mirror of
https://github.com/Kicksecure/security-misc.git
synced 2025-07-11 16:31:12 +07:00
no longer set kernel.unprivileged_userns_clone=0
because it breaks too much fixes https://github.com/Kicksecure/security-misc/issues/274
This commit is contained in:
@ -142,10 +142,11 @@ kernel.sysrq=0
|
||||
## https://github.com/Kicksecure/security-misc/pull/263
|
||||
## https://github.com/Kicksecure/security-misc/issues/274
|
||||
##
|
||||
## KSPP=partial
|
||||
## KSPP sets sysctls kernel.unprivileged_userns_clone=0 and user.max_user_namespaces=0.
|
||||
## KSPP=no
|
||||
## KSPP sets user.max_user_namespaces=0 sysctl, a Linux mainline, stricter setting.
|
||||
##
|
||||
kernel.unprivileged_userns_clone=0
|
||||
## kernel.unprivileged_userns_clone is a Debian specific kernel feature. Not Linux mainline.
|
||||
#kernel.unprivileged_userns_clone=0
|
||||
## Uncomment the following sysctl to entirely disable user namespaces.
|
||||
#user.max_user_namespaces=0
|
||||
|
||||
|
Reference in New Issue
Block a user