Branch: refs/heads/master
Home: https://github.com/NixOS/nixpkgs
Commit: 8c1f5afdf3570c18da7d40bc767115f1254253c5
https://github.com/NixOS/nixpkgs/commit/8c1f5afdf3570c18da7d40bc767115f1254253c5
Author: Joachim Fasting <joach...@fastmail.fm>
Date: 2016-12-06 (Tue, 06 Dec 2016)
Changed paths:
M nixos/modules/security/grsecurity.nix
M pkgs/os-specific/linux/kernel/grsecurity-nixos-config.nix
Log Message:
-----------
grsecurity: delay toggling of sysctls until system is up
We generally trust init, so there's little point in having these enabled
during early bootup; it accomplishes little except fill our logs with
spam.
Commit: 071fbcda2462114ce2bcabb97e011083024774a7
https://github.com/NixOS/nixpkgs/commit/071fbcda2462114ce2bcabb97e011083024774a7
Author: Joachim Fasting <joach...@fastmail.fm>
Date: 2016-12-06 (Tue, 06 Dec 2016)
Changed paths:
M nixos/modules/security/grsecurity.nix
M nixos/modules/security/grsecurity.xml
M pkgs/os-specific/linux/kernel/grsecurity-nixos-config.nix
Log Message:
-----------
grsecurity: enable optional sysfs restrictions
Fairly severe, but can be disabled at bootup via
grsec_sysfs_restrict=0. For the NixOS module we ensure that it is
disabled, for systemd compatibility.
Commit: 31d79afbe5c0dc4f5343e842e40ada6738b1abb3
https://github.com/NixOS/nixpkgs/commit/31d79afbe5c0dc4f5343e842e40ada6738b1abb3
Author: Joachim Fasting <joach...@fastmail.fm>
Date: 2016-12-06 (Tue, 06 Dec 2016)
Changed paths:
M nixos/modules/security/grsecurity.xml
Log Message:
-----------
grsecurity docs: note that pax_sanitize_slab defaults to fast
Commit: 0e765c72e5c1f12d629d9d23d34f5fcb235e2833
https://github.com/NixOS/nixpkgs/commit/0e765c72e5c1f12d629d9d23d34f5fcb235e2833
Author: Joachim Fasting <joach...@fastmail.fm>
Date: 2016-12-06 (Tue, 06 Dec 2016)
Changed paths:
M nixos/modules/security/grsecurity.xml
M pkgs/os-specific/linux/kernel/grsecurity-nixos-config.nix
Log Message:
-----------
grsecurity: enable module hardening
Commit: cc396697a6078d4137e1e1996989408d666fb3d8
https://github.com/NixOS/nixpkgs/commit/cc396697a6078d4137e1e1996989408d666fb3d8
Author: Joachim Fasting <joach...@fastmail.fm>
Date: 2016-12-06 (Tue, 06 Dec 2016)
Changed paths:
M pkgs/os-specific/linux/kernel/grsecurity-nixos-config.nix
Log Message:
-----------
grsecurity: enable ability to lock in readonly mounts
Commit: 9578299bbe5c4f78468fcad6e66c5f4a14c61eb2
https://github.com/NixOS/nixpkgs/commit/9578299bbe5c4f78468fcad6e66c5f4a14c61eb2
Author: Joachim Fasting <joach...@fastmail.fm>
Date: 2016-12-06 (Tue, 06 Dec 2016)
Changed paths:
M pkgs/os-specific/linux/kernel/linux-grsecurity.nix
M pkgs/os-specific/linux/kernel/patches.nix
Log Message:
-----------
grsecurity: 4.8.11-201611271225 -> 4.8.12-201612031658
Compare: https://github.com/NixOS/nixpkgs/compare/601b47ab94e3...9578299bbe5c
_______________________________________________
nix-commits mailing list
nix-comm...@lists.science.uu.nl
http://lists.science.uu.nl/mailman/listinfo/nix-commits