xref: /xnu-11215/config/MASTER (revision bb611c8f)
1#
2# Mach Operating System
3# Copyright (c) 1986 Carnegie-Mellon University
4# Copyright 2001-2018 Apple Inc.
5#
6# All rights reserved.  The CMU software License Agreement
7# specifies the terms and conditions for use and redistribution.
8#
9#######################################################################
10#
11#	Master machine independent configuration file.
12#
13#	Specific configuration files are created based on this and
14#	the machine specific master file using the doconf script.
15#
16#	Any changes to the master configuration files will affect all
17#	other configuration files based upon it.
18#
19#######################################################################
20#
21#	To build a configuration, execute "doconf <configuration>."
22#	Configurations are specified in the "Configurations:" section
23#	of the MASTER and MASTER.* files as follows:
24#
25#	<configuration> = [ <attribute0> <attribute1> ... <attributeN> ]
26#
27#	Lines in the MASTER and MASTER.* files are selected based on
28#	the attribute selector list, found in a comment at the end of
29#	the line.  This is a list of attributes separated by commas.
30#	The "!" operator selects the line if none of the attributes are
31#	specified.
32#
33#	For example:
34#
35#	<foo,bar>	selects a line if "foo" or "bar" are specified.
36#	<!foo,bar>	selects a line if neither "foo" nor "bar" is
37#			specified.
38#
39#	Lines with no attributes specified are selected for all
40#	configurations.
41#
42#######################################################################
43#
44#  SYSTEM SIZE CONFIGURATION (select exactly one)
45#
46#	xlarge = extra large scale system configuration
47#	large  = large scale system configuration
48#	medium = medium scale system configuration
49#	small  = small scale system configuration
50#	xsmall = extra small scale system configuration
51#	bsmall = special extra small scale system configuration
52#
53#######################################################################
54#
55
56options		INET		#				# <inet>
57options		HW_AST		# Hardware ast support		# <hw_ast>
58options 	HW_FOOTPRINT	# Cache footprint support	# <hw_foot>
59
60options 	MACH		# Standard Mach features	# <mach>
61options		MACH_COMPAT	# Vendor syscall compatibility  # <mach>
62options		MACH_FASTLINK	# Fast symbolic links
63options		MACH_HOST	# Mach host (resource alloc.)	# <host>
64options		MACH_IPC_COMPAT	# Enable old IPC interface	# <ipc_compat>
65options		MACH_IPC_TEST	# Testing code/printfs		# <ipc_test>
66options		MACH_FLIPC	# Fast-Local IPC		# <mach_flipc>
67options 	MACH_NP		# Mach IPC support		# <np>
68options		MACH_NBC	# No buffer cache		# <nbc>
69options		MACH_NET	# Fast network access		# <mach_net>
70options		MACH_XP		# external pager support	# <xp>
71options		NO_DIRECT_RPC	# for untyped mig servers	#
72options		LOOP		# loopback support		# <loop>
73options		VLAN		#				# <vlan>
74options		SIXLOWPAN	# 6LoWPAN support		# <sixlowpan>
75options		BOND		#				# <bond>
76options		IF_FAKE		#				# <if_fake>
77options		IF_HEADLESS	#				# <if_headless>
78options		AH_ALL_CRYPTO	# AH all crypto algs		# <ah_all_crypto>
79options		PF		# Packet Filter			# <pf>
80options		PF_ECN		# PF use ECN marking		# <pf_ecn>
81options		PFLOG		# PF log interface		# <pflog>
82options		MEASURE_BW	# interface bandwidth measurement # <measure_bw>
83options		DUMMYNET	# dummynet support		# <dummynet>
84options		TRAFFIC_MGT	# traffic management support		# <traffic_mgt>
85options		MULTICAST	# Internet Protocol Class-D	$
86options		TCPDEBUG	# TCP debug			# <tcpdebug>
87options		ICMP_BANDLIM	# ICMP bandwidth limiting sysctl
