aboutsummaryrefslogtreecommitdiff
path: root/modules/private/system
diff options
context:
space:
mode:
authorIsmaël Bouya <ismael.bouya@normalesup.org>2019-06-23 21:06:04 +0200
committerIsmaël Bouya <ismael.bouya@normalesup.org>2019-06-23 21:06:35 +0200
commit63cd475c66bc1021587660915b2c2a65520cc624 (patch)
tree5e588007f624aa0cd5d76be3d2b77bbfef377f57 /modules/private/system
parentaf3aeef298d176c4f01ef341bf9662dd362834e5 (diff)
downloadNix-63cd475c66bc1021587660915b2c2a65520cc624.tar.gz
Nix-63cd475c66bc1021587660915b2c2a65520cc624.tar.zst
Nix-63cd475c66bc1021587660915b2c2a65520cc624.zip
Add protection for latest CVE in linux kernel
Diffstat (limited to 'modules/private/system')
-rw-r--r--modules/private/system/eldiron.nix4
1 files changed, 4 insertions, 0 deletions
diff --git a/modules/private/system/eldiron.nix b/modules/private/system/eldiron.nix
index 48cba0c..df40187 100644
--- a/modules/private/system/eldiron.nix
+++ b/modules/private/system/eldiron.nix
@@ -17,6 +17,10 @@
17 17
18 imports = builtins.attrValues (import ../..); 18 imports = builtins.attrValues (import ../..);
19 19
20 boot.kernel.sysctl = {
21 # https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md
22 "net.ipv4.tcp_sack" = 0;
23 };
20 myServices.buildbot.enable = true; 24 myServices.buildbot.enable = true;
21 myServices.databases.enable = true; 25 myServices.databases.enable = true;
22 myServices.gitolite.enable = true; 26 myServices.gitolite.enable = true;