CHROMIUM: disable sysrq by default
authorKees Cook <keescook@chromium.org>
Wed, 18 Jul 2012 19:30:24 +0000 (12:30 -0700)
committerGerrit <chrome-bot@google.com>
Wed, 18 Jul 2012 21:02:00 +0000 (14:02 -0700)
commita9e25309a514523c166b32ad2a9be92c2ca384a0
treeb30358254c24a4f6f4bbc8b5407a87a4b8a70823
parent88bde5adc7d29ea7ce31fb62998d7f1dc6fbde02
CHROMIUM: disable sysrq by default

Disable sysrq by default. The init scripts choose the final setting based
on the mode of the device. Currently this means there is a small window
where sysrq could be used to dump kernel addresses or kill processes
when in verified boot mode. This change eliminates that chance.

BUG=chromium-os:32277
TEST=link build, manually disable init logic, verify sysrq sysctl==0

Change-Id: Ic161d9a3e9f807dda9c128ae2f437711918d8fb3
Signed-off-by: Kees Cook <keescook@chromium.org>
Reviewed-on: https://gerrit.chromium.org/gerrit/27790
Reviewed-by: Olof Johansson <olofj@chromium.org>
include/linux/sysrq.h