88options		IFNET_INPUT_SANITY_CHK	# allow dlil/ifnet input sanity check # <ifnet_input_chk>
89options		MULTIPATH	# Multipath domain		# <multipath>
90options		MPTCP		# Multipath TCP			# <mptcp>
91options		SYSV_SEM	# SVID semaphores		# <sysv_sem>
92options		SYSV_MSG	# SVID messages			# <sysv_msg>
93options		SYSV_SHM	# SVID shared mem		# <sysv_shm>
94options		PSYNCH		# pthread synch			# <psynch>
95options		FLOW_DIVERT								# <flow_divert>
96options		NECP									# <necp>
97options		CONTENT_FILTER	#						# <content_filter>
98options 	PACKET_MANGLER	#						# <packet_mangler>
99options 	SIXLOWPAN	#		# <sixlowpan>
100# secure_kernel - secure kernel from user programs
101options     SECURE_KERNEL       # <secure_kernel>
102
103options     OLD_SEMWAIT_SIGNAL  # old semwait_signal handler
104
105#
106#	4.4 general kernel
107#
108options		SOCKETS		# socket support		# <inet>
109options 	DIAGNOSTIC	# diagnostics			# <diagnostic>
110options		PROFILE		# kernel profiling		# <profile>
111options		SENDFILE	# sendfile					# <sendfile>
112options		NETWORKING	# networking layer		# <inet>
113options		CONFIG_FSE	# file system events		# <config_fse>
114options		CONFIG_IMAGEBOOT	# local image boot	# <config_imageboot>
115options		CONFIG_LOCKERBOOT 	# locker boot 	# <config_lockerboot>
116options		CONFIG_MBUF_JUMBO	# jumbo cluster pool	# <config_mbuf_jumbo>
117options		CONFIG_IMAGEBOOT_IMG4	# authenticate image with AppleImage4	# <config_imageboot_img4>
118options		CONFIG_IMAGEBOOT_CHUNKLIST	# authenticate image with a chunk list	# <config_imageboot_chunklist>
119
120options		CONFIG_WORKQUEUE	# <config_workqueue>
121options		CONFIG_WORKLOOP_DEBUG	# <config_workloop_debug>
122
123#
124#	4.4 filesystems
125#
126options		MOCKFS		# Boot from an executable	# <mockfs>
127options		FIFO		# fifo support			# <fifo>
128options		FDESC		# fdesc_fs support		# <fdesc>
129options		DEVFS		# devfs support			# <devfs>
130options		ROUTEFS		# routefs support		# <routefs>
131options		NULLFS		# nullfs support 		# <nullfs>
132options		BINDFS		# bindfs support 		# <bindfs>
133options		FS_COMPRESSION	# fs compression	    # <fs_compression>
134options		CONFIG_DEV_KMEM	    # /dev/kmem device for reading KVA	# <config_dev_kmem>
135
136#
137#	file system features
138#
139options		QUOTA		# file system quotas		# <quota>
140options		NAMEDSTREAMS	# named stream vnop support	# <namedstreams>
141options		CONFIG_APPLEDOUBLE # apple double support	# <config_appledouble>
142options		CONFIG_VOLFS	# volfs path support (legacy)	# <config_volfs>
143options		CONFIG_IMGSRC_ACCESS # source of imageboot dmg	# <config_imgsrc_access>
144options		CONFIG_TRIGGERS	# trigger vnodes		# <config_triggers>
145options		CONFIG_EXT_RESOLVER # e.g. memberd		# <config_ext_resolver>
146options		CONFIG_SEARCHFS	# searchfs syscall support	# <config_searchfs>
147options		CONFIG_MNT_SUID # allow suid binaries  # <config_mnt_suid>
148options		CONFIG_MNT_ROOTSNAP # allow rooting from snapshot # <config_mnt_rootsnap>
149options 	CONFIG_ROSV_STARTUP # allow read-only system volume startup # <config_rosv_startup>
150options		CONFIG_FIRMLINKS # support "firmlinks" # <config_firmlinks>
151options 	CONFIG_MOUNT_VM # mount VM volume on startup # <config_mount_vm>
152options 	CONFIG_MOUNT_PREBOOTRECOVERY # mount Preboot and/or Recovery volume on startup # <config_mount_prebootrecovery>
153options		CONFIG_DATALESS_FILES # support dataless file materialization # <config_dataless_files>
154options         CONFIG_BASESYSTEMROOT # mount BaseSystem as initial root filesystem on some kinds of startup # <config_basesystemroot>
155
156#
157# NFS support
158#
159options		NFSCLIENT	# Be an NFS client		# <nfsclient>
160options		NFSSERVER	# Be an NFS server		# <nfsserver>
