From a35e6f911fa032bb61a0e327465f3dcdf357d8e6 Mon Sep 17 00:00:00 2001 From: Denis Chevalier Date: Thu, 6 Aug 2026 12:31:45 +0200 Subject: update kernel command line --- etc.bash | 1 + etc/kernel/cmdline | 1 + etc/login.defs | 346 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 3 files changed, 348 insertions(+) create mode 100644 etc/kernel/cmdline create mode 100644 etc/login.defs diff --git a/etc.bash b/etc.bash index b4ebce9..da53128 100755 --- a/etc.bash +++ b/etc.bash @@ -2,6 +2,7 @@ sudo cp -rv etc/keyd/* /etc/keyd/ sudo cp -v etc/pacman.conf /etc/ +sudo cp -v etc/kernel/cmdline /etc/kernel/ sudo cp -v etc/pam.d/system-local-login /etc/pam.d/ sudo cp -v etc/pam.d/system-login /etc/pam.d/ sudo cp -v etc/login.defs /etc/ diff --git a/etc/kernel/cmdline b/etc/kernel/cmdline new file mode 100644 index 0000000..e226a97 --- /dev/null +++ b/etc/kernel/cmdline @@ -0,0 +1 @@ +root=PARTUUID=b7b36d6f-21ff-4f11-87a5-d07a84f4cc87 zswap.enabled=0 rootflags=subvol=@ rw rootfstype=btrfs init_on_alloc=1 init_on_free=1 slab_nomerge page_alloc.shuffle=1 vsyscall=none quiet splash diff --git a/etc/login.defs b/etc/login.defs new file mode 100644 index 0000000..8c96e09 --- /dev/null +++ b/etc/login.defs @@ -0,0 +1,346 @@ +# +# /etc/login.defs - Configuration control definitions for the shadow package. +# +# $Id$ +# +# NOTE: This file is adapted for the use on Arch Linux! +# Unsupported options due to the use of util-linux or PAM are removed. + +# +# Delay in seconds before being allowed another attempt after a login failure +# Note: when PAM is used, some modules may enforce a minimum delay (e.g. +# pam_unix(8) enforces a 2s delay) +# +FAIL_DELAY 3 + +# +# Enable display of unknown usernames when login(1) failures are recorded. +# +LOG_UNKFAIL_ENAB no + +# +# Limit the highest user ID number for which the lastlog entries should +# be updated. +# +# No LASTLOG_UID_MAX means that there is no user ID limit for writing +# lastlog entries. +# +#LASTLOG_UID_MAX + +# +# If defined, ":" delimited list of "message of the day" files to +# be displayed upon login. +# +MOTD_FILE +#MOTD_FILE /etc/motd:/usr/lib/news/news-motd + +# +# *REQUIRED* +# Directory where mailboxes reside, _or_ name of file, relative to the +# home directory. If you _do_ define both, MAIL_DIR takes precedence. +# +MAIL_DIR /var/spool/mail +#MAIL_FILE .mail + +# +# If defined, file which inhibits all the usual chatter during the login +# sequence. If a full pathname, then hushed mode will be enabled if the +# user's name or shell are found in the file. If not a full pathname, then +# hushed mode will be enabled if the file exists in the user's home directory. +# +HUSHLOGIN_FILE .hushlogin +#HUSHLOGIN_FILE /etc/hushlogins + +# +# *REQUIRED* The default PATH settings, for superuser and normal users. +# +# (they are minimal, add the rest in the shell startup files) +ENV_SUPATH PATH=/usr/local/sbin:/usr/local/bin:/usr/bin +ENV_PATH PATH=/usr/local/sbin:/usr/local/bin:/usr/bin + +# +# Terminal permissions +# +# TTYGROUP Login tty will be assigned this group ownership. +# TTYPERM Login tty will be set to this permission. +# +# If you have a write(1) program which is "setgid" to a special group +# which owns the terminals, define TTYGROUP as the number of such group +# and TTYPERM as 0620. Otherwise leave TTYGROUP commented out and +# set TTYPERM to either 622 or 600. +# +TTYGROUP tty +TTYPERM 0600 + +# Default initial "umask" value used by login(1) on non-PAM enabled systems. +# Default "umask" value for pam_umask(8) on PAM enabled systems. +# UMASK is also used by useradd(8) and newusers(8) to set the mode for new +# home directories if HOME_MODE is not set. +# 022 is the default value, but 027, or even 077, could be considered +# for increased privacy. There is no One True Answer here: each sysadmin +# must make up their mind. +UMASK 0077 + +# HOME_MODE is used by useradd(8) and newusers(8) to set the mode for new +# home directories. +# If HOME_MODE is not set, the value of UMASK is used to create the mode. +HOME_MODE 0700 + +# +# If "yes", the user must be listed as a member of the first gid 0 group +# in /etc/group (called "root" on most Linux systems) to be able to "su" +# to uid 0 accounts. If the group doesn't exist or is empty, no one +# will be able to "su" to uid 0. +# +SU_WHEEL_ONLY no + +# +# Min/max values for automatic uid selection in useradd(8) +# +UID_MIN 1000 +UID_MAX 60000 +# System accounts +SYS_UID_MIN 500 +SYS_UID_MAX 999 +# Extra per user uids +SUB_UID_MIN 100000 +SUB_UID_MAX 600100000 +SUB_UID_COUNT 65536 +# +# If set to yes, subordinate user ID entries in /etc/subuid are stored +# using the numeric user ID rather than the username. +#SUB_UID_STORE_BY_UID no + +# +# Enable deterministic subordinate UID allocation based on the user's UID. +# When set to "yes", subordinate UID ranges are calculated using a +# deterministic formula instead of searching for the next free range: +# +# WARNING: Do not mix deterministic and linear (default) allocation +# on the same system or across systems sharing /etc/subuid. Mixing +# methods will cause subordinate ID range conflicts and overlaps. +# +# Default: no +# +#SUB_UID_DETERMINISTIC no + +# +# Allow deterministic subordinate UID calculation to wrap around using +# modulo arithmetic when a UID would overflow the configured subordinate +# ID space. Only effective when SUB_UID_DETERMINISTIC is "yes". +# +# When disabled (default), any arithmetic overflow is a hard error, +# ensuring non-overlapping monotonic allocation. +# +# WARNING: SECURITY RISK - MAY CAUSE RANGE OVERLAPS AND PRIVILEGE ESCALATION! +# +# When enabled (WRAP MODE), the subordinate ID space is treated as a ring +# buffer. Uses modulo arithmetic to handle overflow. May cause range +# overlaps between users. +# +# Default: no +# +#UNSAFE_SUB_UID_DETERMINISTIC_WRAP no + +# +# Min/max values for automatic gid selection in groupadd(8) +# +GID_MIN 1000 +GID_MAX 60000 +# System accounts +SYS_GID_MIN 500 +SYS_GID_MAX 999 +# Extra per user group ids +SUB_GID_MIN 100000 +SUB_GID_MAX 600100000 +SUB_GID_COUNT 65536 +# +# If set to yes, subordinate group ID entries in /etc/subgid are stored +# using the numeric user ID rather than the username. +#SUB_GID_STORE_BY_UID no + +# +# Enable deterministic subordinate GID allocation based on the user's UID. +# When set to "yes", subordinate GID ranges are calculated using a +# deterministic formula instead of searching for the next free range: +# +# WARNING: Do not mix deterministic and linear (default) allocation +# on the same system or across systems sharing /etc/subgid. Mixing +# methods will cause subordinate ID range conflicts and overlaps. +# +# Default: no +# +#SUB_GID_DETERMINISTIC no + +# +# Allow deterministic subordinate GID calculation to wrap around using +# modulo arithmetic when a UID would overflow the configured subordinate +# ID space. Only effective when SUB_GID_DETERMINISTIC is "yes". +# +# When disabled (default), any arithmetic overflow is a hard error, +# ensuring non-overlapping monotonic allocation. +# +# WARNING: SECURITY RISK - MAY CAUSE RANGE OVERLAPS AND PRIVILEGE ESCALATION! +# +# When enabled (WRAP MODE), the subordinate ID space is treated as a ring +# buffer. Uses modulo arithmetic to handle overflow. May cause range +# overlaps between users. +# +# Default: no +# +#UNSAFE_SUB_GID_DETERMINISTIC_WRAP no + +# +# Max number of login(1) retries if password is bad +# +LOGIN_RETRIES 5 + +# +# Max time in seconds for login(1) +# +LOGIN_TIMEOUT 60 + +# +# Maximum number of attempts to change password if rejected (too easy) +# +PASS_CHANGE_TRIES 5 + +# +# Password strength controls: +# +# Warn about weak passwords (but still allow them) if you are root. +PASS_ALWAYS_WARN yes +# Minimum acceptable password length. +PASS_MIN_LEN 5 + +# +# Require password before chfn(1)/chsh(1) can make any changes. +# +CHFN_AUTH yes + +# +# Which fields may be changed by regular users using chfn(1) - use +# any combination of letters "frwh" (full name, room number, work +# phone, home phone). If not defined, no changes are allowed. +# For backward compatibility, "yes" = "rwh" and "no" = "frwh". +# +CHFN_RESTRICT rwh + +# +# Password prompt (%s will be replaced by user name). +# +# XXX - it doesn't work correctly yet, for now leave it commented out +# to use the default which is just "Password: ". +#LOGIN_STRING "%s's Password: " + +# +# Only works if compiled with ENCRYPTMETHOD_SELECT defined: +# If set to SHA256, SHA256-based algorithm will be used for encrypting password +# If set to SHA512, SHA512-based algorithm will be used for encrypting password +# If set to YESCRYPT, YESCRYPT-based algorithm will be used for encrypting password +# +# Note: if you use PAM, it is recommended to use a value consistent with +# the PAM modules configuration. +# +ENCRYPT_METHOD YESCRYPT + +# +# Only works if ENCRYPT_METHOD is set to SHA256 or SHA512. +# +# Define the number of SHA rounds. +# With a lot of rounds, it is more difficult to brute-force the password. +# However, more CPU resources will be needed to authenticate users if +# this value is increased. +# +# If not specified, the libc will choose the default number of rounds (5000), +# which is orders of magnitude too low for modern hardware. +# The values must be within the 1000-999999999 range. +# If only one of the MIN or MAX values is set, then this value will be used. +# If MIN > MAX, the highest value will be used. +# +#SHA_CRYPT_MIN_ROUNDS 5000 +#SHA_CRYPT_MAX_ROUNDS 5000 + +# +# Only works if ENCRYPT_METHOD is set to YESCRYPT. +# +# Define the YESCRYPT cost factor. +# With a higher cost factor, it is more difficult to brute-force the password. +# However, more CPU time and more memory will be needed to authenticate users +# if this value is increased. +# +# If not specified, a cost factor of 5 will be used. +# The value must be within the 1-11 range. +# +#YESCRYPT_COST_FACTOR 5 + +# +# Should login be allowed if we can't cd to the home directory? +# Default is no. +# +DEFAULT_HOME yes + +# +# The pwck(8) utility emits a warning for any system account with a home +# directory that does not exist. Some system accounts intentionally do +# not have a home directory. Such accounts may have this string as +# their home directory in /etc/passwd to avoid a spurious warning. +# +NONEXISTENT /nonexistent + +# +# If defined, this command is run when removing a user. +# It should remove any at/cron/print jobs etc. owned by +# the user to be removed (passed as the first argument). +# +#USERDEL_CMD /usr/sbin/userdel_local + +# +# Enable setting of the umask group bits to be the same as owner bits +# (examples: 022 -> 002, 077 -> 007) for non-root users, if the uid is +# the same as gid, and username is the same as the primary group name. +# +# This also enables userdel(8) to remove user groups if no members exist. +# +USERGROUPS_ENAB yes + +# +# If set to a non-zero number, the shadow utilities will make sure that +# groups never have more than this number of users on one line. +# This permits to support split groups (groups split into multiple lines, +# with the same group ID, to avoid limitation of the line length in the +# group file). +# +# 0 is the default value and disables this feature. +# +#MAX_MEMBERS_PER_GROUP 0 + +# +# If useradd(8) should create home directories for users by default (non +# system users only). +# This option is overridden with the -M or -m flags on the useradd(8) +# command-line. +# +#CREATE_HOME yes + +# +# Force use shadow, even if shadow passwd & shadow group files are +# missing. +# +#FORCE_SHADOW yes + +# +# Allow newuidmap and newgidmap when running under an alternative +# primary group. +# +#GRANT_AUX_GROUP_SUBIDS yes + +# +# Select the HMAC cryptography algorithm. +# Used in pam_timestamp module to calculate the keyed-hash message +# authentication code. +# +# Note: it is recommended to check hmac(3) to see the possible algorithms +# that are available in your system. +# +#HMAC_CRYPTO_ALGO SHA512 -- cgit