[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: hardening-check can detect whether kernel is protected or not



On 02/01/2019 17:48, Yves-Alexis Perez wrote:
> On Wed, 2019-01-02 at 17:37 +0100, Mikhail Morfikov wrote:
>> I have one question. Let's say I set the kernel options that are described
>> here[1]. Do I have to use DEB_BUILD_MAINT_OPTIONS or set any additional flags
>> in the debian/rules file to get some extra protection? Does the
>> DEB_BUILD_MAINT_OPTIONS variable do something in the case of building the
>> linux kernel?
> 
> No, DEB_BUILD_MAINT_OPTIONS is not used for that. If you want to tune the
> kernel configuration you need to follow the kernel handbook (
> https://kernel-team.pages.debian.net/kernel-handbook/ch-common-tasks.html#s4.2.3
> )
> 
> Most of the kernel options recommended on the KSPP page are either enabled or
> not relevant for a distribution kernel. There are some left which would be
> nice to have (like some gcc plugins) and unsupported for now, but that's all.
> 
Thanks for the info.


Attachment: signature.asc
Description: OpenPGP digital signature


Reply to: