diff --git a/base/mitigations.nix b/base/mitigations.nix index 27168fb..b139d8a 100644 --- a/base/mitigations.nix +++ b/base/mitigations.nix @@ -2,16 +2,19 @@ { boot.blacklistedKernelModules = [ - "rxrpc" # dirtyfrag - "esp6" # dirtyfrag - "esp4" # dirtyfrag -]; -boot.extraModprobeConfig = '' - # dirtyfrag - install esp4 /bin/false - # dirtyfrag - install esp6 /bin/false - # dirtyfrag - install rxrpc /bin/false -''; + # copy.fail + "af_alg" + "algif_aead" + "algif_hash" + "algif_rng" + "algif_skcipher" + + # dirtyfrag / Fragnesia + "esp4" + "esp6" + "rxrpc" + + # PinTheft + "rds" + ]; }