From: Jeff Vander Stoep Date: Wed, 1 Jun 2016 20:44:47 +0000 (-0700) Subject: ANDROID: restrict access to perf events X-Git-Tag: firefly_0821_release~176^2~390 X-Git-Url: http://demsky.eecs.uci.edu/git/?a=commitdiff_plain;h=377fd8e3af2c1f74b51817032fcbe6c06e49ea7e;p=firefly-linux-kernel-4.4.55.git ANDROID: restrict access to perf events Add: CONFIG_SECURITY_PERF_EVENTS_RESTRICT=y to android-base.cfg The kernel.perf_event_paranoid sysctl is set to 3 by default. No unprivileged use of the perf_event_open syscall will be permitted unless it is changed. Bug: 29054680 Change-Id: Ie7512259150e146d8e382dc64d40e8faaa438917 --- diff --git a/android/configs/android-base.cfg b/android/configs/android-base.cfg index 304f1d4fd7c4..6db5542a51f4 100644 --- a/android/configs/android-base.cfg +++ b/android/configs/android-base.cfg @@ -145,6 +145,7 @@ CONFIG_RTC_CLASS=y CONFIG_RT_GROUP_SCHED=y CONFIG_SECURITY=y CONFIG_SECURITY_NETWORK=y +CONFIG_SECURITY_PERF_EVENTS_RESTRICT=y CONFIG_SECURITY_SELINUX=y CONFIG_SETEND_EMULATION=y CONFIG_STAGING=y