⋄ drop all EDAC (I guess it won’t be of use anyways ⋄ disable all CONFIG_SECURITY_NETWORK (no SELINUX et al.) ⋄ enable CONFIG_SLAB_FREELIST_HARDENED ⋄ enable CONFIG_RESET_ATTACK_MITIGATION ⋄ enable CONFIG_GCC_PLUGIN_STRUCTLEAK_BYREF_ALL ⋄ enable ZSTD
Kernel config files === Syntax: ${hostname}-config
Description