Skip to content
GitLab
Menu
Projects
Groups
Snippets
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Sign in / Register
Toggle navigation
Menu
Open sidebar
HardenedBSD
HardenedBSD
Commits
394e5e99
Commit
394e5e99
authored
May 23, 2021
by
Loic
Browse files
HBSD: prevent kernel reading by non-root users
Signed-off-by:
Loic
<
loic.f@hardenedbsd.org
>
parent
34225c25
Changes
1
Hide whitespace changes
Inline
Side-by-side
sys/conf/kern.post.mk
View file @
394e5e99
...
...
@@ -415,22 +415,22 @@ kernel-install: .PHONY
fi
.
endif
mkdir
-p
${DESTDIR}${KODIR}
${INSTALL}
-p
-m
5
55
-o
${KMODOWN}
-g
${KMODGRP}
${KERNEL_KO}
${DESTDIR}${KODIR}/
${INSTALL}
-p
-m
5
00
-o
${KMODOWN}
-g
${KMODGRP}
${KERNEL_KO}
${DESTDIR}${KODIR}/
.if
defined(DEBUG)
&&
!defined(INSTALL_NODEBUG)
&&
${MK_KERNEL_SYMBOLS}
!=
"no"
mkdir
-p
${DESTDIR}${KERN_DEBUGDIR}${KODIR}
${INSTALL}
-p
-m
5
55
-o
${KMODOWN}
-g
${KMODGRP}
${KERNEL_KO}.debug
${DESTDIR}${KERN_DEBUGDIR}${KODIR}/
${INSTALL}
-p
-m
5
00
-o
${KMODOWN}
-g
${KMODGRP}
${KERNEL_KO}.debug
${DESTDIR}${KERN_DEBUGDIR}${KODIR}/
.
endif
.if
defined(KERNEL_EXTRA_INSTALL)
${INSTALL}
-p
-m
5
55
-o
${KMODOWN}
-g
${KMODGRP}
${KERNEL_EXTRA_INSTALL}
${DESTDIR}${KODIR}/
${INSTALL}
-p
-m
5
00
-o
${KMODOWN}
-g
${KMODGRP}
${KERNEL_EXTRA_INSTALL}
${DESTDIR}${KODIR}/
.
endif
kernel-reinstall
:
@
-chflags
-R
noschg
${DESTDIR}${KODIR}
${INSTALL}
-p
-m
5
55
-o
${KMODOWN}
-g
${KMODGRP}
${KERNEL_KO}
${DESTDIR}${KODIR}
/
${INSTALL}
-p
-m
5
00
-o
${KMODOWN}
-g
${KMODGRP}
${KERNEL_KO}
${DESTDIR}${KODIR}
/
.if
defined(DEBUG)
&&
!defined(INSTALL_NODEBUG)
&&
${MK_KERNEL_SYMBOLS}
!=
"no"
${INSTALL}
-p
-m
5
55
-o
${KMODOWN}
-g
${KMODGRP}
${KERNEL_KO}.debug
${DESTDIR}${KERN_DEBUGDIR}${KODIR}/
${INSTALL}
-p
-m
5
00
-o
${KMODOWN}
-g
${KMODGRP}
${KERNEL_KO}.debug
${DESTDIR}${KERN_DEBUGDIR}${KODIR}/
.
endif
config.o env.o hints.o vers.o vnode_if.o
:
...
...
Write
Preview
Supports
Markdown
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment