CHROMIUM: disable sysrq by default
Disable sysrq by default. The init scripts choose the final setting based
on the mode of the device. Currently this means there is a small window
where sysrq could be used to dump kernel addresses or kill processes
when in verified boot mode. This change eliminates that chance.
BUG=chromium-os:32277
TEST=link build, manually disable init logic, verify sysrq sysctl==0
Change-Id: Ic161d9a3e9f807dda9c128ae2f437711918d8fb3
Signed-off-by: Kees Cook <keescook@chromium.org>
Reviewed-on: https://gerrit.chromium.org/gerrit/27790
Reviewed-by: Olof Johansson <olofj@chromium.org>