Skip to content

Use slub_debug=FZ? #253

Description

@cynicsketch

https://tails.net/contribute/design/kernel_hardening/
https://gitlab.tails.boum.org/tails/tails/-/issues/19613
https://kspp.github.io/Recommended_Settings

slub_debug is not apparently used in Kicksecure.

Tails and KSPP, however, do recommend using slub_debug=FZ, which still used in Tails to this day.

The consensus is that slub debugging is not generally harmful because the "information leak" is only to root when kernel lockdown is enabled, and that it therefore doesn't matter that kernel pointer hashing is disabled because root should never be compromised.

Concerns of risk of slub debugging would therefore be overstated.

Not sure about any other contraindictions, though.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions