From d102ec19972865032f12f90bffe3e592546f0267 Mon Sep 17 00:00:00 2001 From: Raja Grewal Date: Mon, 5 Aug 2024 15:07:56 +1000 Subject: [PATCH] Enable `kfence.sample_interval=100` --- README.md | 5 ++--- etc/default/grub.d/40_kernel_hardening.cfg | 2 +- 2 files changed, 3 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index a187056..16f7df3 100644 --- a/README.md +++ b/README.md @@ -147,9 +147,8 @@ configuration file. - Provide the option to modify machine check exception handler. -- Provide the option to enable the kernel Electric-Fence sampling-based memory - safety error detector which can identify heap out-of-bounds access, use-after-free, - and invalid-free errors. +- Enable the kernel Electric-Fence sampling-based memory safety error detector + which can identify heap out-of-bounds access, use-after-free, and invalid-free errors. - Provide the option to disable 32 bit vDSO mappings. diff --git a/etc/default/grub.d/40_kernel_hardening.cfg b/etc/default/grub.d/40_kernel_hardening.cfg index fab54cf..bbfee13 100644 --- a/etc/default/grub.d/40_kernel_hardening.cfg +++ b/etc/default/grub.d/40_kernel_hardening.cfg @@ -134,7 +134,7 @@ GRUB_CMDLINE_LINUX="$GRUB_CMDLINE_LINUX debugfs=off" ## ## https://www.kernel.org/doc/html/latest/dev-tools/kfence.html ## -#GRUB_CMDLINE_LINUX="$GRUB_CMDLINE_LINUX kfence.sample_interval=100" +GRUB_CMDLINE_LINUX="$GRUB_CMDLINE_LINUX kfence.sample_interval=100" ## Disable x86 Virtual Dynamic Shared Object (vDSO) mappings. ##