14ffb8edc0
pygoscelis: Default to CONFIG_BPF_UNPRIV_DEFAULT_OFF
2021-09-02 19:13:27 +02:00
5077c82174
pygoscelis: Bump to 5.14.0-T14s
2021-09-02 19:13:27 +02:00
80a06c3fab
pachyrhynchus-config: Support landlock
2021-09-02 00:15:48 +02:00
4ebf421944
pachyrhynchus-config: Compress modules with XZ
2021-09-02 00:13:58 +02:00
9f1dbfd415
pachyrhynchus-config: Bump to 5.14.0-gentoo
2021-09-02 00:12:03 +02:00
43f838264b
aptenodytes: Enable task stats and accounting for htop
2021-08-31 14:00:24 +02:00
0346dff326
aptenodytes: Bump to 5.14.0-gentoo
2021-08-31 14:00:24 +02:00
c12fde2f49
Revert "aptenodytes: Disable some RAID and SCSI lowlevel meta-knobs"
...
This reverts commit 9a84b2be758b49722ffadb3fb644391dfa47ba61 which broke
my boot process.
2021-08-31 14:00:24 +02:00
837d118875
aptenodytes: Bump to 5.13.13-gentoo
2021-08-29 12:47:02 +02:00
f632d4bca5
pygoscelis: Bump to 5.13.13-T14s
2021-08-26 23:41:05 +02:00
9a84b2be75
aptenodytes: Disable some RAID and SCSI lowlevel meta-knobs
2021-08-22 22:44:45 +02:00
6912f24065
aptenodytes: Disable CONFIG_FW_LOADER_USER_HELPER as suggested by for udev
2021-08-22 22:42:48 +02:00
5d8060d0e5
aptenodytes: Bump to 5.13.12-gentoo
2021-08-20 10:55:07 +02:00
c2e06d97d4
pachyrhynchus: Enable BPF_UNPRIV_DEFAULT_OFF
2021-08-20 10:02:33 +02:00
4698763f30
pachyrhynchus: Enable GENTOO_KERNEL_SELF_PROTECTION
2021-08-20 10:02:33 +02:00
7a2e2b14f8
pachyrhynchus: Bump to 5.13.12-gentoo
2021-08-20 10:02:32 +02:00
4cb80899dc
pygoscelis: Enable CURVE25519
2021-08-18 09:50:30 +02:00
b7ea8c6cae
pygoscelis: Disable TPM, TEE and others (disable TPM support, again)
...
This reverts the remaining options from earlier commit
4a4699674f58e72604f8eb1f74f23f253d19b801 because actually I do not trust
the TPM for my personal thread model enough and it doesn't support the
GPG ciphers I want to use. (Instead I use an external USB token again.)
2021-08-18 09:50:30 +02:00
621dc029cd
pygoscelis: Bump to 5.13.12-T14s
2021-08-18 09:50:29 +02:00
32e135d70d
pygoscelis: Enable CONFIG_GENTOO_KERNEL_SELF_PROTECTION
2021-08-12 16:53:25 +02:00
d54c235e88
pygoscelis: Bump to 5.13.10-T14s
2021-08-12 16:53:25 +02:00
297b2f5d2f
aptenodytes: Enable GENTOO_KERNEL_SELF_PROTECTION
2021-08-12 16:51:45 +02:00
9740b68fe7
aptenodytes: Bump to 5.13.10-gentoo
2021-08-12 16:51:45 +02:00
973dc59390
aptenodytes: Disable the automounter
2021-08-12 16:51:45 +02:00
6ab0b9cf35
aptenodytes: Convert FUSE into a module
2021-08-12 16:51:45 +02:00
e732a96cff
aptenodytes: Disable a compat CONFIG key
2021-08-12 16:51:45 +02:00
d6ab291c30
aptenodytes: Disable the ancient quota format v1
2021-08-12 16:51:44 +02:00
8c1c0c502e
aptenodytes: Convert USB mass storage support into a module
2021-08-12 16:51:44 +02:00
f300436802
aptenodytes: Disable USB3 support
2021-08-12 16:51:44 +02:00
e874a259e7
aptenodytes: Disable PINCTRL
2021-08-12 16:51:44 +02:00
7d5f6d3bc0
aptenodytes: Convert some builtins into modules
2021-08-12 16:51:44 +02:00
b86bf6bd9b
aptenodytes: Configure modules
...
- signing
- signing with SHA512
- compression with XZ
- trimming of unused symbols
2021-08-12 16:51:43 +02:00
62c523b776
aptenodytes: Enable modules for the dracut initramfs
...
Holy cow, how can s.o. be so ignorant to enforce modules?
2021-08-12 16:51:43 +02:00
1225a0a23b
aptenodytes: Disable PSTORE (probably unsupported)
2021-08-11 17:35:04 +02:00
25b19f0427
aptenodytes: Disable unused net HW support
2021-08-11 17:35:04 +02:00
d92c226594
aptenodytes: Disable SAS expander support
2021-08-11 17:35:04 +02:00
a2d1ee202a
aptenodytes: Disable support for ATA_FORCE
2021-08-11 17:35:04 +02:00
3d36750b14
aptenodytes: Drop unused TCP congestion control algorithms
2021-08-11 17:35:04 +02:00
3d133e1e5a
aptenodytes: Enable block device writeback throttling
2021-08-11 17:35:04 +02:00
c77f03e902
aptenodytes: Drop CONFIG_X86_REROUTE_FOR_BROKEN_BOOT_IRQS
2021-08-11 17:35:04 +02:00
e4d82e6488
aptenodytes: Bump to 5.13.9-gentoo
2021-08-11 17:35:04 +02:00
b9777de673
pygoscelis: Downgrade to 5.13.9-T14s
...
Back, and forth, and back, and..
2021-08-08 15:09:11 +02:00
e2f26190d1
aptenodytes: Bump to 5.13.8-gentoo
2021-08-07 12:13:33 +02:00
8a1cc382b6
aptenodytes: Enable CONFIG_USER_NS for podman
...
Actually for app-emulation/runc-1.0.0
2021-08-07 12:13:32 +02:00
23a96891a0
aptenodytes: Enable BRIDGE_VLAN_FILTERING for podman
...
Actually for net-misc/cni-plugins-0.9.1.
2021-08-07 12:13:32 +02:00
15a703c803
centro: Enable landlock
2021-08-03 21:21:23 +02:00
0931f47365
centro: Disable SECURITY_LOADPIN
2021-08-03 21:21:22 +02:00
7f78017654
centro: Enable HARDENED_USERCOPY_PAGESPAN
2021-08-03 21:21:22 +02:00
07af2bf453
centro: Disable misc section
2021-08-03 21:21:22 +02:00
2f5b81cb29
centro: Disable CONFIG_SQUASHFS
2021-08-03 21:21:22 +02:00