Re: F44 Change Proposal: Mitigate vulnerabilities/attacks by enabling kernel.kptr_restrict and net.core.bpf_jit_harden by default, and by obsoleting a package that risks to accidentally disable kernel.yama.ptrace_scope by default [SystemWide]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Christopher,

On Mon, Sep 08, 2025 at 06:11:51PM +0000, Christopher Klooz wrote:
> The below change proposal was accidentally sent to the mailing list under a wrong name.

And the new name is so long I originally missed this. Sorry.

The long name also suggests (at least to me) that this is really
multiple proposals. It seems to suggest three different policy
changes. One for logging and processing kernel addresses, impacting
programs needing to inspect e.g. /proc/kallsyms. One for BPF using
packages, impacting performance and power consumption. And one for
tracing/profiling/debugging user space programs, impacting whether
installing such a package works out of the box or not.

It would be good to turn this into three separate proposals with input
from some of the affected package maintainers to come up with a good
way to set these values to make sure when you install a package it
works out of the box. I don't think just asking FESCO to pick a
default value, force the systemd package maintainers to set that
and then hope users will read some documentation to enable their
installed packages to work again is a great policy.

Cheers,

Mark
-- 
_______________________________________________
devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Users]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]

  Powered by Linux