]> git.ipfire.org Git - ipfire-3.x.git/commitdiff
sysctl.conf: Turn on hard- and symlink protection
authorPeter Müller <peter.mueller@ipfire.org>
Tue, 5 May 2020 20:19:36 +0000 (22:19 +0200)
committerMichael Tremer <michael.tremer@ipfire.org>
Wed, 6 May 2020 10:25:23 +0000 (10:25 +0000)
This backports 29a8992b7228771fb2cfc68679596598fb01105a into IPFire 3.x

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
setup/setup.nm
setup/sysctl/kernel-hardening.conf

index 09d94e23de875c8c0d944039bef82dd6d2242f20..cc8454bfa35b37776b1c6ee0e37ce663ecd12b88 100644 (file)
@@ -5,7 +5,7 @@
 
 name       = setup
 version    = 3.0
-release    = 14
+release    = 15
 arch       = noarch
 
 groups     = Base Build System/Base
index 33e096c7ce5036574ab8d025b37efc284a995ee7..d92485d619c87efb4d59dc3afbfe1fa7a7922d58 100644 (file)
@@ -7,3 +7,7 @@ kernel.dmesg_restrict = 1
 # Improve KASLR effectiveness for mmap.
 vm.mmap_rnd_bits = 32
 vm.mmap_rnd_compat_bits = 16
+
+# Turn on hard- and symlink protection
+fs.protected_symlinks = 1
+fs.protected_hardlinks = 1