161options		CONFIG_NFS_GSS	# Support NFS GSSAPI		# <config_nfs_gss>
162options		CONFIG_NFS4	# Use NFSv4			# <config_nfs4>
163options		CONFIG_NETBOOT	# network booting (requires NFSCLIENT) # <config_netboot>
164
165#
166# Machine Independent Apple Features
167#
168profile				# build a profiling kernel	# <profile>
169
170#
171# IPv6 Support
172#
173options         IPSEC           # IP security            	# <ipsec>
174options         IPSEC_ESP       # IP security            	# <ipsec>
175
176pseudo-device   gif     1				# <gif>
177pseudo-device   dummy   2				# <dummy>
178pseudo-device   stf 	1 				# <stf>
179
180options			CRYPTO				# <ipsec,crypto>
181options			CRYPTO_SHA2			# <crypto_sha2>
182options			ENCRYPTED_SWAP			# <encrypted_swap>
183
184options			CONFIG_IMG4			# <config_img4>
185
186options		ZLIB	# inflate/deflate support	# <zlib>
187options		ZLIBC	# inflate/deflate support	# <zlibc>
188
189options		IF_BRIDGE				# <if_bridge>
190
191#
192#  configurable kernel event related resources
193#
194options   CONFIG_KN_HASHSIZE=64		# <medium,large,xlarge>
195options   CONFIG_KN_HASHSIZE=48		# <small,xsmall>
196options   CONFIG_KN_HASHSIZE=20		# <bsmall>
197
198#
199#  configurable vfs related resources
200#  CONFIG_VNODES - used to pre allocate vnode related resources
201#  CONFIG_NC_HASH - name cache hash table allocation
202#  CONFIG_VFS_NAMES - name strings
203#
204#  263168 magic number for medium CONFIG_VNODES is based on memory
205#  Number vnodes  is (memsize/64k) + 1024
206#  This is the calculation that is used by launchd in tiger
207#  we are clipping the max based on 16G
208#  ie ((16*1024*1024*1024)/(64 *1024)) + 1024 = 263168;
209
210options   CONFIG_VNODES=263168		# <large,xlarge>
211options   CONFIG_VNODES=263168		# <medium>
212options   CONFIG_VNODES=10240		# <small>
213options   CONFIG_VNODES=750		# <bsmall>
214
215options   CONFIG_NC_HASH=5120		# <large,xlarge>
216options   CONFIG_NC_HASH=4096		# <medium>
217options   CONFIG_NC_HASH=2048		# <small,xsmall>
218options   CONFIG_NC_HASH=1024		# <bsmall>
219
220options   CONFIG_VFS_NAMES=5120		# <large,xlarge>
221options   CONFIG_VFS_NAMES=4096		# <medium>
222options   CONFIG_VFS_NAMES=3072		# <small,xsmall>
223options   CONFIG_VFS_NAMES=2048		# <bsmall>
224
225options   CONFIG_MAX_CLUSTERS=8		# <xlarge,large,medium>
226options   CONFIG_MAX_CLUSTERS=4		# <small,xsmall,bsmall>
227
228#
229#  configurable options for minumum number of buffers for kernel memory
230#
231options   CONFIG_MIN_NBUF=256		# <medium,large,xlarge>
232options   CONFIG_MIN_NBUF=128		# <small>
233options   CONFIG_MIN_NBUF=80		# <xsmall>
234options   CONFIG_MIN_NBUF=64		# <bsmall>
235
236options   CONFIG_MIN_NIOBUF=128		# <medium,large,xlarge>
237options   CONFIG_MIN_NIOBUF=64		# <xsmall,small>
238options   CONFIG_MIN_NIOBUF=32		# <bsmall>
239
240#
241# set maximum space used for packet buffers
242#
243options        CONFIG_NMBCLUSTERS="((1024 * 1024) / MCLBYTES)"	# <large,xlarge>
244options        CONFIG_NMBCLUSTERS="((1024 * 512) / MCLBYTES)"	# <medium>
245options        CONFIG_NMBCLUSTERS="((1024 * 256) / MCLBYTES)"	# <bsmall,xsmall,small>
246
247#
248# Configure size of TCP hash table
249#
250options CONFIG_TCBHASHSIZE=4096		# <medium,large,xlarge>
251options CONFIG_TCBHASHSIZE=128		# <xsmall,small,bsmall>
252
253#
254# Configure bandwidth limiting sysctl
255#
256options CONFIG_ICMP_BANDLIM=250		# <medium,large,xlarge>
257options CONFIG_ICMP_BANDLIM=50		# <xsmall,small,bsmall>
258
259#
260#  configurable async IO options
261#  CONFIG_AIO_MAX - system wide limit of async IO requests.
262#  CONFIG_AIO_PROCESS_MAX - process limit of async IO requests.
263#  CONFIG_AIO_THREAD_COUNT - number of async IO worker threads created.
