Page MenuHomeFreeBSD

Add destructive dtrace to bsdinstall hardening menu
ClosedPublic

Authored by code.jpe_gmail.com on Sep 23 2017, 2:13 PM.

Details

Summary

Very few users require destructive dtrace, so it is a good candidate for the installer hardening menu. It is currently enabled by default since this was the historic state before the tuneable was introduced.

Diff Detail

Repository
rS FreeBSD src repository
Lint
Automatic diff as part of commit; lint not applicable.
Unit
Automatic diff as part of commit; unit tests not applicable.

Event Timeline

allanjude added inline comments.Oct 2 2017, 4:32 AM
usr.sbin/bsdinstall/scripts/hardening
50 ↗(On Diff #33355)

Might be better worded as "Disallow DTrace destructive-mode"

code.jpe_gmail.com marked an inline comment as done.
gnn accepted this revision.Nov 13 2017, 1:33 AM
This revision is now accepted and ready to land.Nov 13 2017, 1:33 AM
This revision was automatically updated to reflect the committed changes.