# TODO: draft of security hardening sysctls:
# what about bpf_jit_enable?
# vm.mmap_min_addr has a good value
# TODO: draft of security hardening sysctls:
# what about bpf_jit_enable?
# vm.mmap_min_addr has a good value
# and since v5.11 it enables unprivileged userfaultfd for user-mode only.
l += [SysctlCheck('harden_userspace', 'kspp', 'fs.protected_symlinks', '1')]
# and since v5.11 it enables unprivileged userfaultfd for user-mode only.
l += [SysctlCheck('harden_userspace', 'kspp', 'fs.protected_symlinks', '1')]