Disable rxrpc, kafs, af_key, esp4, esp6 across all systems that enable metacfg.base. None of them are used on these hosts, and they have a history of CVEs — blacklisting reduces kernel attack surface. |
||
|---|---|---|
| .. | ||
| darwin | ||
| home | ||
| nixos | ||
| common.nix | ||
Disable rxrpc, kafs, af_key, esp4, esp6 across all systems that enable metacfg.base. None of them are used on these hosts, and they have a history of CVEs — blacklisting reduces kernel attack surface. |
||
|---|---|---|
| .. | ||
| darwin | ||
| home | ||
| nixos | ||
| common.nix | ||