x86: Lock down IO port access when securelevel is enabled
authorMatthew Garrett <mjg59@srcf.ucam.org>
Thu, 8 Mar 2012 15:35:59 +0000 (10:35 -0500)
committerBen Hutchings <ben@decadent.org.uk>
Mon, 27 Feb 2017 15:58:07 +0000 (15:58 +0000)
commit631fc14b935fda5a4ef3d2be33417b1adb7ed160
treec99f32a6dc74d0320c04aac4ec44203f64e1f0f6
parentb2fa4635ef4cc2b27c15a032f9327baef1148cf9
x86: Lock down IO port access when securelevel is enabled

IO port access would permit users to gain access to PCI configuration
registers, which in turn (on a lot of hardware) give access to MMIO register
space. This would potentially permit root to trigger arbitrary DMA, so lock
it down when securelevel is set.

Signed-off-by: Matthew Garrett <mjg59@srcf.ucam.org>
Gbp-Pq: Topic features/all/securelevel
Gbp-Pq: Name x86-lock-down-io-port-access-when-securelevel-is-ena.patch
arch/x86/kernel/ioport.c
drivers/char/mem.c