Skip to content

Conversation

@raja-grewal
Copy link
Contributor

This pull request upgrades existing sysctl to now disable ptrace() usage by all processes.

Previously it was restricted to users with CAP_SYS_PTRACE and this upgrade is not expected to cause any more software breakages than the previous setting.

See #321 for further details.

Note this is essentially a resubmission of #242.

Changes

kernel.yama.ptrace_scope=2
to
kernel.yama.ptrace_scope=3

Mandatory Checklist

  • Legal agreements accepted. By contributing to this organisation, you acknowledge you have read, understood, and agree to be bound by these these agreements:

Terms of Service, Privacy Policy, Cookie Policy, E-Sign Consent, DMCA, Imprint

Optional Checklist

The following items are optional but might be requested in certain cases.

  • I have tested it locally
  • I have reviewed and updated any documentation if relevant
  • I am providing new code and test(s) for it

@raja-grewal raja-grewal marked this pull request as ready for review October 1, 2025 04:34
Copy link
Contributor

@ArrayBolt3 ArrayBolt3 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Merged into my arraybolt3/trixie branch with some minor typo fixes.

@adrelanos adrelanos merged commit 35fce26 into Kicksecure:master Oct 18, 2025
@raja-grewal raja-grewal deleted the stop_ptrace branch October 19, 2025 01:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants