Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upDom0 should not have network drivers #3799
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment
Hide comment
|
Duplicate of #3656 |
marmarek
marked this as
a duplicate of
#3656
Apr 8, 2018
marmarek
closed this
Apr 8, 2018
andrewdavidwong
added
the
duplicate
label
Apr 8, 2018
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
DemiMarie commentedApr 8, 2018
•
edited
Edited 1 time
-
DemiMarie
edited Apr 8, 2018 (most recent)
Qubes OS version:
R4.0
Affected component(s):
Dom0 kernel
Steps to reproduce the behavior:
Run
find /lib/modules/4.14.18-1.pvops.qubes.x86_64/kernel/drivers/netExpected behavior:
No output, or an error because that directory does not exist
Actual behavior:
Many lines of output.
General notes:
Dom0 should not have a network connection. Therefore, it has no need for any of those drivers, and they increase attack surface in the event of a misconfiguration.
While these drivers must be built if we are to use common Dom0 and DomU kernels, we can delete them from the Dom0 kernel package.
Can these drivers be safely deleted?
Related issues:
#2743