264#
265options   CONFIG_AIO_MAX=360			# <xlarge>
266options   CONFIG_AIO_MAX=180			# <large>
267options   CONFIG_AIO_MAX=90			# <medium>
268options   CONFIG_AIO_MAX=45			# <small>
269options   CONFIG_AIO_MAX=20			# <xsmall>
270options   CONFIG_AIO_MAX=10			# <bsmall>
271
272options   CONFIG_AIO_PROCESS_MAX=64		# <xlarge>
273options   CONFIG_AIO_PROCESS_MAX=32		# <large>
274options   CONFIG_AIO_PROCESS_MAX=16		# <medium>
275options   CONFIG_AIO_PROCESS_MAX=12		# <small>
276options   CONFIG_AIO_PROCESS_MAX=8		# <xsmall>
277options   CONFIG_AIO_PROCESS_MAX=4		# <bsmall>
278
279options   CONFIG_AIO_THREAD_COUNT=16		# <xlarge>
280options   CONFIG_AIO_THREAD_COUNT=8		# <large>
281options   CONFIG_AIO_THREAD_COUNT=4		# <medium>
282options   CONFIG_AIO_THREAD_COUNT=3		# <small>
283options   CONFIG_AIO_THREAD_COUNT=2		# <xsmall,bsmall>
284
285options   CONFIG_MAXVIFS=32			# <medium,large,xlarge>
286options   CONFIG_MAXVIFS=16			# <small,xsmall>
287options   CONFIG_MAXVIFS=2			# <bsmall>
288
289options   CONFIG_MFCTBLSIZ=256			# <medium,large,xlarge>
290options   CONFIG_MFCTBLSIZ=128			# <small,xsmall>
291options   CONFIG_MFCTBLSIZ=16			# <bsmall>
292
293#
294# configurable kernel message buffer size
295#
296options   CONFIG_MSG_BSIZE_REL=4096		# <msgb_small>
297options   CONFIG_MSG_BSIZE_DEV=4096		# <msgb_small>
298options   CONFIG_MSG_BSIZE_REL=16384		# <msgb_large>
299options   CONFIG_MSG_BSIZE_DEV=131072		# <msgb_large>
300options   CONFIG_MSG_BSIZE=CONFIG_MSG_BSIZE_REL	# <!development,debug>
301options   CONFIG_MSG_BSIZE=CONFIG_MSG_BSIZE_DEV	# <development,debug>
302
303#
304# maximum size of the per-process Mach IPC table
305#
306options   CONFIG_IPC_TABLE_ENTRIES_STEPS=64  	# 137898 entries	# <bsmall,small,xsmall>
307options   CONFIG_IPC_TABLE_ENTRIES_STEPS=256 	# 300714 entries	# <medium,large,xlarge>
308
309#
310#  configurable kernel - use these options to strip strings from panic
311#  and printf calls.
312#  no_printf_str - saves around 45K of kernel footprint.
313#
314options   CONFIG_NO_PRINTF_STRINGS		# <no_printf_str>
315options   CONFIG_NO_KPRINTF_STRINGS		# <no_kprintf_str>
316
317# support vsprintf (deprecated in favor of vsnprintf)
318options   CONFIG_VSPRINTF               # <vsprintf>
319
320#
321# configurable kernel - general switch to say we are building for an
322# embedded device
323#
324options   CONFIG_EMBEDDED			# <config_embedded>
325
326options   CONFIG_ARROW              # <config_arrow>
327
328
329# support dynamic signing of code
330#
331options		CONFIG_DYNAMIC_CODE_SIGNING	# <dynamic_codesigning>
332
333# enforce library validation on all processes.
