]> gitweb.fluxo.info Git - puppet-nodo.git/commitdiff
Adds nodo::subsystem::sysctl::unprivileged_bpf_disabled
authorSilvio Rhatto <rhatto@riseup.net>
Mon, 8 Jan 2018 00:49:26 +0000 (22:49 -0200)
committerSilvio Rhatto <rhatto@riseup.net>
Mon, 8 Jan 2018 00:49:26 +0000 (22:49 -0200)
manifests/subsystem/sysctl/unprivileged_bpf_disabled.pp [new file with mode: 0644]

diff --git a/manifests/subsystem/sysctl/unprivileged_bpf_disabled.pp b/manifests/subsystem/sysctl/unprivileged_bpf_disabled.pp
new file mode 100644 (file)
index 0000000..f82bfc9
--- /dev/null
@@ -0,0 +1,6 @@
+# See https://www.debian.org/security/2017/dsa-4073
+class nodo::subsystem::sysctl::unprivileged_bpf_disabled() {
+  nodo::subsystem::sysctl::entry { 'kernel.unprivileged_bpf_disabled':
+    value => '1',
+  }
+}