From 84e4c6a9a55a611e73edd8c4d997ca78fb92add5 Mon Sep 17 00:00:00 2001 From: Gabriel Arazas Date: Sat, 28 Dec 2024 14:52:52 +0800 Subject: [PATCH] nixos/profiles/hardened: remove hardened kernel We'll place it at the host-level instead. --- modules/nixos/profiles/hardened.nix | 4 ---- 1 file changed, 4 deletions(-) diff --git a/modules/nixos/profiles/hardened.nix b/modules/nixos/profiles/hardened.nix index c3d934b6..dd12ab82 100644 --- a/modules/nixos/profiles/hardened.nix +++ b/modules/nixos/profiles/hardened.nix @@ -10,10 +10,6 @@ # Don't replace it mid-way! DON'T TURN LEFT!!!! security.protectKernelImage = true; - # Hardened config equals hardened kernel equals hardened co--approval from the - # security-minded people. - boot.kernelPackages = lib.mkOverride 500 pkgs.linuxKernel.packages.linux_6_6_hardened; - # Disable system console entirely. We don't need it so get rid of it. boot.kernel.sysctl."kernel.sysrq" = 0; }