From b2bcae7f1f3f3569737bb194e23e9c572777a133 Mon Sep 17 00:00:00 2001 From: Mikael Voss Date: Thu, 7 Nov 2024 10:49:26 +0100 Subject: [PATCH] =?UTF-8?q?Update=206.10.13=E2=80=AF=E2=86=92=E2=80=AF6.11?= =?UTF-8?q?.4?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- config.nix | 2 ++ package.nix | 4 ++-- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/config.nix b/config.nix index 1f92ce3..cf09114 100644 --- a/config.nix +++ b/config.nix @@ -133,6 +133,7 @@ SLAB_MERGE_DEFAULT = false; SLAB_FREELIST_RANDOM = true; SLAB_FREELIST_HARDENED = true; + SLAB_BUCKETS = true; SLAB_CANARY = true; SLUB_CPU_PARTIAL = true; RANDOM_KMALLOC_CACHES = true; @@ -175,6 +176,7 @@ FORTIFY_SOURCE = true; SECURITY_DMESG_RESTRICT = true; + PROC_MEM_FORCE_PTRACE = true; SECURITY_PERF_EVENTS_RESTRICT = true; SECURITY_TIOCSTI_RESTRICT = true; SECURITY = true; diff --git a/package.nix b/package.nix index f398a0e..d4e993d 100644 --- a/package.nix +++ b/package.nix @@ -86,7 +86,7 @@ in stdenv.mkDerivation (finalAttrs: { __structuredAttrs = true; pname = "linux-hardened"; - version = "6.10.13-hardened1"; + version = "6.11.4-hardened1"; modDirVersion = lib.versions.pad 3 finalAttrs.version; @@ -94,7 +94,7 @@ in stdenv.mkDerivation (finalAttrs: { owner = "anthraxx"; repo = finalAttrs.pname; rev = "v${finalAttrs.version}"; - hash = "sha256-XWrX1jlUv1cwGzCz8Qqaa1mbetvPWY2ivPLyw6Fx54c="; + hash = "sha256-qXwYvsOZnwvPWzMFychFTdZcturwrSNFv2LiguutayE="; }; depsBuildBuild = [