Skip to content

security: openpax: disable OpenPaX by default - #20

Merged
kaniini merged 1 commit into
edera/mainlinefrom
fwd/openpax-default-off
Oct 9, 2026
Merged

kaniini merged 1 commit into
edera/mainlinefrom
fwd/openpax-default-off

Conversation

@kaniini

@kaniini kaniini commented Oct 9, 2026

Copy link
Copy Markdown

Forward port of 514cd60bedff from edera/6.18-lts; it was the only Edera commit there with no counterpart on mainline. It applies cleanly.

OPENPAX now defaults to n, and OPENPAX_SOFTMODE depends on OPENPAX.

Checked:

  • defconfig now has # CONFIG_OPENPAX is not set.
  • Asking for soft mode without OpenPaX leaves both off.
  • x86_64 defconfig vmlinux builds with OpenPaX off. 074df2b8456b (pax_softmode unconditionally) already covers that.
  • The nightly's kernel-build.sh enables OPENPAX explicitly, so its builds still include OpenPaX.

Please use Rebase and merge, so edera/mainline stays linear.

OPENPAX currently defaults to y, which means OpenPaX gets enabled
for any configuration that picks up the new symbol, including ones
that never asked for it. Default it to n so it has to be selected
explicitly.

While at it, make OPENPAX_SOFTMODE depend on OPENPAX. Soft mode does
nothing without OpenPaX enabled, so there is no reason for it to be
selectable (and default y) on its own.

Signed-off-by: Alex Zenla <alex@edera.dev>
(cherry picked from commit 514cd60)
@kaniini
kaniini merged commit afd07ff into edera/mainline Oct 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants