diff --git a/kernel/Dockerfile b/kernel/Dockerfile index ed06a69..c2c5b03 100644 --- a/kernel/Dockerfile +++ b/kernel/Dockerfile @@ -298,13 +298,6 @@ RUN < 78.5 ms; with # patches/0004 (PCI configuration through ECAM, one trap an access), 73.7. - # BPF_LSM is deliberately NOT enabled, and this is where the decision is written down - # so it is not made again by accident. It depends on CONFIG_SECURITY, which is off here - # and would put LSM hooks on paths this kernel is tuned for boot time on — and what it - # buys is the ability to enforce access policy *inside* a VM that holds one workload, - # which is a boundary drawn inside the boundary this machine already is. Somebody who - # needs to develop BPF LSM programs turns on CONFIG_SECURITY and this, deliberately, - # with a measurement, and accepts that it is a different machine. # Boot performance: the RAID6 PQ benchmark probes all SIMD implementations at boot to # pick the fastest. It must stay disabled. (RAID6_PQ itself is not selected today, so