From 9cb730124eab508333c3c50de4fb2da565b4185c Mon Sep 17 00:00:00 2001 From: RoyalOughtness <129108030+RoyalOughtness@users.noreply.github.com> Date: Thu, 1 Oct 2026 09:44:14 -0700 Subject: [PATCH 1/3] feat: enable CONFIG_ZERO_CALL_USED_REGS --- copr_script.sh | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/copr_script.sh b/copr_script.sh index c1cb319..076ad78 100644 --- a/copr_script.sh +++ b/copr_script.sh @@ -38,6 +38,12 @@ configs_to_enable=( # https://www.kernelconfig.io/CONFIG_IOMMU_DEFAULT_DMA_STRICT # Equivalent to defaulting iommu.passthrough=0 iommu.strict=1, already set by our kargs CONFIG_IOMMU_DEFAULT_DMA_STRICT + + # https://www.kernelconfig.io/CONFIG_ZERO_CALL_USED_REGS + # Zero contents of caller-used registers before returning. + # Reduces attack surface with negigible perf impact and a + # slight increase in kernel image size + CONFIG_ZERO_CALL_USED_REGS ) configs_to_disable=( From f9dfbe9032aca79e0d30b945a3a58f3b290573ae Mon Sep 17 00:00:00 2001 From: RoyalOughtness <129108030+RoyalOughtness@users.noreply.github.com> Date: Thu, 1 Oct 2026 09:45:41 -0700 Subject: [PATCH 2/3] fix --- copr_script.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/copr_script.sh b/copr_script.sh index 076ad78..80ff8c3 100644 --- a/copr_script.sh +++ b/copr_script.sh @@ -41,8 +41,8 @@ configs_to_enable=( # https://www.kernelconfig.io/CONFIG_ZERO_CALL_USED_REGS # Zero contents of caller-used registers before returning. - # Reduces attack surface with negigible perf impact and a - # slight increase in kernel image size + # Reduces side channel attack vectors with negligible perf impact and a + # slight increase in kernel image size (<1% on x86_64, 5% on aarch64) CONFIG_ZERO_CALL_USED_REGS ) From 86bd17dae05ce4acea4d511a78364d323877b197 Mon Sep 17 00:00:00 2001 From: RoyalOughtness <129108030+RoyalOughtness@users.noreply.github.com> Date: Thu, 1 Oct 2026 09:46:32 -0700 Subject: [PATCH 3/3] fix --- copr_script.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/copr_script.sh b/copr_script.sh index 80ff8c3..7dd6b25 100644 --- a/copr_script.sh +++ b/copr_script.sh @@ -41,7 +41,7 @@ configs_to_enable=( # https://www.kernelconfig.io/CONFIG_ZERO_CALL_USED_REGS # Zero contents of caller-used registers before returning. - # Reduces side channel attack vectors with negligible perf impact and a + # Reduces side channel attack vectors with negligible perf impact and a # slight increase in kernel image size (<1% on x86_64, 5% on aarch64) CONFIG_ZERO_CALL_USED_REGS )