X-Git-Url: https://jxself.org/git/?a=blobdiff_plain;f=kconfig-hardened-check.py;h=10c2997ad0802556b165df7925506340171f363c;hb=94a1a16b8115079117385630c7c91580b092715a;hp=a7a7d9cf05df6b867ed03c1c5052590a3e8460dd;hpb=0206c185f57805aeaed251f727e112fe2e8cc86e;p=kconfig-hardened-check.git diff --git a/kconfig-hardened-check.py b/kconfig-hardened-check.py index a7a7d9c..10c2997 100755 --- a/kconfig-hardened-check.py +++ b/kconfig-hardened-check.py @@ -32,9 +32,13 @@ # kpti=on # ssbd=force-on # -# N.B. Hardening sysctl's: -# net.core.bpf_jit_harden +# N.B. Hardening sysctls: +# net.core.bpf_jit_harden=2 # kptr_restrict=2 +# vm.unprivileged_userfaultfd=0 +# kernel.perf_event_paranoid=3 +# kernel.yama.ptrace_scope=1 +# kernel.unprivileged_bpf_disabled=1 import sys from argparse import ArgumentParser