334#
335options		CONFIG_ENFORCE_LIBRARY_VALIDATION  # <config_library_validation>
336
337# support loading a second static trust cache
338#
339options CONFIG_SECOND_STATIC_TRUST_CACHE # <second_static_trust_cache>
340
341# support supplemental signatures
342#
343options CONFIG_SUPPLEMENTAL_SIGNATURES # <config_supplemental_signatures>
344
345#
346# code decryption... used on embedded for app protection, DSMOS on desktop
347#
348options		CONFIG_CODE_DECRYPTION		# <config_code_decryption>
349
350#
351# User Content Protection, used on embedded
352#
353options		CONFIG_PROTECT			# <config_protect>
354
355#allow write-protection of key page
356options		CONFIG_KEYPAGE_WP		# <config_keypage_wp>
357
358#
359# allow vm_pageout_scan to dynamically adjust its priority based on priorities of waiters
360#
361options		CONFIG_VPS_DYNAMIC_PRIO		# <vps_dynamic_prio>
362
363#
364# enable per-process memory priority tracking
365#
366options		CONFIG_MEMORYSTATUS		# <memorystatus>
367
368#
369# enable per-process dirty-status tracking
370#
371options		CONFIG_DIRTYSTATUS_TRACKING	# <dirtystatus_tracking>
372#
373# enable jetsam - used on embedded
374#
375options		CONFIG_JETSAM			# <jetsam>
376
377#
378# enable new link table implementation stats/debugging
379# (adds mesaureable overhead)
380#
381options		CONFIG_LTABLE_STATS			# <config_ltable_stats>
382options		CONFIG_LTABLE_DEBUG			# <config_ltable_debug>
383
384#
385# enable new wait queue implementation stats / debugging
386#
387options		CONFIG_WAITQ_STATS			# <config_waitq_stats>
388options		CONFIG_WAITQ_DEBUG			# <config_waitq_debug>
389
390#
391# enable freezing of suspended processes - used on embedded
392#
393options		CONFIG_FREEZE			# <freeze>
394
395options		CHECK_CS_VALIDATION_BITMAP	# <config_cs_validation_bitmap>
396
397#
398# enable physical writes accounting
399#
400options		CONFIG_PHYS_WRITE_ACCT		# <phys_write_acct>
401
402#
403# enable detectiion of file cache thrashing - used on platforms with
404# dynamic VM compression enabled
405#
406options		CONFIG_PHANTOM_CACHE		# <phantom_cache>
407
408#
409# memory pressure event support
410#
411options		VM_PRESSURE_EVENTS		# <vm_pressure_events>
412
413options		CONFIG_SECLUDED_MEMORY		# <config_secluded_memory>
414
415options		CONFIG_BACKGROUND_QUEUE		# <config_background_queue>
416
417#
418# Ledger features
419#
420options		CONFIG_LEDGER_INTERVAL_MAX	# <config_ledger_interval_max>
421
422#
423# I/O Scheduling
424#
425options		CONFIG_IOSCHED			# <config_iosched>
426
427#
428# Accounting for I/O usage
429#
430options 	CONFIG_IO_ACCOUNTING 		# <config_io_accounting>
431
432#
433# Enable inheritance of importance through specially marked mach ports and for file locks
434# For now debug is enabled wherever inheritance is
435#
436options		IMPORTANCE_INHERITANCE		# <importance_inheritance>
437options		IMPORTANCE_TRACE		# <importance_trace>
438options		IMPORTANCE_DEBUG		# <importance_debug>
439
440options		CONFIG_TELEMETRY		# <config_telemetry>
441
442options		CONFIG_PROC_UUID_POLICY		# <config_proc_uuid_policy>
443
444#
445# ECC data logging
446#
447options		CONFIG_ECC_LOGGING		# <config_ecc_logging>
448
449#
450# Application core dumps
451#
452options		CONFIG_COREDUMP			# <config_coredump>
453
454#
455# Vnode guards
456#
457options		CONFIG_VNGUARD			# <config_vnguard>
458
459#
460#  Ethernet (ARP)
461#
462pseudo-device	ether				# <networking,inet>
463#
464#  Network loopback device
465#
466pseudo-device	loop				# <networking,inet>
467#
468#  UCB pseudo terminal service
469#
470pseudo-device  pty     512 init pty_init       # <xlarge>
471pseudo-device  pty     256 init pty_init       # <large>
472pseudo-device  pty     128 init pty_init       # <medium>
473pseudo-device  pty      48 init pty_init       # <small>
474pseudo-device  pty      16 init pty_init       # <xsmall>
475pseudo-device  pty       8 init pty_init       # <bsmall>
476#
477# Cloning pseudo terminal service
478#
479pseudo-device	ptmx	1 init ptmx_init
480
481#
482# vnode device
483#
484pseudo-device  vndevice		4       init    vndevice_init   # <development,debug>
485
486#
487# memory device
488pseudo-device	mdevdevice	1	init	mdevinit
489
490#
491#
492# packet filter device
493#
494pseudo-device	bpfilter	4	init	bpf_init		# <networking,inet>
495
496#
497# fsevents device
498pseudo-device	fsevents	1	init	fsevents_init	# <config_fse>
499
500pseudo-device	random		1	init	random_init
501pseudo-device	dtrace		1	init	dtrace_init	# <config_dtrace>
502pseudo-device	helper		1	init	helper_init	# <config_dtrace>
503pseudo-device	lockstat	1	init	lockstat_init	# <config_dtrace>
504pseudo-device	lockprof	1	init	lockprof_init	# <config_dtrace>
505pseudo-device	sdt		1	init	sdt_init	# <config_dtrace>
506pseudo-device	systrace	1	init	systrace_init	# <config_dtrace>
507pseudo-device	fbt		1	init	fbt_init	# <config_dtrace>
508pseudo-device	profile_prvd	1	init	profile_init	# <config_dtrace>
509
510
511#
512# IOKit configuration options
513#
514
515options		HIBERNATION	# system hibernation	# <hibernation>
516options		IOKITCPP	# C++ implementation	# <iokitcpp>
517options		IOKITSTATS	# IOKit statistics	# <iokitstats>
518options		IOTRACKING	# IOKit tracking	# <iotracking>
519options		CONFIG_SLEEP	#			# <config_sleep>
520options		CONFIG_MAX_THREADS=500	# IOConfigThread threads
521options         NO_KEXTD                		# <no_kextd>
522options         NO_KERNEL_HID           		# <no_kernel_hid>
523
524#
525# Libkern configuration options
526#
527
528options		LIBKERNCPP		# C++ implementation	# <libkerncpp>
529options		CONFIG_BLOCKS		# Blocks runtime	# <config_blocks>
530options		CONFIG_KXLD		# kxld/runtime linking of kexts # <config_kxld>
531options		CONFIG_KEC_FIPS		# Kernel External Components for FIPS compliance (KEC_FIPS) # <config_kec_fips>
532
533# Note that when adding this config option to an architecture, one MUST
534# add the architecture to the preprocessor test at the beginning of
535# libkern/kmod/cplus_{start.c,stop.c}.
