LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 02-05-2016, 04:56 AM   #1
BratPit
Member
 
Registered: Jan 2011
Posts: 250

Rep: Reputation: 100Reputation: 100
Thoughts about some kernel options in generic


On the occasion of stripping generic kernel to custom I'd like to ask some questions:

1. Option x32 ABI seems useless in distribution without recompilation all packages.

Some non invasive security option:

1. CONFIG_SECURITY_YAMA -Yama switching on /proc/sys/kernel/yama/ptrace_scope /default/ 1 .

https://www.kernel.org/doc/Documenta...urity/Yama.txt

2.CONFIG_DEVKMEM - should be disabled

3. CONFIG_DEBUG_RODATA- This makes sure that certain kernel data sections are marked to block modification

CONFIG_DEBUG_MODULE_RONX - the same for modules

4.CONFIG_CC_STACKPROTECTOR - to strong option from gcc 4.9 /there is 5.3/

5.proc/sys/kernel/kptr_restrict set to "1" to block the reporting of known kernel address leaks to users.

6.MAybe hardlink and symlink restrictions in /proc/sys/fs/ set to 1 but this may break some world writeble shares from samba.

It is only a suggestion to Pat.

Last edited by BratPit; 02-05-2016 at 06:07 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] setting up initrd / generic kernel in Grub2...can't load generic Ubunoob001 Slackware 12 03-20-2015 07:32 AM
[SOLVED] Kernel Panic with generic kernel on Dell poweredge 2850 Slackware 14.1 Dieselchair Slackware 44 08-22-2014 06:46 PM
kernel-generic and kernel-generic-smp ?? liuyug Slackware - Installation 5 06-01-2014 07:01 PM
slack 12, switch to generic kernel from huge kernel, using grub? jaguarrh Slackware 8 09-19-2007 06:29 AM
Kernel 2.6.2 options question - LOCKED options ? tvojvodi Linux - General 0 02-17-2004 04:23 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 04:49 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration