mirror of
				https://github.com/TommyTran732/Fedora-CoreOS-Ignition.git
				synced 2025-11-04 11:08:35 +01:00 
			
		
		
		
	Enable module sig enforce and lockdown=confidentiality
Signed-off-by: Tommy <contact@tommytran.io>
This commit is contained in:
		@@ -12,6 +12,8 @@
 | 
			
		||||
      "nosmt=force",
 | 
			
		||||
      "l1d_flush=on",
 | 
			
		||||
      "spec_rstack_overflow=safe-ret",
 | 
			
		||||
      "module.sig_enforce=1",
 | 
			
		||||
      "lockdown=confidentiality",
 | 
			
		||||
      "random.trust_bootloader=off",
 | 
			
		||||
      "random.trust_cpu=off",
 | 
			
		||||
      "intel_iommu=on",
 | 
			
		||||
 
 | 
			
		||||
@@ -192,6 +192,8 @@ kernel_arguments:
 | 
			
		||||
    - nosmt=force
 | 
			
		||||
    - l1d_flush=on
 | 
			
		||||
    - spec_rstack_overflow=safe-ret
 | 
			
		||||
    - module.sig_enforce=1
 | 
			
		||||
    - lockdown=confidentiality
 | 
			
		||||
    - random.trust_bootloader=off
 | 
			
		||||
    - random.trust_cpu=off
 | 
			
		||||
    - intel_iommu=on
 | 
			
		||||
 
 | 
			
		||||
@@ -12,6 +12,8 @@
 | 
			
		||||
      "nosmt=force",
 | 
			
		||||
      "l1d_flush=on",
 | 
			
		||||
      "spec_rstack_overflow=safe-ret",
 | 
			
		||||
      "module.sig_enforce=1",
 | 
			
		||||
      "lockdown=confidentiality",
 | 
			
		||||
      "random.trust_bootloader=off",
 | 
			
		||||
      "random.trust_cpu=off",
 | 
			
		||||
      "intel_iommu=on",
 | 
			
		||||
 
 | 
			
		||||
@@ -256,6 +256,8 @@ kernel_arguments:
 | 
			
		||||
    - nosmt=force
 | 
			
		||||
    - l1d_flush=on
 | 
			
		||||
    - spec_rstack_overflow=safe-ret
 | 
			
		||||
    - module.sig_enforce=1
 | 
			
		||||
    - lockdown=confidentiality
 | 
			
		||||
    - random.trust_bootloader=off
 | 
			
		||||
    - random.trust_cpu=off
 | 
			
		||||
    - intel_iommu=on
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user