User:Pietinger/Tutorials/Manual kernel configuration

Tutorial: Manual kernel configuration
This tutorial gathers all links and informations needed for a manual kernel configuration. Only our Gentoo default sources will be used.

Basics
Many options in your kernel configuration depends on other options. Many options selects one or more other options. Sometimes a option is not visible whilst others are not enabled. My recommendation for later: Look into every  of an option you want to enable or disable.

You can search for kernel modules by pressing Typing a leading "CONFIG_" is not necessary.

You must enable all modules which kernel needs to find its root partition static <*> into your kernel and not as odule !

Never edit .config
I quote from this thread:

"Horrible things happen if you use a text editor on the kernel .config file. If you are lucky, you will get a kernel that won't build. If not, it may be broken in ways that nobody has ever seen before.

Use menuconfig and its search. Press / If the symbol you want is not found, press the 'z' key to toggle the display of hidden symbols. Search again.

The search will find it but you still can't select it. Read the help on the menu option. Pay attention to the Depends on: That boolean expression must be true before the item can be selected. Select other things so that your symbol can be selected.

Read the Selects: too. Now ask yourself if you would have got that right with your text editor?

The usual advice to someone who has used a text editor on the .config file is to throw it away and start it again."

More informations
If you have never done a manual kernel configuration you really should read all these before starting:
 * User:NeddySeagoon/PC_Boot_Process
 * Kernel/Gentoo_Kernel_Configuration_Guide
 * Kernel/Configuration
 * Short Explanation which kernel modules are needed for your harddisk: []

Before you start
1. Choose which kernel version you want and install it. This may help you: User:Pietinger/Tutorials/Selecting_a_convenient_kernel_version

2. Gather some informations: Boot with Handbook:AMD64/Installation/Media or any other Live Distribution CD and do (as user root):

Notice all "Kernel driver in use: XXXX" and all modules. You will need it later. For an INTEL system ask also:

Notice family,model and stepping.

Basic Settings (Must have)
1. Start with our Handbook:AMD64/Installation/Kernel. I am missing some important options. Add these for all 5.15.x LTS kernels

Do the same for a kernel 6.1 with one difference: "Choose SLAB allocator" has moved from "General Setup" to:

If you ask why not enabling "Randomize slab freelist" and "Harden slab freelist metadata" ... This you will get automatically if you harden your kernel with KSPP ;-)

In all Links you will get now, you will need only the chapter Kernel Configuration:

2. Links for configuring your Harddisk or NVMe:
 * SATA HD or SATA SSD: HDD and/or
 * NVMe: NVMe or
 * Old IDE or PATA: Kernel/Gentoo_Kernel_Configuration_Guide

3. This is also a must; you will have a black screen (= stuck at "Loading Linux 5.15.74-gentoo ...") without: Framebuffer

4. It is highly recommended to add your microcode for your CPU:
 * INTEL: [] or
 * AMD: AMD_microcode

5. Search with and your notice from lscpi -k for your ethernet module. Enable it (and disable all others because unneeded).

6. Search with and your notice from lscpi -k for additionally modules needed for your harddisk. If you miss a module kernel needs to find its root partition you will get a kernel panic and kernel cannot boot. For example: If you find a module named "vmd" you must enable it also:

(from: https://forums.gentoo.org/viewtopic-t-1156306-highlight-.html )

7. If you have a "high-end-CPU" with many logical cores you should check this kernel option and change it to your quantity of logical cores:

(from: https://forums.gentoo.org/viewtopic-p-8744767.html#8744767 )

8. If you have an USB-C and you search with for module thunderbolt you will find only "INTEL_WMI_THUNDERBOLT". But this is the wrong driver; you will need instead:

Enable only this option - dont enable write by debugfs in this submenu ! Maybe you want read this: https://docs.kernel.org/admin-guide/thunderbolt.html

9. At last we need: Libinput

This configuration should be able to boot your kernel. If you want to use a graphical environment you need:

Graphics adapter
Choose from these links:
 * Intel or
 * Nouveau or
 * Radeon or
 * AMDGPU

Sound and others
This should be done also:
 * ALSA
 * Power_management/Processor
 * Power_management/Guide
 * System_time

Optional settings

 * CDROM
 * Webcams
 * Motion
 * NTFS
 * KDE Vaults needs: Encfs

At last you can check all other modules you have in your lists from lspci -k and lsmod by searching with

Driver needs Firmware
Some kernel modules needs firmware (mostly Graphics adapter, WLAN and some Ethernet). If you use one of these kernel modules you should emerge Linux_firmware. Now you have two options for this module:

a) If you have configured your module as odule, then the kernel is able to load firmware for this module at boot-time from /lib/firmware, because all odules will be loaded after kernel has access to its root partition.

b) If you have configured your module static <*> into your kernel, then you must do a little bit more. These modules will be loaded before kernel has access to its root partition and therefore is not able to load firmware from /lib/firmware.

You would get an error message in your "dmesg" saying "Direct firmware load for xxxx/xxx failed with error -2". Therefore you must compile all needed firmware also into your kernel (example):

With these settings you will copy this firmware files INTO your kernel (when you compile your kernel with "make") and now kernel is able to load this firmware "from itself" without needing access to /lib/firmware at boot-time.

(Yes, it is the same place where you can also define microcode blob; if more than one firmware blobs must be loaded you separate them with a space).

Every Wiki article recommends to use option (a) because it is very easy. Option (b) is necessary if you want to build a monolithic kernel without module support, or if you have other reasons to build a module (which needs firmware) static into your kernel.

Starting with a clean environment
If you have done already some configurations and want to start from beginning you can clean up all with

The first command (distclean) deletes all old data - also your .config file !

Cheat Sheets
These are only valid if you have done a standard installation according to our Handbook:AMD64


 * Updating to a new kernel version:


 * Changing the configuration of your used kernel:

What does a "make oldconfig" ?
This will do three things:

1. Remove elements that are not anymore in the new kernel (if kernel developers have removed an existant option in the new kernel).

2. Keep the settings that are valid for the new kernel (takeover).

3. Ask you about all the new settings (only it there are new options; seldom with a change of the minor version; almost always with a new major version).

The prompt for new settings will show y/m/n/?

Yes makes the option built in, M makes it a module, No leaves it out and ? shows the help.

Not all four options are shown every time. If an option cannot be a module then of course M is missing.

One of y/n/m will be a capital letter. This is the default, it may or may not be what you need. You can take this default simply with.

Kconfig / KSPP ?
View the content of ... and examine if you have really enabled some security options. Take a look into User:Pietinger/Tutorials/Kernel_Hardening_with_KSPP

CONFIG_DEBUG ?
If you do this search you will see many lines:

Most of them are disabled with # CONFIG_* is not set - some are enabled. If experienced users tell you "dont enable debugging", they are usually correct. But not in every case, because for some settings you dont have an influence like all CONFIG_ARCH_* and CONFIG_HAVE_*. An Intel X86_64 system gives you these enabled:

Two more options depends on:

And if you hopefully harden your kernel with KSPP you will get automatically these (example X86_64 system):

Now you have 13 (18 with 6.1) DEBUG-options enabled and this is completely fine ! If you find any other lines with enabled DEBUG you should ask yourself why you have enabled them. A really bad example is:

Because I am paranoid I have in my kernel config also these, I DONT recommend:

Useful links

 * https://www.kernel.org/doc/html/latest/
 * https://kernelnewbies.org/LinuxChanges
 * https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git