1
0
mirror of https://github.com/tommytran732/Fedora-CoreOS-Ignition synced 2024-11-13 21:31:34 -05:00

Compare commits

..

2 Commits

Author SHA1 Message Date
3cb75ee460
Remove 5 seconds wait
Signed-off-by: Tommy <contact@tommytran.io>
2024-05-27 15:15:41 -07:00
4906ea33d8
Update kargs
Signed-off-by: Tommy <contact@tommytran.io>
2024-05-27 13:23:30 -07:00
5 changed files with 14 additions and 3 deletions

View File

@ -6,12 +6,15 @@
"shouldExist": [ "shouldExist": [
"mitigations=auto,nosmt", "mitigations=auto,nosmt",
"spectre_v2=on", "spectre_v2=on",
"spectre_bhi=on",
"spec_store_bypass_disable=on", "spec_store_bypass_disable=on",
"tsx=off", "tsx=off",
"kvm.nx_huge_pages=force", "kvm.nx_huge_pages=force",
"nosmt=force", "nosmt=force",
"l1d_flush=on", "l1d_flush=on",
"spec_rstack_overflow=safe-ret", "spec_rstack_overflow=safe-ret",
"gather_data_sampling=force",
"reg_file_data_sampling=on",
"random.trust_bootloader=off", "random.trust_bootloader=off",
"random.trust_cpu=off", "random.trust_cpu=off",
"intel_iommu=on", "intel_iommu=on",

View File

@ -190,12 +190,15 @@ kernel_arguments:
should_exist: should_exist:
- mitigations=auto,nosmt - mitigations=auto,nosmt
- spectre_v2=on - spectre_v2=on
- spectre_bhi=on
- spec_store_bypass_disable=on - spec_store_bypass_disable=on
- tsx=off - tsx=off
- kvm.nx_huge_pages=force - kvm.nx_huge_pages=force
- nosmt=force - nosmt=force
- l1d_flush=on - l1d_flush=on
- spec_rstack_overflow=safe-ret - spec_rstack_overflow=safe-ret
- gather_data_sampling=force
- reg_file_data_sampling=on
- random.trust_bootloader=off - random.trust_bootloader=off
- random.trust_cpu=off - random.trust_cpu=off
- intel_iommu=on - intel_iommu=on

2
kargs
View File

@ -14,4 +14,4 @@
# This file is just incase you want to quickly copy-paste the kernel arguments into `rpm-ostree kargs` # This file is just incase you want to quickly copy-paste the kernel arguments into `rpm-ostree kargs`
mitigations=auto,nosmt spectre_v2=on spec_store_bypass_disable=on tsx=off kvm.nx_huge_pages=force nosmt=force l1d_flush=on spec_rstack_overflow=safe-ret random.trust_bootloader=off random.trust_cpu=off intel_iommu=on amd_iommu=isolation_force efi=disable_early_pci_dma iommu=force iommu.passthrough=0 iommu.strict=1 slab_nomerge init_on_alloc=1 init_on_free=1 pti=on vsyscall=none ia32_emulation=0 page_alloc.shuffle=1 randomize_kstack_offset=on debugfs=off mitigations=auto,nosmt spectre_v2=on spectre_bhi=on spec_store_bypass_disable=on tsx=off kvm.nx_huge_pages=force nosmt=force l1d_flush=on spec_rstack_overflow=safe-ret gather_data_sampling=force reg_file_data_sampling=on random.trust_bootloader=off random.trust_cpu=off intel_iommu=on amd_iommu=force_isolation efi=disable_early_pci_dma iommu=force iommu.passthrough=0 iommu.strict=1 slab_nomerge init_on_alloc=1 init_on_free=1 pti=on vsyscall=none ia32_emulation=0 page_alloc.shuffle=1 randomize_kstack_offset=on debugfs=off lockdown=confidentiality module.sig_enforce=1 console=tty0 console=ttyS0,115200

View File

@ -6,12 +6,15 @@
"shouldExist": [ "shouldExist": [
"mitigations=auto,nosmt", "mitigations=auto,nosmt",
"spectre_v2=on", "spectre_v2=on",
"spectre_bhi=on",
"spec_store_bypass_disable=on", "spec_store_bypass_disable=on",
"tsx=off", "tsx=off",
"kvm.nx_huge_pages=force", "kvm.nx_huge_pages=force",
"nosmt=force", "nosmt=force",
"l1d_flush=on", "l1d_flush=on",
"spec_rstack_overflow=safe-ret", "spec_rstack_overflow=safe-ret",
"gather_data_sampling=force",
"reg_file_data_sampling=on",
"random.trust_bootloader=off", "random.trust_bootloader=off",
"random.trust_cpu=off", "random.trust_cpu=off",
"intel_iommu=on", "intel_iommu=on",
@ -237,7 +240,7 @@
"name": "postinst2.service" "name": "postinst2.service"
}, },
{ {
"contents": "[Unit]\nDescription=Download gVisor\nAfter=network-online.target\nBefore=docker.service\n\n[Service]\nUser=unpriv\nWorkingDirectory=/var/home/unpriv\nType=oneshot\nExecStart=/usr/bin/sleep 5\nExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/runsc\nExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/runsc.sha512\nExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/containerd-shim-runsc-v1\nExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/containerd-shim-runsc-v1.sha512\n\n[Install]\nWantedBy=multi-user.target\n", "contents": "[Unit]\nDescription=Download gVisor\nAfter=network-online.target\nBefore=docker.service\n\n[Service]\nUser=unpriv\nWorkingDirectory=/var/home/unpriv\nType=oneshot\nExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/runsc\nExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/runsc.sha512\nExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/containerd-shim-runsc-v1\nExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/containerd-shim-runsc-v1.sha512\n\n[Install]\nWantedBy=multi-user.target\n",
"enabled": true, "enabled": true,
"name": "gvisor-downloader.service" "name": "gvisor-downloader.service"
}, },

View File

@ -99,7 +99,6 @@ systemd:
User=unpriv User=unpriv
WorkingDirectory=/var/home/unpriv WorkingDirectory=/var/home/unpriv
Type=oneshot Type=oneshot
ExecStart=/usr/bin/sleep 5
ExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/runsc ExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/runsc
ExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/runsc.sha512 ExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/runsc.sha512
ExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/containerd-shim-runsc-v1 ExecStart=/usr/bin/curl -O https://storage.googleapis.com/gvisor/releases/release/latest/x86_64/containerd-shim-runsc-v1
@ -270,12 +269,15 @@ kernel_arguments:
should_exist: should_exist:
- mitigations=auto,nosmt - mitigations=auto,nosmt
- spectre_v2=on - spectre_v2=on
- spectre_bhi=on
- spec_store_bypass_disable=on - spec_store_bypass_disable=on
- tsx=off - tsx=off
- kvm.nx_huge_pages=force - kvm.nx_huge_pages=force
- nosmt=force - nosmt=force
- l1d_flush=on - l1d_flush=on
- spec_rstack_overflow=safe-ret - spec_rstack_overflow=safe-ret
- gather_data_sampling=force
- reg_file_data_sampling=on
- random.trust_bootloader=off - random.trust_bootloader=off
- random.trust_cpu=off - random.trust_cpu=off
- intel_iommu=on - intel_iommu=on