536options         CONFIG_STATIC_CPPINIT   # Static library initializes kext cpp runtime # <config_static_cppinit>
537
538#
539# libsa configuration options
540#
541
542# CONFIG_KEXT_BASEMENT - alloc post boot loaded kexts after prelinked kexts
543#
544options		CONFIG_KEXT_BASEMENT		#	# <config_kext_basement>
545
546#
547# Persona Management
548#
549options		CONFIG_PERSONAS	    # Persona management    # <config_personas>
550options		PERSONA_DEBUG	    # Persona debugging     # <persona_debug>
551
552#
553# security configuration options
554#
555
556options		CONFIG_MACF	# Mandatory Access Control Framework	# <config_macf>
557options		CONFIG_MACF_SOCKET_SUBSET	# MAC socket subest (no labels)	# <config_macf>
558#options	CONFIG_MACF_DEBUG   # debug	    	    # <config_macf>
559
560options		CONFIG_AUDIT	    # Kernel auditing	    # <config_audit>
561
562options		CONFIG_ARCADE		# Arcade validation support	# <config_arcade>
563
564options		CONFIG_SETUID		# setuid/setgid support # <config_setuid>
565
566options		CONFIG_SECURE_BSD_ROOT	# secure BSD root	# <config_secure_bsd_root>
567
568options		CONFIG_KAS_INFO		# kas_info support	# <config_kas_info>
569
570options		CONFIG_ZALLOC_SEQUESTER		# Sequester VA for zones # <config_zalloc_sequester>
571
572#
573# MACH configuration options.
574#
575# TASK_SWAPPER enables code that manages demand for physical memory by
576#	forcibly suspending tasks when the demand exceeds supply. This
577#	option should be on.
578#
579options		TASK_SWAPPER	#	<task_swapper_disabled>
580
581#
582# This defines configuration options that are normally used only during
583# kernel code development and debugging. They add run-time error checks or
584# statistics gathering, which will slow down the system
585#
586##########################################################
587#
588# MACH_ASSERT controls the assert() and ASSERT() macros, used to verify the
589#	consistency of various algorithms in the kernel. The performance impact
590#	of this option is significant.
591#
592options		MACH_ASSERT	#		# <mach_assert>
593#
594# MACH_DEBUG enables the mach_debug_server, a message interface used to
595#	retrieve or control various statistics. This interface may expose data
596#	structures that would not normally be allowed outside the kernel, and
597#	MUST NOT be enabled on a released configuration.
598#	Other options here enable information retrieval for specific subsystems
599#
600options		MACH_DEBUG	# IPC debugging interface	# <mdebug>
601options		MACH_IPC_DEBUG	# Enable IPC debugging calls	# <ipc_debug>
602options		MACH_VM_DEBUG	#				# <debug>
603#
604# MACH_MP_DEBUG control the possible dead locks that may occur by controlling
605#	that IPL level has been raised down to SPL0 after some calls to
606#	hardclock device driver.
607#
608options		MACH_MP_DEBUG	#				# <debug>
609options		CONFIG_ZCACHE 	# Enable per-cpu caching for zones	# <config_zcache>
610options		CONFIG_ZLEAKS	# Live zone leak debugging	# <zleaks>
611
612#
613# CONFIG_TASK_ZONE_INFO allows per-task zone information to be extracted
614# Primarily useful for xnu debug and development.
