From ffce1bd60774208ff62f4a6b6f29376b7501004e Mon Sep 17 00:00:00 2001 From: h7x4 Date: Wed, 20 May 2026 16:33:07 +0900 Subject: [PATCH] base/mitigations: blacklist modules for copyfail and pintheft --- base/mitigations.nix | 27 +++++++++++++++------------ 1 file changed, 15 insertions(+), 12 deletions(-) diff --git a/base/mitigations.nix b/base/mitigations.nix index 27168fb..b139d8a 100644 --- a/base/mitigations.nix +++ b/base/mitigations.nix @@ -2,16 +2,19 @@ { boot.blacklistedKernelModules = [ - "rxrpc" # dirtyfrag - "esp6" # dirtyfrag - "esp4" # dirtyfrag -]; -boot.extraModprobeConfig = '' - # dirtyfrag - install esp4 /bin/false - # dirtyfrag - install esp6 /bin/false - # dirtyfrag - install rxrpc /bin/false -''; + # copy.fail + "af_alg" + "algif_aead" + "algif_hash" + "algif_rng" + "algif_skcipher" + + # dirtyfrag / Fragnesia + "esp4" + "esp6" + "rxrpc" + + # PinTheft + "rds" + ]; }