nixos/hardened: don't set kernel.dmesg_restrict

Upstreamed in anthraxx/linux-hardened@e3d3f13ffb.
This commit is contained in:
Emily 2020-04-05 04:57:03 +01:00
parent cf1bce6a7a
commit 9da578a78f

View file

@ -76,9 +76,6 @@ with lib;
# (e.g., parent/child)
boot.kernel.sysctl."kernel.yama.ptrace_scope" = mkOverride 500 1;
# Restrict access to kernel ring buffer (information leaks)
boot.kernel.sysctl."kernel.dmesg_restrict" = mkDefault true;
# Hide kptrs even for processes with CAP_SYSLOG
boot.kernel.sysctl."kernel.kptr_restrict" = mkOverride 500 2;