From: Borislav Petkov Date: Tue, 2 Jan 2018 13:19:49 +0000 (+0100) Subject: x86/kaiser: Reenable PARAVIRT X-Git-Tag: v3.2.98~5 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=bd99918270ac4c710ef2aede774a5647ad7e50e8;p=thirdparty%2Fkernel%2Fstable.git x86/kaiser: Reenable PARAVIRT Now that the required bits have been addressed, reenable PARAVIRT. Signed-off-by: Borislav Petkov Signed-off-by: Greg Kroah-Hartman Signed-off-by: Ben Hutchings --- diff --git a/security/Kconfig b/security/Kconfig index 19f83193e7ab8..4b05ddcce22cc 100644 --- a/security/Kconfig +++ b/security/Kconfig @@ -99,7 +99,7 @@ config SECURITY config KAISER bool "Remove the kernel mapping in user mode" default y - depends on X86_64 && SMP && !PARAVIRT + depends on X86_64 && SMP help This enforces a strict kernel and user space isolation, in order to close hardware side channels on kernel address information.