615#
616options		CONFIG_TASK_ZONE_INFO		# <task_zone_info>
617#
618# CONFIG_DEBUGGER_FOR_ZONE_INFO restricts zone info so that it is only
619# available when the kernel is being debugged.
620#
621options		CONFIG_DEBUGGER_FOR_ZONE_INFO	# <debugger_for_zone_info>
622#
623# MACH_LDEBUG controls the internal consistency checks and
624#	data gathering in the locking package. This also enables a debug-only
625#	version of simple-locks on uniprocessor machines. The code size and
626#	performance impact of this option is significant.
627#
628options		MACH_LDEBUG	#		# <debug>
629
630#
631# configuration option for full, partial, or no kernel debug event tracing
632#
633options		KDEBUG			# kernel tracing	# <kdebug>
634options		IST_KDEBUG		# limited tracing	# <ist_kdebug>
635options		NO_KDEBUG       	# no kernel tracing 	# <no_kdebug>
636
637#
638# CONFIG_DTRACE enables code needed to support DTrace. Currently this is
639# only used for delivery of traps/interrupts to DTrace.
640#
641options		CONFIG_DTRACE		#		    # <config_dtrace>
642
643options		LOCK_STATS		#		    # <lock_stats>
644
645# kernel performance tracing
646options     KPERF                  # <kperf>
647options     KPC                    # <kpc>
648
649
650options     PGO                    # <pgo>
651
652# MACH_COUNTERS enables code that handles various counters in the system.
653#
654options		MACH_COUNTERS	#			    # <debug>
655
656# DEVELOPMENT define for development builds
657options		DEVELOPMENT	# dev kernel	    	    # <development>
658
659# DEBUG kernel
660options		DEBUG		# general debugging code    # <debug>
661options		CONFIG_NONFATAL_ASSERTS	# non fatal asserts	# <softasserts>
662
663##########################################################
664#
665# This defines configuration options that are normally used only during
666# kernel code development and performance characterization. They add run-time
667# statistics gathering, which will slow down the system,
668#
669##########################################################
670#
671# MACH_IPC_STATS controls the collection of statistics in the MACH IPC
672#	subsystem.
673#
674#options	MACH_IPC_STATS
675#
676# MACH_CLUSTER_STATS controls the collection of various statistics concerning
677#	the effectiveness and behavior of the clustered pageout and pagein
678#	code.
679#
680#options	MACH_CLUSTER_STATS
681
682options		MACH_BSD	# BSD subsystem on top of Mach	# <mach_bsd>
683options         IOKIT		#				# <iokit>
684
685#
686#  configurable kernel related resources (CONFIG_THREAD_MAX needs to stay in
687#  sync with bsd/conf/MASTER until we fix the config system... todo XXX
688#
689options   CONFIG_THREAD_MAX=2560		# <medium,large,xlarge>
690options   CONFIG_THREAD_MAX=1536		# <small,xsmall>
691options   CONFIG_THREAD_MAX=1024		# <bsmall>
692
693options   CONFIG_TASK_MAX=1024			# <medium,large,xlarge>
694options   CONFIG_TASK_MAX=768			# <small,>
695options   CONFIG_TASK_MAX=512			# <xsmall,bsmall>
696
697#
698# Minimum zone map size: 115 MB
699#
700options   CONFIG_ZONE_MAP_MIN=120586240	# <xsmall,bsmall,small,medium,large,xlarge>
701
702# Sizes must be a power of two for the zhash to
703# be able to just mask off bits instead of mod
704options	  CONFIG_ZLEAK_ALLOCATION_MAP_NUM=16384 #<medium,large,xlarge>
705options	  CONFIG_ZLEAK_ALLOCATION_MAP_NUM=8192	#<small,xsmall,bsmall>
706options   CONFIG_ZLEAK_TRACE_MAP_NUM=8192 #<medium,large,xlarge>
707options   CONFIG_ZLEAK_TRACE_MAP_NUM=4096 #<small,xsmall,bsmall>
708
709# vc_progress_white - make the progress gear white instead of black
710options	  CONFIG_VC_PROGRESS_WHITE		# <vc_progress_white>
711
712#
713# Timeshare scheduler implementations
714#
715options		CONFIG_SCHED_TRADITIONAL	# <config_sched_traditional>
716options		CONFIG_SCHED_PROTO		# <config_sched_proto>
