public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
* [PATCH v2] sysctl.conf: Turn on BPF JIT hardening, if the JIT is enabled
@ 2021-04-09 19:13 Peter Müller
  2021-04-12  9:19 ` Michael Tremer
  0 siblings, 1 reply; 4+ messages in thread
From: Peter Müller @ 2021-04-09 19:13 UTC (permalink / raw)
  To: development

[-- Attachment #1: Type: text/plain, Size: 1485 bytes --]

The second version of this patch splits this up into different
architecture-specific sysctl config files, as i586 does not support BPF
JIT, hence the net.core.bpf_jit_harden does not exist on that
architecture.

Fixes: #12384

Signed-off-by: Peter Müller <peter.mueller(a)ipfire.org>
---
 config/etc/sysctl-aarch64.conf  | 2 ++
 config/etc/sysctl-armv5tel.conf | 2 ++
 config/etc/sysctl-x86_64.conf   | 3 +++
 3 files changed, 7 insertions(+)
 create mode 100644 config/etc/sysctl-aarch64.conf
 create mode 100644 config/etc/sysctl-armv5tel.conf

diff --git a/config/etc/sysctl-aarch64.conf b/config/etc/sysctl-aarch64.conf
new file mode 100644
index 000000000..9f840806d
--- /dev/null
+++ b/config/etc/sysctl-aarch64.conf
@@ -0,0 +1,2 @@
+# Turn on BPF JIT hardening, if the JIT is enabled.
+net.core.bpf_jit_harden = 2
diff --git a/config/etc/sysctl-armv5tel.conf b/config/etc/sysctl-armv5tel.conf
new file mode 100644
index 000000000..9f840806d
--- /dev/null
+++ b/config/etc/sysctl-armv5tel.conf
@@ -0,0 +1,2 @@
+# Turn on BPF JIT hardening, if the JIT is enabled.
+net.core.bpf_jit_harden = 2
diff --git a/config/etc/sysctl-x86_64.conf b/config/etc/sysctl-x86_64.conf
index 7384bed51..c7abecc5d 100644
--- a/config/etc/sysctl-x86_64.conf
+++ b/config/etc/sysctl-x86_64.conf
@@ -1,3 +1,6 @@
 # Improve KASLR effectiveness for mmap
 vm.mmap_rnd_bits = 32
 vm.mmap_rnd_compat_bits = 16
+
+# Turn on BPF JIT hardening, if the JIT is enabled.
+net.core.bpf_jit_harden = 2
-- 
2.26.2


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2021-04-13  9:47 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-04-09 19:13 [PATCH v2] sysctl.conf: Turn on BPF JIT hardening, if the JIT is enabled Peter Müller
2021-04-12  9:19 ` Michael Tremer
2021-04-12 17:58   ` Peter Müller
2021-04-13  9:47     ` Michael Tremer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox