nixy/kernel: set hardened kern ver and add unprivileged_userns_clone needed for chromium

This commit is contained in:
2025-08-30 10:27:56 +02:00
parent 9b58967454
commit 82e45af049

View File

@@ -89,10 +89,11 @@ in
"amdgpu.sg_display=0"
"amdgpu.gttsize=2048"
];
kernelPackages = pkgs.linuxPackages_latest;
kernelPackages = pkgs.linuxPackages_hardened;
kernel.sysctl = {
"net.core.default_qdisc" = "fq";
"net.ipv4.tcp_congestion_control" = "bbr";
"kernel.unprivileged_userns_clone" = "1"; /* Needed with harderned kernel */
};
loader.efi.canTouchEfiVariables = true;
loader.systemd-boot = {