summaryrefslogtreecommitdiff
path: root/nonsystemd/openrc/sysctl.conf
diff options
context:
space:
mode:
Diffstat (limited to 'nonsystemd/openrc/sysctl.conf')
-rw-r--r--nonsystemd/openrc/sysctl.conf27
1 files changed, 24 insertions, 3 deletions
diff --git a/nonsystemd/openrc/sysctl.conf b/nonsystemd/openrc/sysctl.conf
index de238b937..0e09c78af 100644
--- a/nonsystemd/openrc/sysctl.conf
+++ b/nonsystemd/openrc/sysctl.conf
@@ -11,14 +11,31 @@
# of values and keys.
# kernel.sysrq = 16
+# Append the PID to the core filename
+# kernel.core_uses_pid = 1
+
# Source route verification
-net.ipv4.conf.all.rp_filter = 1
+#net.ipv4.conf.default.rp_filter = 2
+#net.ipv4.conf.*.rp_filter = 2
+-net.ipv4.conf.all.rp_filter = 1
# Do not accept source routing
-net.ipv4.conf.all.accept_source_route = 0
+net.ipv4.conf.default.accept_source_route = 0
+# net.ipv4.conf.*.accept_source_route = 0
+-net.ipv4.conf.all.accept_source_route = 0
# Promote secondary addresses when the primary address is removed
-net.ipv4.conf.all.promote_secondaries = 1
+#net.ipv4.conf.default.promote_secondaries = 1
+#net.ipv4.conf.*.promote_secondaries = 1
+-net.ipv4.conf.all.promote_secondaries = 1
+
+# ping(8) without CAP_NET_ADMIN and CAP_NET_RAW
+# The upper limit is set to 2^31-1. Values greater than that get rejected by
+# the kernel because of this definition in linux/include/net/ping.h:
+# #define GID_T_MAX (((gid_t)~0U) >> 1)
+# That's not so bad because values between 2^31 and 2^32-1 are reserved on
+# systemd-based systems anyway: https://systemd.io/UIDS-GIDS.html#summary
+-net.ipv4.ping_group_range = 0 2147483647
# Fair Queue CoDel packet scheduler to fight bufferbloat
net.core.default_qdisc = fq_codel
@@ -26,3 +43,7 @@ net.core.default_qdisc = fq_codel
# Enable hard and soft link protection
fs.protected_hardlinks = 1
fs.protected_symlinks = 1
+
+# Enable regular file and FIFO protection
+fs.protected_regular = 1
+fs.protected_fifos = 1