nixy/kernel: set hardened kern ver and add unprivileged_userns_clone needed for chromium

This commit is contained in:
Asmir A 2025-08-30 10:27:56 +02:00
parent 9b58967454
commit 82e45af049
Signed by: asmir
GPG Key ID: 020C42B7A9ABA3E2

View File

@ -89,10 +89,11 @@ in
"amdgpu.sg_display=0"
"amdgpu.gttsize=2048"
];
kernelPackages = pkgs.linuxPackages_latest;
kernelPackages = pkgs.linuxPackages_hardened;
kernel.sysctl = {
"net.core.default_qdisc" = "fq";
"net.ipv4.tcp_congestion_control" = "bbr";
"kernel.unprivileged_userns_clone" = "1"; /* Needed with harderned kernel */
};
loader.efi.canTouchEfiVariables = true;
loader.systemd-boot = {