Commit Graph

795 Commits

Author SHA1 Message Date
Jan Alexander Steffens 32666e1c86 5.5.2.arch1-1 2020-02-04 19:44:58 +00:00
Jan Alexander Steffens 0895ab7437 5.5.1.arch2-1 2020-02-04 18:04:41 +00:00
Jan Alexander Steffens 90b69f3da5 Disable INTEL_IOMMU_DEFAULT_ON
Intel IOMMU support is still in a shitty state. What a shame.
2020-02-04 18:04:39 +00:00
Jan Alexander Steffens 5c532afbaa 5.5.1.arch1-1: Enable INTEL_IOMMU_DEFAULT_ON
IOMMU is important for security in systems using PCI bridges (e.g.
Thunderbolt, USB4) or other means of DMA from potentially untrusted
devices (e.g. FireWire). It's also used to safely pass devices into VMs.

Enable it by default. It can still be disabled at boot using
intel_iommu=off. intel_iommu=igfx_off is also available to exclude just
the iGPU.
2020-02-01 17:53:24 +00:00
Jan Alexander Steffens 727d1e1d47 5.5.arch1-1 2020-01-27 22:28:27 +00:00
Jan Alexander Steffens 9b0026f12a 5.4.15.arch1-1 2020-01-26 10:12:29 +00:00
Jan Alexander Steffens 76b830c740 5.4.14.arch1-1 2020-01-23 10:46:25 +00:00
Jan Alexander Steffens 2231922647 5.4.13.arch1-1 2020-01-17 23:41:56 +00:00
Jan Alexander Steffens 91d5b604de FS#62384: Enable BPF_KPROBE_OVERRIDE
https://bugs.archlinux.org/task/62384
2020-01-17 23:41:55 +00:00
Jan Alexander Steffens d106759d8b 5.4.12.arch1-1 2020-01-15 06:53:23 +00:00
Jan Alexander Steffens 7eba9021b0 5.4.11.arch1-1 2020-01-12 12:53:49 +00:00
Jan Alexander Steffens 82ffbb90fb 5.4.10.arch1-1 2020-01-09 14:24:15 +00:00
Jan Alexander Steffens c1d93c3940 5.4.8.arch1-1 2020-01-05 00:15:40 +00:00
Jan Alexander Steffens 5ac0903843 5.4.7.arch1-1 2019-12-31 17:50:17 +00:00
Jan Alexander Steffens 2e75b6eae8 5.4.6.arch3-1 2019-12-24 05:19:44 +00:00
Jan Alexander Steffens 81acb691ce 5.4.6.arch2-1 2019-12-24 03:05:40 +00:00
Jan Alexander Steffens 03f2d38060 5.4.6.arch1-1 2019-12-21 17:06:17 +00:00
Jan Alexander Steffens 8da6888066 5.4.5.arch1-1 2019-12-18 20:10:23 +00:00
Jan Alexander Steffens 82824d9db4 5.4.4.arch1-1 2019-12-18 00:18:38 +00:00
Jan Alexander Steffens 2b1504741e 5.4.3.arch1-1 2019-12-13 11:34:26 +00:00
Jan Alexander Steffens f3603dadd9 Disable SND_HDA_INTEL_DETECT_DMIC
It's not ready; the drivers that are supposed to step in when
snd-hda-intel aborts probing aren't working yet. v5.5 will have a better
solution for driver selection, anyway.
2019-12-13 11:34:25 +00:00
Jan Alexander Steffens 72e584c261 5.4.2.arch1-1 2019-12-05 14:44:50 +00:00
Jan Alexander Steffens 3ead601c9d 5.4.1.arch1-1 2019-11-29 14:56:15 +00:00
Jan Alexander Steffens 196a2934c5 Disable RMI4_F54
Doesn't crash now, but still pretty useless.
  - V4L device still confuses applications.
  - Reading a sensor image makes the touchpad unusable as an input
    device until it is power-cycled.
2019-11-27 20:28:02 +00:00
Jan Alexander Steffens 97381f5f19 Enable SND_HDA_INTEL_DETECT_DMIC
Now that we have SOF, let it handle systems with DMICs.
2019-11-27 20:28:01 +00:00
Jan Alexander Steffens 426a33d8ae FS#63464: Disable misbehaving SOF drivers
Reading the changes made at
https://github.com/thesofproject/linux/pull/1382/files
2019-11-27 20:27:58 +00:00
Jan Alexander Steffens d27c858681 5.4.arch1-1 2019-11-25 23:56:20 +00:00
Jan Alexander Steffens 59bfce8dfb 5.3.13.1-1 2019-11-24 10:48:33 +00:00
Jan Alexander Steffens 55cc8e46b2 5.3.12.1-1 2019-11-20 20:29:19 +00:00
Jan Alexander Steffens c189ce4263 Enable INIT_ON_ALLOC_DEFAULT_ON
https://outflux.net/blog/archives/2019/11/14/security-things-in-linux-v5-3/
2019-11-18 21:33:26 +00:00
Jan Alexander Steffens cad3b7156f 5.3.11.1-1 2019-11-12 23:21:40 +00:00
Jan Alexander Steffens 069aef7db3 5.3.10.1-1 2019-11-10 12:15:37 +00:00
Jan Alexander Steffens f5bf538e52 5.3.9.1-1 2019-11-06 14:16:18 +00:00
Jan Alexander Steffens f15e18814a Remove all dotfiles from the docs 2019-11-06 12:30:48 +00:00
Jan Alexander Steffens 50486f6ac1 Update pkgdesc 2019-11-06 12:30:47 +00:00
Jan Alexander Steffens 51fb75705c Rename _srcver to _srctag and move the 'v' into it 2019-11-06 12:30:46 +00:00
Jan Alexander Steffens 0a1031132c Use a more readable timestamp 2019-11-05 19:39:30 +00:00
Jan Alexander Steffens 44420b8b15 Disable full dynticks 2019-11-03 14:24:59 +00:00
Jan Alexander Steffens aa190d3c60 Disable some stray Freescale audio modules 2019-11-03 14:24:58 +00:00
Jan Alexander Steffens 35f8455e06 FS#64302: Disable Google SMI
Crashes on various non-Google Chromebooks and Coreboot-using laptops
like Librem and reflashed ThinkPads.
2019-11-03 10:45:25 +00:00
Jan Alexander Steffens a53987ae76 FS#63464: Disable Sound Open Firmware
We don't ship any firmware files (yet) and the drivers can be loaded
in preference to the SST drivers, which we do have firmware for.
2019-11-02 08:23:45 +00:00
Jan Alexander Steffens b204fb2896 Disable CONFIG_RMI4_F54
The V4L touch device created is buggy, causing userspace applications
(PipeWire) to behave badly and even kernel panics when running

    v4l2-compliance -t 0 -s 1
2019-10-31 15:11:37 +00:00
Jan Alexander Steffens 88cc595d11 5.3.8.1-1: Changes for new kmod and mkinitcpio hooks 2019-10-29 15:13:05 +00:00
Jan Alexander Steffens dcfb5e03cb 5.3.7.arch1-2: gcc rebuild 2019-10-25 13:34:47 +00:00
Jan Alexander Steffens 3f306c2e10 FS#55784 enable google modules 2019-10-19 14:01:12 +00:00
Jan Alexander Steffens 7f6d8f62e6 5.3.7.arch1-1 2019-10-18 00:42:21 +00:00
Jan Alexander Steffens 63f3e95b8a 5.3.6.arch1-1: removal of extramodules-ARCH 2019-10-11 19:17:40 +00:00
Jan Alexander Steffens 3e302bf52a 5.3.5.arch1-1 2019-10-07 19:29:12 +00:00
Jan Alexander Steffens abfd9fa0c4 .tmp_versions (aka MODVERDIR) was dropped in 5.3 2019-10-07 19:29:12 +00:00
Jan Alexander Steffens 5944df9027 Drop base group 2019-10-07 19:29:07 +00:00
Jan Alexander Steffens fa64c7292f 5.3.4.arch1-1 2019-10-05 14:05:45 +00:00
Jan Alexander Steffens 964e000a29 5.3.2.arch2-1 2019-10-04 00:16:59 +00:00
Jan Alexander Steffens be16067dd6 Enable SUNRPC_DISABLE_INSECURE_ENCTYPES 2019-10-03 14:51:04 +00:00
Jan Alexander Steffens 1d31b2e9a7 5.3.2.arch1-1 2019-10-01 08:15:52 +00:00
Jan Alexander Steffens 459ca63ba1 5.3.1.arch1-1 2019-09-21 11:55:15 +00:00
Jan Alexander Steffens bd82bdc99a 5.3.arch1-1 2019-09-16 04:19:09 +00:00
Jan Alexander Steffens e5427c3766 5.2.14.arch2-1 2019-09-12 11:30:14 +00:00
