From d0014e71af1cda5b1cca89327072e56ed00fd195 Mon Sep 17 00:00:00 2001 From: Alex Zenla Date: Sat, 26 Sep 2026 13:09:58 -0700 Subject: [PATCH] security: openpax: disable OpenPaX by default OPENPAX currently defaults to y, which means OpenPaX gets enabled for any configuration that picks up the new symbol, including ones that never asked for it. Default it to n so it has to be selected explicitly. While at it, make OPENPAX_SOFTMODE depend on OPENPAX. Soft mode does nothing without OpenPaX enabled, so there is no reason for it to be selectable (and default y) on its own. Signed-off-by: Alex Zenla (cherry picked from commit 514cd60bedffac5e9cd8c42888fd18434b409a86) --- security/Kconfig.openpax | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/security/Kconfig.openpax b/security/Kconfig.openpax index 76ee145094d93b..df65b38ed396e4 100644 --- a/security/Kconfig.openpax +++ b/security/Kconfig.openpax @@ -6,7 +6,7 @@ menu "OpenPaX options" config OPENPAX bool "Enable OpenPaX features" - default y + default n help This configuration setting enables OpenPaX features. OpenPaX adds memory safety-related defenses to the kernel which @@ -14,6 +14,7 @@ config OPENPAX config OPENPAX_SOFTMODE bool "Support PaX soft mode" + depends on OPENPAX default y help Enabling this option will allow you to configure OpenPaX