly advised to support inline static call to avoid any 135799cf983cSMark Rutland overhead. 135899cf983cSMark Rutland 135999cf983cSMark Rutlandconfig HAVE_PREEMPT_DYNAMIC_KEY 136099cf983cSMark Rutland bool 136199cf983cSMark Rutland depends on HAVE_ARCH_JUMP_LABEL && CC_HAS_ASM_GOTO 136299cf983cSMark Rutland select HAVE_PREEMPT_DYNAMIC 136399cf983cSMark Rutland help 136499cf983cSMark Rutland An architecture should select this if it can handle the preemption 136599cf983cSMark Rutland model being selected at boot time using static keys. 136699cf983cSMark Rutland 136799cf983cSMark Rutland Each preemption function will be given an early return based on a 136899cf983cSMark Rutland static key. This should have slightly lower overhead than non-inline 136999cf983cSMark Rutland static calls, as this effectively inlines each trampoline into the 137099cf983cSMark Rutland start of its callee. This may avoid redundant work, and may 137199cf983cSMark Rutland integrate better with CFI schemes. 137299cf983cSMark Rutland 137399cf983cSMark Rutland This will have greater overhead than using inline static calls as 137499cf983cSMark Rutland the call to the preemption function cannot be entirely elided. 13756ef869e0SMichal Hocko 137659612b24SNathan Chancellorconfig ARCH_WANT_LD_ORPHAN_WARN 137759612b24SNathan Chancellor bool 137859612b24SNathan Chancellor help 137959612b24SNathan Chancellor An arch should select this symbol once all linker sections are explicitly 138059612b24SNathan Chancellor included, size-asserted, or discarded in the linker scripts. This is 138159612b24SNathan Chancellor important because we never want expected sections to be placed heuristically 138259612b24SNathan Chancellor by the linker, since the locations of such sections can change between linker 138359612b24SNathan Chancellor versions. 138459612b24SNathan Chancellor 13854f5b0c17SMike Rapoportconfig HAVE_ARCH_PFN_VALID 13864f5b0c17SMike Rapoport bool 13874f5b0c17SMike Rapoport 13885d6ad668SMike Rapoportconfig ARCH_SUPPORTS_DEBUG_PAGEALLOC 13895d6ad668SMike Rapoport bool 13905d6ad668SMike Rapoport 1391df4e817bSPasha Tatashinconfig ARCH_SUPPORTS_PAGE_TABLE_CHECK 1392df4e817bSPasha Tatashin bool 1393df4e817bSPasha Tatashin 13942ca408d9SBrian Gerstconfig ARCH_SPLIT_ARG64 13952ca408d9SBrian Gerst bool 13962ca408d9SBrian Gerst help 13972ca408d9SBrian Gerst If a 32-bit architecture requires 64-bit arguments to be split into 13982ca408d9SBrian Gerst pairs of 32-bit arguments, select this option. 13992ca408d9SBrian Gerst 14007facdc42SAl Viroconfig ARCH_HAS_ELFCORE_COMPAT 14017facdc42SAl Viro bool 14027facdc42SAl Viro 140358e106e7SBalbir Singhconfig ARCH_HAS_PARANOID_L1D_FLUSH 140458e106e7SBalbir Singh bool 140558e106e7SBalbir Singh 14061bdda24cSThomas Gleixnerconfig DYNAMIC_SIGFRAME 14071bdda24cSThomas Gleixner bool 14081bdda24cSThomas Gleixner 140950468e43SJarkko Sakkinen# Select, if arch has a named attribute group bound to NUMA device nodes. 141050468e43SJarkko Sakkinenconfig HAVE_ARCH_NODE_DEV_GROUP 141150468e43SJarkko Sakkinen bool 141250468e43SJarkko Sakkinen 14132521f2c2SPeter Oberparleitersource "kernel/gcov/Kconfig" 141445332b1bSMasahiro Yamada 141545332b1bSMasahiro Yamadasource "scripts/gcc-plugins/Kconfig" 1416fa1b5d09SLinus Torvalds 141722471e13SRandy Dunlapendmenu 1418