소스 검색

Blacklisted Firewire SBP-2 module to prevent RAM dumping via IEEE-1394

Maxim Kammerer 12 년 전
부모
커밋
0cfbc2f330
3개의 변경된 파일5개의 추가작업 그리고 4개의 파일을 삭제
  1. 1 0
      doc/changelog.txt
  2. 2 2
      src/root/config/grub.cfg
  3. 2 2
      src/root/config/syslinux.cfg

+ 1 - 0
doc/changelog.txt

@@ -3,6 +3,7 @@
 
   * Better support for QEMU mouse virtualization
   * Xorg server 1.13
+  * Firewire SBP-2 module is blacklisted to prevent Firewire RAM access
 
   * Added "gentoo=xkms" boot parameter for forcing X modesetting driver
   * More robust Xorg autoconfiguration

+ 2 - 2
src/root/config/grub.cfg

@@ -68,11 +68,11 @@ set menu_color_highlight=yellow/red
 
 
 menuentry "[${tag}] Liberté Linux VERSION"                         --class=linux {
-linux  ${kernel} cdroot_hash=${fshash} add_efi_memmap quiet memtest=1 loglevel=4
+linux  ${kernel} cdroot_hash=${fshash} add_efi_memmap blacklist=firewire-sbp2 quiet memtest=1 loglevel=4
 }
 
 menuentry "[${tag}] Liberté Linux VERSION (Framebuffer Graphics)"  --class=linux {
-linux  ${kernel} cdroot_hash=${fshash} add_efi_memmap nomodeset gentoo=xfb quiet memtest=1 loglevel=4
+linux  ${kernel} cdroot_hash=${fshash} add_efi_memmap nomodeset gentoo=xfb blacklist=firewire-sbp2 quiet memtest=1 loglevel=4
 }
 
 menuentry "[${tag}] Liberté Linux VERSION (Administrator Console)" --class=linux {

+ 2 - 2
src/root/config/syslinux.cfg

@@ -54,7 +54,7 @@ MENU CLEAR
 LABEL liberte
     MENU LABEL Liberté Linux VERSION
     LINUX  /liberte/boot/kernel-x86.zi
-    APPEND cdroot_hash=FSHASH video=800x600-32 quiet memtest=1 loglevel=4
+    APPEND cdroot_hash=FSHASH video=800x600-32 blacklist=firewire-sbp2 quiet memtest=1 loglevel=4
     TEXT HELP
 Select for normal boot.
 Optional params: readonly, [no]toram, gentoo={nosettings,noanon}.
@@ -63,7 +63,7 @@ Optional params: readonly, [no]toram, gentoo={nosettings,noanon}.
 LABEL vesa
     MENU LABEL Liberté Linux VERSION (VESA Graphics)
     LINUX  /liberte/boot/kernel-x86.zi
-    APPEND cdroot_hash=FSHASH nomodeset gentoo=xvesa quiet memtest=1 loglevel=4
+    APPEND cdroot_hash=FSHASH nomodeset gentoo=xvesa blacklist=firewire-sbp2 quiet memtest=1 loglevel=4
     TEXT HELP
 Disables framebuffer console and forces VESA graphics in X.
 Optional params: readonly, [no]toram, gentoo={nosettings,noanon}.