linux-hardened: Disable GCC_PLUGIN_RANDSTRUCT
This commit is contained in:
parent
48f0389bf8
commit
5dda1324be
@ -97,11 +97,6 @@ ${optionalString (versionAtLeast version "4.11") ''
|
|||||||
GCC_PLUGIN_STRUCTLEAK y # A port of the PaX structleak plugin
|
GCC_PLUGIN_STRUCTLEAK y # A port of the PaX structleak plugin
|
||||||
''}
|
''}
|
||||||
|
|
||||||
${optionalString (versionAtLeast version "4.13") ''
|
|
||||||
GCC_PLUGIN_RANDSTRUCT y # A port of the PaX randstruct plugin
|
|
||||||
GCC_PLUGIN_RANDSTRUCT_PERFORMANCE y
|
|
||||||
''}
|
|
||||||
|
|
||||||
# Disable various dangerous settings
|
# Disable various dangerous settings
|
||||||
ACPI_CUSTOM_METHOD n # Allows writing directly to physical memory
|
ACPI_CUSTOM_METHOD n # Allows writing directly to physical memory
|
||||||
PROC_KCORE n # Exposes kernel text image layout
|
PROC_KCORE n # Exposes kernel text image layout
|
||||||
|
Loading…
x
Reference in New Issue
Block a user