projects/kspp/README.md
The Kernel Self Protection Project is a community effort to harden the upstream Linux kernel by eliminating classes of vulnerabilities.
Many similar protections have existed in other projects, but have yet to have been upstreamed. Since Moby is a consumer of the Linux kernel and aims to be the most secure distro it can be, it is in our maintainers' best interests to collaborate on upstream Linux security measures.
Near-term:
kernel_config and sysctl settings with the
KSPP recommendations -
we should continue to track these
check_kernel_config.sh)Long-term: