3
0
Fork 0
forked from mirrors/nixpkgs
Nix Packages collection
Go to file
Joachim Fasting 43fc394a5c
grsecurity module: disable EFI runtime services by default
Enabling EFI runtime services provides a venue for injecting code into
the kernel.

When grsecurity is enabled, we close this by default by disabling access
to EFI runtime services.  The upshot of this is that
/sys/firmware/efi/efivars will be unavailable by default (and attempts
to mount it will fail).

This is not strictly a grsecurity related option, it could be made into
a general option, but it seems to be of particular interest to
grsecurity users (for non-grsecurity users, there are other, more
immediate kernel injection attack dangers to contend with anyway).
2016-08-02 10:24:49 +02:00
.github PR template: go back to old option name for now 2016-06-29 21:44:05 +02:00
doc DOC: unstable packages names should append -unstable, not -git or -svn 2016-07-29 08:53:24 +02:00
lib lib: refactor nixpkgsVersion with fileContents 2016-08-01 18:35:26 +09:00
maintainers qt57: init at 5.7.0 2016-07-29 17:46:13 -05:00
nixos grsecurity module: disable EFI runtime services by default 2016-08-02 10:24:49 +02:00
pkgs Merge pull request #17420 from lukasepple/master 2016-08-02 10:19:15 +02:00
.gitignore kde5: consolidate packages into desktops/kde-5 2016-03-01 10:36:00 -06:00
.mention-bot Blacklist jhasse 2016-03-05 23:23:19 +01:00
.travis.yml travis: mount /run/user as 755 2016-07-18 23:09:04 -05:00
.version as always, no newline in .version 2016-02-28 23:39:38 +00:00
COPYING
default.nix Separate fix-point from config importing hacks and other impurities 2016-07-14 14:33:23 -07:00
README.md README.md: add code triagers badge 2016-07-22 15:00:55 +02:00

logo

Build Status Code Triagers Badge Issue Stats Issue Stats

Nixpkgs is a collection of packages for the Nix package manager. It is periodically built and tested by the hydra build daemon as so-called channels. To get channel information via git, add nixpkgs-channels as a remote:

% git remote add channels git://github.com/NixOS/nixpkgs-channels.git

For stability and maximum binary package support, it is recommended to maintain custom changes on top of one of the channels, e.g. nixos-16.03 for the latest release and nixos-unstable for the latest successful build of master:

% git remote update channels
% git rebase channels/nixos-16.03

For pull-requests, please rebase onto nixpkgs master.

NixOS linux distribution source code is located inside nixos/ folder.

Communication: