Skip to content

Set xen_privcmd.unrestricted in the workstation kernel opts, to account for XSA-482 patches. #79

@zenmonkeykstop

Description

@zenmonkeykstop

Fixes for XSA-482 restrict the privcmd module, which breaks core Qubes functionality (basically any inter-vm communication). XSA-482 doesn't impact Qubes security due to the lack of Secure Boot for VMs anyway, so we can remove restrictions on privcmd until a better fix is available.

(For the corresponding non-grsec Qubes fix, see QubesOS/qubes-linux-kernel#1256 )

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions