From 3877550114c37be4dfcb6dce7f28ef5400529326 Mon Sep 17 00:00:00 2001
From: Mathias Kresin <dev@kresin.me>
Date: Thu, 26 Apr 2018 22:25:11 +0200
Subject: arm64: enable harden branch predictor

Enable the harden branch predictor for arm64 as it is recommend.

Signed-off-by: Mathias Kresin <dev@kresin.me>
---
 target/linux/armvirt/64/config-default | 2 ++
 1 file changed, 2 insertions(+)

(limited to 'target/linux/armvirt/64/config-default')

diff --git a/target/linux/armvirt/64/config-default b/target/linux/armvirt/64/config-default
index 4e63668f5f..0045651333 100644
--- a/target/linux/armvirt/64/config-default
+++ b/target/linux/armvirt/64/config-default
@@ -106,6 +106,7 @@ CONFIG_GENERIC_CSUM=y
 CONFIG_GENERIC_TIME_VSYSCALL=y
 CONFIG_GPIO_GENERIC=y
 CONFIG_GPIO_GENERIC_PLATFORM=y
+CONFIG_HARDEN_BRANCH_PREDICTOR=y
 CONFIG_HAVE_ALIGNED_STRUCT_PAGE=y
 CONFIG_HAVE_ARCH_HUGE_VMAP=y
 CONFIG_HAVE_ARCH_KASAN=y
@@ -177,6 +178,7 @@ CONFIG_SYS_SUPPORTS_HUGETLBFS=y
 # CONFIG_THUNDER_NIC_PF is not set
 # CONFIG_THUNDER_NIC_RGX is not set
 # CONFIG_THUNDER_NIC_VF is not set
+CONFIG_UNMAP_KERNEL_AT_EL0=y
 CONFIG_VEXPRESS_CONFIG=y
 CONFIG_VEXPRESS_SYSCFG=y
 CONFIG_VIDEOMODE_HELPERS=y
-- 
cgit v1.2.3