x86/kaiser: Reenable PARAVIRT
authorBorislav Petkov <bp@suse.de>
Tue, 2 Jan 2018 13:19:49 +0000 (14:19 +0100)
committerYves-Alexis Perez <corsac@debian.org>
Thu, 4 Jan 2018 11:12:40 +0000 (11:12 +0000)
Now that the required bits have been addressed, reenable
PARAVIRT.

Signed-off-by: Borislav Petkov <bp@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Gbp-Pq: Topic features/all/kpti
Gbp-Pq: Name x86-kaiser-reenable-paravirt.patch

security/Kconfig

index 93b4e24f142de9021db038c24c82d25cbc9fda6b..e9526e757647f5c19a0cbddbbd814ccc5f7b2930 100644 (file)
@@ -43,7 +43,7 @@ config SECURITY
 config KAISER
        bool "Remove the kernel mapping in user mode"
        default y
-       depends on X86_64 && SMP && !PARAVIRT
+       depends on X86_64 && SMP
        help
          This enforces a strict kernel and user space isolation, in order
          to close hardware side channels on kernel address information.