From 94a1a16b8115079117385630c7c91580b092715a Mon Sep 17 00:00:00 2001 From: Alexander Popov Date: Thu, 22 Aug 2019 13:34:49 +0300 Subject: [PATCH] Add some new sysctls (to remember them) --- kconfig-hardened-check.py | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/kconfig-hardened-check.py b/kconfig-hardened-check.py index a7a7d9c..10c2997 100755 --- a/kconfig-hardened-check.py +++ b/kconfig-hardened-check.py @@ -32,9 +32,13 @@ # kpti=on # ssbd=force-on # -# N.B. Hardening sysctl's: -# net.core.bpf_jit_harden +# N.B. Hardening sysctls: +# net.core.bpf_jit_harden=2 # kptr_restrict=2 +# vm.unprivileged_userfaultfd=0 +# kernel.perf_event_paranoid=3 +# kernel.yama.ptrace_scope=1 +# kernel.unprivileged_bpf_disabled=1 import sys from argparse import ArgumentParser -- 2.31.1