port to new settings style

This commit is contained in:
Cyryl Płotnicki 2020-05-09 11:02:36 +01:00
parent 519a73d762
commit ad36f9455d
3 changed files with 50 additions and 5 deletions

View file

@ -31,7 +31,7 @@
};
hardware.nvidiaOptimus.disable = true;
hardware.nvidia.optimus_prime.enable = false;
hardware.nvidia.prime.sync.enable = false;
hardware.bumblebee.enable = false;
imports = [

View file

@ -20,10 +20,9 @@
hardware.bluetooth = {
enable = true;
package = pkgs.bluezFull;
extraConfig = ''
[General]
Enable=Source,Sink,Media,Socket
'';
config = {
General = { Enable = "Source,Sink,Media,Socket"; };
};
};
services.printing = {

46
nixos/security-kernel.nix Normal file
View file

@ -0,0 +1,46 @@
{ config, pkgs, ... }:
{
boot.kernelPatches = [ {
name = "cyplo-hardened";
patch = null;
extraConfig = ''
LOCKUP_DETECTOR y
HARDLOCKUP_DETECTOR y
BUG y
SECURITY_SELINUX_DISABLE n
STRICT_KERNEL_RWX y
DEBUG_CREDENTIALS y
DEBUG_NOTIFIERS y
DEBUG_SG y
SCHED_STACK_END_CHECK y
SHUFFLE_PAGE_ALLOCATOR y
SLUB_DEBUG y
PAGE_POISONING y
PAGE_POISONING_NO_SANITY y
PAGE_POISONING_ZERO y
SECURITY_SAFESETID y
PANIC_TIMEOUT -1
GCC_PLUGINS y
GCC_PLUGIN_LATENT_ENTROPY y
GCC_PLUGIN_STRUCTLEAK y
GCC_PLUGIN_STRUCTLEAK_BYREF_ALL y
GCC_PLUGIN_STACKLEAK y
GCC_PLUGIN_RANDSTRUCT y
GCC_PLUGIN_RANDSTRUCT_PERFORMANCE y
ACPI_CUSTOM_METHOD n
PROC_KCORE n
INET_DIAG n
'';
} ];
}