[09/21] linux: Wipe all memory when rebooting on EFI

Message ID d3b90853-25aa-4c49-b9fd-c52f251db4d6@ipfire.org
State Accepted
Commit 7a390182197285d03b3672ce450b3715016c36cc
Headers
Series linux: Update to 5.15.85 and backport many IPFire 3.x changes |

Commit Message

Peter Müller Dec. 26, 2022, 7:27 p.m. UTC
  Backported from IPFire 3.x as 49242a5661a550b370fff56f893df0983700ef32.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
---
 config/kernel/kernel.config.x86_64-ipfire | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
  

Comments

Michael Tremer Dec. 27, 2022, 11:23 a.m. UTC | #1
Acked-by: Michael Tremer <michael.tremer@ipfire.org>

> On 26 Dec 2022, at 20:27, Peter Müller <peter.mueller@ipfire.org> wrote:
> 
> Backported from IPFire 3.x as 49242a5661a550b370fff56f893df0983700ef32.
> 
> Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
> ---
> config/kernel/kernel.config.x86_64-ipfire | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/config/kernel/kernel.config.x86_64-ipfire b/config/kernel/kernel.config.x86_64-ipfire
> index 519fc8770..39ca3af30 100644
> --- a/config/kernel/kernel.config.x86_64-ipfire
> +++ b/config/kernel/kernel.config.x86_64-ipfire
> @@ -1882,7 +1882,7 @@ CONFIG_EFI_GENERIC_STUB_INITRD_CMDLINE_LOADER=y
> # CONFIG_EFI_CAPSULE_LOADER is not set
> # CONFIG_EFI_TEST is not set
> # CONFIG_APPLE_PROPERTIES is not set
> -# CONFIG_RESET_ATTACK_MITIGATION is not set
> +CONFIG_RESET_ATTACK_MITIGATION=y
> # CONFIG_EFI_RCI2_TABLE is not set
> CONFIG_EFI_DISABLE_PCI_DMA=y
> # end of EFI (Extensible Firmware Interface) Support
> -- 
> 2.35.3
  

Patch

diff --git a/config/kernel/kernel.config.x86_64-ipfire b/config/kernel/kernel.config.x86_64-ipfire
index 519fc8770..39ca3af30 100644
--- a/config/kernel/kernel.config.x86_64-ipfire
+++ b/config/kernel/kernel.config.x86_64-ipfire
@@ -1882,7 +1882,7 @@  CONFIG_EFI_GENERIC_STUB_INITRD_CMDLINE_LOADER=y
 # CONFIG_EFI_CAPSULE_LOADER is not set
 # CONFIG_EFI_TEST is not set
 # CONFIG_APPLE_PROPERTIES is not set
-# CONFIG_RESET_ATTACK_MITIGATION is not set
+CONFIG_RESET_ATTACK_MITIGATION=y
 # CONFIG_EFI_RCI2_TABLE is not set
 CONFIG_EFI_DISABLE_PCI_DMA=y
 # end of EFI (Extensible Firmware Interface) Support