Jan Alexander Steffens fb70c8b707 5.2.14.arch1-1 2019-09-10 18:35:42 +00:00
Jan Alexander Steffens 7e1a83f951 5.2.13.arch1-1 2019-09-06 22:49:04 +00:00
Jan Alexander Steffens 90bb282f44 5.2.11.arch1-1 2019-08-29 08:36:50 +00:00
Jan Alexander Steffens 92f97e2c06 5.2.10.arch1-1 2019-08-25 18:27:22 +00:00
Jan Alexander Steffens 8e4727a949 5.2.9.arch1-1 2019-08-16 11:52:16 +00:00
Jan Alexander Steffens 985d9718d5 5.2.8.arch1-1 2019-08-09 21:57:03 +00:00
Jan Alexander Steffens beb43151ff 5.2.7.arch1-1 2019-08-07 06:10:19 +00:00
Jan Alexander Steffens 87901caa08 5.2.6.arch1-1 2019-08-04 15:19:22 +00:00
Jan Alexander Steffens ec7e9200bb 5.2.5.arch1-1 2019-07-31 09:05:53 +00:00
Jan Alexander Steffens c75fb07643 FS#62432: Disable FW_LOADER_USER_HELPER 2019-07-30 21:04:09 +00:00
Jan Alexander Steffens 5506b0f0ba 5.2.4.arch1-1 2019-07-28 11:14:09 +00:00
Jan Alexander Steffens 11b0a33e9c 5.2.3.arch1-1 2019-07-26 08:35:18 +00:00
Jan Alexander Steffens 439e5a0af4 5.2.2.arch1-1: Disable stackleak; shows up in perf as 6-7% overhead 2019-07-21 19:43:40 +00:00
Jan Alexander Steffens 53d0c2511a 5.2.1.arch1-1 2019-07-14 21:46:06 +00:00
Jan Alexander Steffens e77150c276 Enable stackleak 2019-07-10 15:18:09 +00:00
Jan Alexander Steffens 0471ab33d5 5.2.arch2-1 2019-07-09 04:10:19 +00:00
Jan Alexander Steffens 900b5ef2ae 5.1.16.arch1-1 2019-07-03 21:10:13 +00:00
Jan Alexander Steffens 9807c7310f 5.1.15.arch1-1 2019-06-25 07:26:32 +00:00
Jan Alexander Steffens c8269e7394 Update config 2019-06-24 07:28:51 +00:00
Jan Alexander Steffens 772e4b80ca 5.1.14.arch1-1 2019-06-22 18:59:48 +00:00
Jan Alexander Steffens eb811dba04 5.1.12.arch1-1 2019-06-19 11:26:25 +00:00
Jan Alexander Steffens ba5f8f7c09 5.1.11.arch1-1 2019-06-18 04:05:28 +00:00
Jan Alexander Steffens c37deb1824 5.1.10.arch1-1 2019-06-15 23:58:02 +00:00
Jan Alexander Steffens 31e769d81c 5.1.9.arch1-1 2019-06-11 19:51:35 +00:00
Jan Alexander Steffens 6621446c2d 5.1.8.arch1-1 2019-06-09 21:32:47 +00:00
Jan Alexander Steffens 1e4f39a1bf 5.1.7.arch1-1 2019-06-04 16:51:55 +00:00
Jan Alexander Steffens e4b9cbe32c 5.1.6.arch1-1 2019-06-01 03:09:20 +00:00
Jan Alexander Steffens 8b38521a3a 5.1.5.arch1-2 2019-05-27 04:36:29 +00:00
Jan Alexander Steffens 4374e1a82c 5.1.5.arch1-1 2019-05-25 21:24:16 +00:00
Jan Alexander Steffens 36a6aa8c9b 5.1.4.arch1-1 2019-05-22 12:05:50 +00:00
Jan Alexander Steffens cafb13e936 5.1.3.arch2-1 2019-05-22 00:18:32 +00:00
Jan Alexander Steffens 7346697334 5.1.3.arch1-1 2019-05-17 07:09:24 +00:00
Jan Alexander Steffens e290a19e5c 5.1.2.arch1-1 2019-05-15 06:33:53 +00:00
Jan Alexander Steffens be8523fe94 5.1.1.arch1-1 2019-05-11 14:01:14 +00:00
Jan Alexander Steffens 10505f2f9b Disable integrity, enable safesetid, only load yama by default 2019-05-07 20:04:22 +00:00
Jan Alexander Steffens 78a111327b 5.1.arch1-1 2019-05-06 23:33:26 +00:00
Jan Alexander Steffens f77c905fa7 5.0.13.arch1-1 2019-05-05 19:10:38 +00:00
Jan Alexander Steffens fbbcaeb99e 5.0.12.arch2-1 2019-05-04 22:19:57 +00:00
Jan Alexander Steffens 3bda620d1d 5.0.12.arch1-1 2019-05-04 12:58:17 +00:00
Jan Alexander Steffens da62aa3423 5.0.11.arch1-1 2019-05-02 22:02:04 +00:00
Jan Alexander Steffens f84d330b5f 5.0.10.arch1-1 2019-04-27 22:09:22 +00:00
Jan Alexander Steffens 3834b7ae37 5.0.9.arch1-1 2019-04-20 15:57:11 +00:00
Jan Alexander Steffens aabc2350df 5.0.8.arch1-1 2019-04-17 20:21:15 +00:00