mirror of
https://github.com/kata-containers/kata-containers.git
synced 2025-05-15 03:41:19 +00:00
At the proper step pass-through the var KBUILD_SIGN_PIN so that the kernel_headers step has the PIN for encrypting the signing key. Signed-off-by: Zvonko Kaiser <zkaiser@nvidia.com>
34 lines
790 B
Plaintext
34 lines
790 B
Plaintext
# Support mmconfig PCI config space access.
|
|
# It's used to enable the MMIO access method for PCIe devices.
|
|
CONFIG_PCI_MMCONFIG=y
|
|
|
|
# Support for loading modules.
|
|
# It is used to support loading GPU drivers.
|
|
CONFIG_MODULES=y
|
|
CONFIG_MODULE_UNLOAD=y
|
|
|
|
# Linux kernel version suffix
|
|
CONFIG_LOCALVERSION="-nvidia-gpu${CONF_GUEST_SUFFIX}"
|
|
|
|
# Newer NVIDIA drivers need additional symbols
|
|
CONFIG_X86_MCE=y
|
|
CONFIG_ARCH_SUPPORTS_MEMORY_FAILURE=y
|
|
CONFIG_X86_SUPPORTS_MEMORY_FAILURE=y
|
|
CONFIG_MEMORY_FAILURE=y
|
|
CONFIG_MTRR=y
|
|
CONFIG_X86_PAT=y
|
|
|
|
# CC related configs
|
|
CONFIG_CRYPTO_ECC=y
|
|
CONFIG_CRYPTO_ECDH=y
|
|
CONFIG_CRYPTO_ECDSA=y
|
|
|
|
# Module signing
|
|
CONFIG_MODULE_SIG=y
|
|
CONFIG_MODULE_SIG_FORCE=y
|
|
CONFIG_MODULE_SIG_ALL=y
|
|
CONFIG_MODULE_SIG_SHA512=y
|
|
CONFIG_SYSTEM_TRUSTED_KEYS=""
|
|
CONFIG_SYSTEM_TRUSTED_KEYRING=y
|
|
|