Build a monolithic kernel
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- linux
- Domain
- build-system, operating-systems, security
Research direction
Read the kernel configuration changes described in this issue and the referenced SecureDrop issue #1886 first; no file or test is named. Done means the build uses built-in settings instead of modules, disables CONFIG_MODULES, and disables the blacklisted modules at build time.
Written by the indexing model from the issue text.
Description
At https://github.com/freedomofpress/kernel-builder/pull/45#issuecomment-2029144010 @thedeadliestcatch wrote:
I would strongly suggest considering building monolithic kernels with a minimal config. If you transition away from HVM to pvgrub, and even if you don't, it will be a good idea. Removing LKM support has several benefits in terms of reducing attack surface in the kernel for ROP and code injection scenarios (after all, LKM support comes with the implicit need for a dynamic linker in kernel space).
I replied:
This is a good point and something I started wondering about mid-last week, whether there was any benefit to building individual modules. I'll look into doing a monolithic build.
From what I can tell we just need to change all the m settings to y and then turn off CONFIG_MODULES. We should make sure that the blacklisted modules (see https://github.com/freedomofpress/securedrop/issues/1886) are disabled at build-time as well.
- Dominant language
- Python
- Stars
- 5
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Getting set up
- Ships a Dockerfile or Docker Compose file
- No pull request template
- No contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from freedomofpress/kernel-builder
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
6.18 kernels don't include metapackage in buildinfoPossibly taken @legoktm claimed this 8 days ago. Open
freedomofpress/kernel-builder#90 · 1 assignee ·
-
Difficulty 3/5 1-2 days Newbie friendliness 55/100
-
Difficulty 5/5 Over a week Newbie friendliness 18/100
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
All issues in freedomofpress/kernel-builder
Similar issues
-
docs(types): update the collection binding note now that typed collections shipped in pycubrid 1.9.0Opendocumentation priority: low size: S
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
cubrid-lab/sqlalchemy-cubrid#768 ·
Maintainers usually reply within 1 day
-
bug help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day
-
documentation
Difficulty 1/5 Under an hour Newbie friendliness 65/100
ansys/pydpf-core#3547 ·
Maintainers usually reply within 1 day
-
core
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
vectorize-io/hindsight#5457 ·
Maintainers usually reply within 1 day
-
[Bug]: LangChain drops OpenAI Responses text blocks from session recordingPossibly taken @ktz03 claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
volcengine/OpenViking#5806 ·
Maintainers usually reply within 1 day