717options		CONFIG_SCHED_GRRR		# <config_sched_grrr>
718options		CONFIG_SCHED_GRRR_CORE		# <config_sched_grrr>
719options		CONFIG_SCHED_MULTIQ		# <config_sched_multiq>
720options		CONFIG_SCHED_TIMESHARE_CORE	# <config_sched_traditional,config_sched_multiq>
721options		CONFIG_CLUTCH			# <config_clutch>
722options 	CONFIG_SCHED_AUTO_JOIN		# <config_sched_auto_join>
723
724options		CONFIG_SCHED_IDLE_IN_PLACE	# <config_sched_idle_in_place>
725options		CONFIG_SCHED_SFI		# <config_sched_sfi>
726options		CONFIG_GZALLOC			# <config_gzalloc>
727options		CONFIG_SCHED_DEFERRED_AST	# <config_sched_deferred_ast>
728
729# Enable allocation of contiguous physical memory through vm_map_enter_cpm()
730options		VM_CPM				# <vm_cpm>
731
732options	    CONFIG_SKIP_PRECISE_USER_KERNEL_TIME    # <config_skip_precise_user_kernel_time>
733
734#
735# Switch to disable cpu, wakeup and high memory watermark monitors
736#
737options 	CONFIG_NOMONITORS			# <config_nomonitors>
738
739options		MACH_KDP	    # KDP		# <mach_kdp>
740options		CONFIG_SERIAL_KDP   # KDP over serial	# <config_serial_kdp>
741options		CONFIG_KDP_INTERACTIVE_DEBUGGING	# <kdp_interactive_debugging>
742
743options 	CONFIG_TASKWATCH
744#
745# Kernel Power On Self Tests
746#
747options		CONFIG_XNUPOST				# <config_xnupost>
748
749#
750# Kernel proc reference instrumentation
751#
752options PROC_REF_DEBUG					# <proc_ref_debug>
753
754#
755# Kernel OS reason debug instrumentation
756#
757options OS_REASON_DEBUG					# <os_reason_debug>
758
759#
760# Kernel Voucher Attr Manager for Activity Trace
761#
762options 	CONFIG_ATM				# <config_atm>
763
764# Group related tasks together into coalitions
765options		CONFIG_COALITIONS			# <config_coalitions>
766
767# Enable support for sysdiagnose notifications
768options		CONFIG_SYSDIAGNOSE			# <config_sysdiagnose>
769
770# Configurable Security Restrictions
771options		CONFIG_CSR				# <config_csr>
772options		CONFIG_CSR_FROM_DT		# <config_csr_from_dt>
773
774#
775# Console options
776#
777options		SERIAL_CONSOLE	# bi-directional serial over UART
778options		VIDEO_CONSOLE	# uni-directional output over framebuffer
779
780#
781# Syscall options
782#
783options		CONFIG_REQUIRES_U32_MUNGING	# incoming U32 argument structures must be munged to match U64	# <config_requires_u32_munging>
784
785#
786# copyout() instrumentation
787#
788options		COPYOUT_SHIM			# Shim for copyout memory analysis via kext #<copyout_shim>
789
790#
791# Enable hardware correlation of mach absolute time
792# across intel/arm boundary
793options		CONFIG_MACH_BRIDGE_SEND_TIME #  # <config_mach_bridge_send_time>
794options		CONFIG_MACH_BRIDGE_RECV_TIME #  # <config_mach_bridge_recv_time>
795
796#
797# Telemetry for 32-bit process launch
798#
799options		CONFIG_32BIT_TELEMETRY # # <config_32bit_telemetry>
800
801options		CONFIG_QUIESCE_COUNTER # Support for _COMM_PAGE_CPU_QUIESCENT_COUNTER # <config_quiesce_counter>
802options		CONFIG_ARM_PFZ	# Support for PFZ on ARM # <config_arm_pfz>
803
804#
805# Sanitizers
806#
807options		CONFIG_KASAN		# <config_kasan>
808options		CONFIG_UBSAN		# <config_ubsan>
809options		CONFIG_KSANCOV		# <config_ksancov>
810
811# dark boot support
812options		CONFIG_DARKBOOT		# <config_darkboot>
813
814# support for processes delaying idle sleep for pending IO
815options		CONFIG_DELAY_IDLE_SLEEP # <config_delay_idle_sleep>
816
817# support for storing a 64-bit user supplied value in the proc structure
818options		CONFIG_PROC_UDATA_STORAGE # <config_proc_udata_storage>
819
820pseudo-device ksancov 1 init ksancov_init_dev # <config_ksancov>
821
822# debug instrumentation to catch code that leaves interrupts masked
823# for an excessive period of time
824options   INTERRUPT_MASKED_DEBUG # <interrupt_masked_debug>
825