nixos: Set mmap ASLR entropy to a safe default on AArch64
The eval-time access to kernel config is not enabled for any nixpkgs-packaged kernels by default since it requires IFD and so all kernels (including nixos-apple-silicon and rpi kernel) will end up with the max of 33, which will lead to the systemd-sysctl service failing. Additionally, there are factors other than the pagesize which can cause 33 to be an invalid argument.
This commit is contained in:
@@ -96,18 +96,10 @@ in
|
||||
# Maximise address space randomisation.
|
||||
"vm.mmap_rnd_bits" = lib.mkMerge [
|
||||
(lib.mkIf pkgs.stdenv.hostPlatform.isAarch64 (
|
||||
let
|
||||
kernel = config.boot.kernelPackages.kernel;
|
||||
isYes = kernel.config.isYes or (_: false);
|
||||
in
|
||||
lib.mkDefault (
|
||||
if isYes "ARM64_64K_PAGES" then
|
||||
29
|
||||
else if isYes "ARM64_16K_PAGES" then
|
||||
31
|
||||
else
|
||||
33
|
||||
)
|
||||
# Ideally, we'd want to set this to 33 on 4K pagesize
|
||||
# kernels, but some vendor kernels e.g. linux_rpi can
|
||||
# do a maximum of 24.
|
||||
lib.mkDefault 24
|
||||
))
|
||||
(lib.mkIf pkgs.stdenv.hostPlatform.isx86_64 (lib.mkDefault 32))
|
||||
];
|
||||
|
||||
Reference in New Issue
Block a user