MEDIUM RHCOS (Node) M24: CoreOS Kernel Arguments P3

Pending Compare Branch Scanned: 2026-08-12

Remediation required. This group (6 checks) fails on vanilla RHCOS 10.2 and requires MachineConfig remediation. Verified on cnfdt16 (OCP 5.0, RHCOS 10.2) with compliance-operator v1.8.2.

Overview

Configures RHCOS kernel boot arguments for security hardening. Enables page table isolation (PTI), vsyscall emulation restrictions, page poisoning, audit subsystem, and USB device restrictions.

Profile: NIST 800-53 Moderate (rhcos4-moderate)

Compliance Checks

Check Description
audit-backlog-limit-kernel-argument Set audit backlog limit via kernel arg
audit-option Enable audit=1 kernel argument
nousb-kernel-argument Disable USB via kernel argument
page-poison-kernel-argument Enable page poisoning
pti-kernel-argument Enable page table isolation (Meltdown mitigation)
vsyscall-kernel-argument Set vsyscall=none (disable legacy syscall interface)

Verification

oc debug node/<node> -- chroot /host cat /proc/cmdline | tr ' ' '\n' | grep -E 'audit|nousb|page_poison|pti|vsyscall'

Upstream Proposal

The following changes could eliminate the need for MachineConfig remediation. Items are categorized by recommended scope:

audit=1, audit_backlog_limit=8192, pti=on, page_poison=1, vsyscall=none All OCP Low
openshift/os Default kernel command line arguments View Proposed Change
KSPP-recommended boot parameters. Enable audit subsystem, kernel page table isolation, memory poisoning, vsyscall elimination.
Scope: audit=1 and KSPP kernel args (pti, page_poison, vsyscall=none) are universally beneficial security defaults with negligible performance impact.
nousb RAN High
openshift/os (opt-in only) Optional hardening profile kernel arg
Disables USB entirely. Prevents USB-based attacks but breaks BMC KVM and USB provisioning. Should be opt-in, not default.
Scope: Disabling USB entirely breaks BMC KVM and USB-based provisioning. Must be opt-in for specific hardened deployments only.

PR History

audit=1, audit_backlog_limit=8192, pti=on, page_poison=1, vsyscall=none Not Filed blocked
Mostly redundant with existing defaults. pti=on is already the default on x86_64 for Meltdown-vulnerable CPUs. audit=1 is already effective — audit messages flood console on fresh FCOS boot (fedora-coreos-tracker#220). page_poison=1 is a legacy KSPP recommendation superseded by init_on_alloc/init_on_free in modern kernels. vsyscall=none may already be the default on modern builds. audit_backlog_limit=8192 is operational tuning. CoreOS hardening discussion (fedora-coreos-tracker#805) focused on GRUB passwords, not kernel args.
Legend
Remediation Status
✅ PASS (vanilla) Passes on unhardened RHCOS; no remediation needed
🟢 Verified Remediation tested on live cluster, confirmed PASS
🔵 In Progress Remediation actively being developed or tested
🟡 Pending Not yet started; needs remediation work
🟠 Partial Some checks pass or remediation not fully validated
⚪ On Hold Work paused (blocked or deprioritized)
Upstream Verdict
🔼 Candidate Suitable for upstreaming to ComplianceAsCode
🟣 PR Open Upstream PR filed
🎯 RAN Only Only applies to RAN deployments
⚙️ Platform Requires OCP platform-level configuration
✅ Pass Already passing upstream
📍 Site Site/deployment-specific configuration
— N/A Not applicable for upstreaming
Platform
RHCOS Node-level checks (MachineConfig)
OCP Platform-level checks (API/CR)
Mixed Both RHCOS and OCP checks
Severity
HIGH
MEDIUM
LOW
MANUAL

Keyboard Shortcuts

Navigation
j / Next row
k / Previous row
Enter Open selected / Expand details
Esc Clear selection / Close modal
Actions
/ Focus search
d Toggle dark mode
? Show this help
g h Go to home
Filters
1 Show all
2 Pending only
3 In Progress only
4 Complete only