Branch: refs/heads/master
  Home:   https://github.com/NixOS/nixpkgs
  Commit: 8c1f5afdf3570c18da7d40bc767115f1254253c5
      
https://github.com/NixOS/nixpkgs/commit/8c1f5afdf3570c18da7d40bc767115f1254253c5
  Author: Joachim Fasting <joach...@fastmail.fm>
  Date:   2016-12-06 (Tue, 06 Dec 2016)

  Changed paths:
    M nixos/modules/security/grsecurity.nix
    M pkgs/os-specific/linux/kernel/grsecurity-nixos-config.nix

  Log Message:
  -----------
  grsecurity: delay toggling of sysctls until system is up

We generally trust init, so there's little point in having these enabled
during early bootup; it accomplishes little except fill our logs with
spam.


  Commit: 071fbcda2462114ce2bcabb97e011083024774a7
      
https://github.com/NixOS/nixpkgs/commit/071fbcda2462114ce2bcabb97e011083024774a7
  Author: Joachim Fasting <joach...@fastmail.fm>
  Date:   2016-12-06 (Tue, 06 Dec 2016)

  Changed paths:
    M nixos/modules/security/grsecurity.nix
    M nixos/modules/security/grsecurity.xml
    M pkgs/os-specific/linux/kernel/grsecurity-nixos-config.nix

  Log Message:
  -----------
  grsecurity: enable optional sysfs restrictions

Fairly severe, but can be disabled at bootup via
grsec_sysfs_restrict=0. For the NixOS module we ensure that it is
disabled, for systemd compatibility.


  Commit: 31d79afbe5c0dc4f5343e842e40ada6738b1abb3
      
https://github.com/NixOS/nixpkgs/commit/31d79afbe5c0dc4f5343e842e40ada6738b1abb3
  Author: Joachim Fasting <joach...@fastmail.fm>
  Date:   2016-12-06 (Tue, 06 Dec 2016)

  Changed paths:
    M nixos/modules/security/grsecurity.xml

  Log Message:
  -----------
  grsecurity docs: note that pax_sanitize_slab defaults to fast


  Commit: 0e765c72e5c1f12d629d9d23d34f5fcb235e2833
      
https://github.com/NixOS/nixpkgs/commit/0e765c72e5c1f12d629d9d23d34f5fcb235e2833
  Author: Joachim Fasting <joach...@fastmail.fm>
  Date:   2016-12-06 (Tue, 06 Dec 2016)

  Changed paths:
    M nixos/modules/security/grsecurity.xml
    M pkgs/os-specific/linux/kernel/grsecurity-nixos-config.nix

  Log Message:
  -----------
  grsecurity: enable module hardening


  Commit: cc396697a6078d4137e1e1996989408d666fb3d8
      
https://github.com/NixOS/nixpkgs/commit/cc396697a6078d4137e1e1996989408d666fb3d8
  Author: Joachim Fasting <joach...@fastmail.fm>
  Date:   2016-12-06 (Tue, 06 Dec 2016)

  Changed paths:
    M pkgs/os-specific/linux/kernel/grsecurity-nixos-config.nix

  Log Message:
  -----------
  grsecurity: enable ability to lock in readonly mounts


  Commit: 9578299bbe5c4f78468fcad6e66c5f4a14c61eb2
      
https://github.com/NixOS/nixpkgs/commit/9578299bbe5c4f78468fcad6e66c5f4a14c61eb2
  Author: Joachim Fasting <joach...@fastmail.fm>
  Date:   2016-12-06 (Tue, 06 Dec 2016)

  Changed paths:
    M pkgs/os-specific/linux/kernel/linux-grsecurity.nix
    M pkgs/os-specific/linux/kernel/patches.nix

  Log Message:
  -----------
  grsecurity: 4.8.11-201611271225 -> 4.8.12-201612031658


Compare: https://github.com/NixOS/nixpkgs/compare/601b47ab94e3...9578299bbe5c
_______________________________________________
nix-commits mailing list
nix-comm...@lists.science.uu.nl
http://lists.science.uu.nl/mailman/listinfo/nix-commits

Reply via email to