Skip to content

[FEAT] Additional Kernel Boot Parameters #1393

@raja-grewal

Description

@raja-grewal

Benefit

I was browsing through the current kernel boot parameters and potentially noticed a few ones that we could consider maybe adding to the config. From those below, some could certainly be optional while others might be candidates for enabling by default after comprehensive testing.

Solution

Candidates for inclusion by default are: kfence.sample_interval=100, vdso32=0, cfi=kcfi, efi_pstore.pstore_disable=1, erst_disable. Candidates for optional inclusion are: ipv6.disable=1.

Alternatives

Retain current kernel boot parameters without modification.

Declaration

  • I agree to follow this project's Code of Conduct.
  • I declare that this is not a request for alternate community messaging or social platforms.
  • I declare that I have read the secureblue website and my feature request is in-scope.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions