genmkfile debdistfile

This commit is contained in:
Patrick Schleizer 2025-09-18 10:00:33 -04:00
parent f70550d015
commit 06c045f70f
No known key found for this signature in database
GPG key ID: CB8D50BB77BB3C48
3 changed files with 141 additions and 8 deletions

9
debian/security-misc-desktop.install vendored Normal file
View file

@ -0,0 +1,9 @@
## Copyright (C) 2020 - 2025 ENCRYPTED SUPPORT LLC <adrelanos@whonix.org>
## See the file COPYING for copying conditions.
## This file was generated using 'genmkfile debinstfile'.
/etc/bluetooth/30_security-misc.conf
/usr/lib/NetworkManager/conf.d/80_ipv6-privacy.conf
/usr/lib/NetworkManager/conf.d/80_randomize-mac.conf
/usr/lib/systemd/networkd.conf.d/80_ipv6-privacy-extensions.conf

132
debian/security-misc-shared.install vendored Normal file
View file

@ -0,0 +1,132 @@
## Copyright (C) 2020 - 2025 ENCRYPTED SUPPORT LLC <adrelanos@whonix.org>
## See the file COPYING for copying conditions.
## This file was generated using 'genmkfile debinstfile'.
/var/cache/security-misc/state-files/placeholder
/etc/security/faillock.conf.security-misc
/etc/security/access-security-misc.conf
/etc/security/limits.d/30_security-misc.conf
/etc/gitconfig
/etc/apparmor.d/tunables/home.d/security-misc
/etc/ssh/ssh_config.d/30_security-misc.conf
/etc/ssh/sshd_config.d/30_security-misc.conf
/etc/usbguard/IPCAccessControl.d/:sudo
/etc/usbguard/rules.d/30_security-misc.conf
/etc/usbguard/usbguard-daemon.conf.security-misc
/etc/kernel/postinst.d/30_remove-system-map
/etc/sudoers.d/security-misc
/etc/systemd/system/emergency.service.d/override.conf
/etc/systemd/system/rescue.service.d/override.conf
/etc/profile.d/30_security-misc.sh
/etc/default/grub.d/40_cpu_mitigations.cfg
/etc/default/grub.d/41_recovery_restrict.cfg
/etc/default/grub.d/40_signed_modules.cfg
/etc/default/grub.d/40_kernel_hardening.cfg
/etc/default/grub.d/40_remount_secure.cfg
/etc/default/grub.d/41_quiet_boot.cfg
/etc/apt/apt.conf.d/40sandbox
/etc/apt/apt.conf.d/40error-on-any
/etc/securetty.security-misc
/etc/dracut.conf.d/30-security-misc.conf
/etc/skel/.gnupg/gpg.conf
/etc/skel/.config/xfce4/xfconf/xfce-perchannel-xml/thunar.xml
/etc/hide-hardware-info.d/30_default.conf
/etc/security-misc/emerg-shutdown/30_security_misc.conf
/etc/modprobe.d/30_security-misc_disable.conf
/etc/modprobe.d/30_security-misc_conntrack.conf
/etc/modprobe.d/30_security-misc_blacklist.conf
/usr/libexec/security-misc/pam-abort-on-locked-password
/usr/libexec/security-misc/ensure-shutdown
/usr/libexec/security-misc/askpass
/usr/libexec/security-misc/panic-on-oops
/usr/libexec/security-misc/mmap-rnd-bits
/usr/libexec/security-misc/echo-path
/usr/libexec/security-misc/emerg-shutdown
/usr/libexec/security-misc/pam-info
/usr/libexec/security-misc/permission-lockdown
/usr/libexec/security-misc/pam_only_if_su
/usr/libexec/security-misc/remove-system.map
/usr/libexec/security-misc/pam_only_if_login
/usr/libexec/security-misc/disable-kernel-module-loading
/usr/libexec/security-misc/hide-hardware-info
/usr/libexec/security-misc/virusforget
/usr/libexec/security-misc/pam_faillock_not_if_x
/usr/src/security-misc/emerg-shutdown.c
/usr/bin/disabled-gps-by-security-misc
/usr/bin/disabled-netfilesys-by-security-misc
/usr/bin/disabled-framebuffer-by-security-misc
/usr/bin/disabled-miscellaneous-by-security-misc
/usr/bin/disabled-intelme-by-security-misc
/usr/bin/disabled-firewire-by-security-misc
/usr/bin/disabled-network-by-security-misc
/usr/bin/disabled-thunderbolt-by-security-misc
/usr/bin/disabled-cdrom-by-security-misc
/usr/bin/disabled-filesys-by-security-misc
/usr/bin/permission-hardener
/usr/bin/disabled-intelpmt-by-security-misc
/usr/bin/disabled-bluetooth-by-security-misc
/usr/bin/remount-secure
/usr/lib/modules-load.d/30_security-misc.conf
/usr/lib/systemd/coredump.conf.d/30_security-misc.conf
/usr/lib/systemd/system-preset/50-security-misc.preset
/usr/lib/systemd/system/panic-on-oops.service
/usr/lib/systemd/system/permission-hardener.service
/usr/lib/systemd/system/remove-system-map.service
/usr/lib/systemd/system/proc-hidepid.service
/usr/lib/systemd/system/block-shutdown.service
/usr/lib/systemd/system/emerg-shutdown.service
/usr/lib/systemd/system/hide-hardware-info.service
/usr/lib/systemd/system/harden-module-loading.service
/usr/lib/systemd/system/user@.service.d/sysfs.conf
/usr/lib/systemd/system/usbguard.service.d/30_security-misc.conf
/usr/lib/systemd/system/haveged.service.d/30_security-misc.conf
/usr/lib/systemd/system/remount-secure.service
/usr/lib/systemd/system/ensure-shutdown.service
/usr/lib/systemd/system/sysinit-post.target
/usr/lib/systemd/system/ensure-shutdown-trigger.service
/usr/lib/systemd/pstore.conf.d/30_security-misc.conf
/usr/lib/udev/rules.d/95-emerg-shutdown.rules
/usr/lib/issue.d/20_security-misc.issue
/usr/lib/dracut/modules.d/99emerg-shutdown/module-setup.sh
/usr/lib/dracut/modules.d-disabled/20remount-secure/module-setup.sh
/usr/lib/dracut/modules.d-disabled/20remount-secure/remount-secure.sh
/usr/lib/permission-hardener.d/25_default_whitelist_qubes.conf
/usr/lib/permission-hardener.d/25_default_whitelist_firejail.conf
/usr/lib/permission-hardener.d/30_default.conf
/usr/lib/permission-hardener.d/25_default_whitelist_bubblewrap.conf
/usr/lib/permission-hardener.d/25_default_whitelist_virtualbox.conf
/usr/lib/permission-hardener.d/25_default_whitelist_ssh.conf
/usr/lib/permission-hardener.d/25_default_whitelist_chromium.conf
/usr/lib/permission-hardener.d/25_default_whitelist_selinux.conf
/usr/lib/permission-hardener.d/25_default_whitelist_policykit.conf
/usr/lib/permission-hardener.d/25_default_whitelist_pam.conf
/usr/lib/permission-hardener.d/25_default_whitelist_dbus.conf
/usr/lib/permission-hardener.d/25_default_whitelist_postfix.conf
/usr/lib/permission-hardener.d/25_default_whitelist_mount.conf
/usr/lib/permission-hardener.d/25_default_whitelist_hardened_malloc.conf
/usr/lib/permission-hardener.d/25_default_whitelist_sudo.conf
/usr/lib/permission-hardener.d/25_default_whitelist_unix_chkpwd.conf
/usr/lib/permission-hardener.d/25_default_whitelist_fuse.conf
/usr/lib/permission-hardener.d/25_default_whitelist_passwd.conf
/usr/lib/permission-hardener.d/25_default_whitelist_spice.conf
/usr/lib/sysctl.d/30_silent-kernel-printk.conf
/usr/lib/sysctl.d/990-security-misc.conf
/usr/lib/sysctl.d/30_security-misc_kexec-disable.conf
/usr/share/glib-2.0/schemas/30_security-misc.gschema.override
/usr/share/doc/security-misc/fstab-vm
/usr/share/pam-configs/faillock-preauth-security-misc
/usr/share/pam-configs/wheel-security-misc
/usr/share/pam-configs/umask-security-misc
/usr/share/pam-configs/unix-faillock-security-misc
/usr/share/pam-configs/console-lockdown-security-misc
/usr/share/pam-configs/mkhomedir-security-misc
/usr/share/pam-configs/pam-abort-on-locked-password-security-misc
/usr/share/lintian/overrides/security-misc
/usr/share/security-misc/lkrg/30-lkrg-virtualbox.conf
/usr/share/security-misc/lkrg/lkrg-virtualbox
/usr/share/security-misc/emerg-shutdown-initramfs.service
/usr/share/security-misc/security-misc-memlockd.cfg
/usr/share/security-misc/permission-hardener-new-mode-legacy-hardcoded
/usr/share/security-misc/dolphinrc
/usr/share/security-misc/permission-hardener-existing-mode-legacy-hardcoded

View file

@ -1,8 +0,0 @@
## Copyright (C) 2020 - 2025 ENCRYPTED SUPPORT LLC <adrelanos@whonix.org>
## See the file COPYING for copying conditions.
## This file was generated using 'genmkfile debinstfile'.
etc/*
usr/*
var/*