nixy/kernel: set hardened kern ver and add unprivileged_userns_clone needed for chromium

This commit is contained in:
Asmir A 2025-08-30 10:27:56 +02:00
parent 9b58967454
commit 82e45af049
Signed by: asmir
GPG Key ID: 020C42B7A9ABA3E2

View File

@ -89,10 +89,11 @@ in
"amdgpu.sg_display=0" "amdgpu.sg_display=0"
"amdgpu.gttsize=2048" "amdgpu.gttsize=2048"
]; ];
kernelPackages = pkgs.linuxPackages_latest; kernelPackages = pkgs.linuxPackages_hardened;
kernel.sysctl = { kernel.sysctl = {
"net.core.default_qdisc" = "fq"; "net.core.default_qdisc" = "fq";
"net.ipv4.tcp_congestion_control" = "bbr"; "net.ipv4.tcp_congestion_control" = "bbr";
"kernel.unprivileged_userns_clone" = "1"; /* Needed with harderned kernel */
}; };
loader.efi.canTouchEfiVariables = true; loader.efi.canTouchEfiVariables = true;
loader.systemd-boot = { loader.systemd-boot = {