Raja Grewal
|
0b0683499a
|
Consistent line length formatting
|
2024-08-09 13:30:39 +10:00 |
|
Raja Grewal
|
e5a38fc856
|
Typo
|
2024-08-09 13:30:15 +10:00 |
|
Patrick Schleizer
|
89e816dda6
|
bumped changelog version
|
2024-08-06 14:01:39 +00:00 |
|
Patrick Schleizer
|
967f9e257b
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-08-06 09:57:56 -04:00 |
|
Patrick Schleizer
|
a25aaf900a
|
Merge pull request #260 from raja-grewal/vdso32
Enable `vdso32=0`
|
2024-08-06 09:55:20 -04:00 |
|
Patrick Schleizer
|
6bc039a430
|
Merge pull request #259 from raja-grewal/kfence
Enable `kfence.sample_interval=100`
|
2024-08-06 09:52:56 -04:00 |
|
Patrick Schleizer
|
ce60d5615f
|
Merge pull request #258 from raja-grewal/legacy_tiocsti
Enable `dev.tty.legacy_tiocsti=0`
|
2024-08-06 09:48:08 -04:00 |
|
Patrick Schleizer
|
b0278428a7
|
Merge pull request #257 from raja-grewal/slab_debug
Enable `slab_debug=FZ`
|
2024-08-06 09:39:04 -04:00 |
|
Raja Grewal
|
8559079312
|
Enable vdso32=0
|
2024-08-05 15:10:02 +10:00 |
|
Raja Grewal
|
d102ec1997
|
Enable kfence.sample_interval=100
|
2024-08-05 15:07:56 +10:00 |
|
Raja Grewal
|
c0d140f221
|
Enable dev.tty.legacy_tiocsti=0
|
2024-08-05 15:06:34 +10:00 |
|
Raja Grewal
|
aa34d86598
|
Enable slab_debug=FZ
|
2024-08-05 14:27:17 +10:00 |
|
Patrick Schleizer
|
fa9091869d
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-08-04 16:20:36 -04:00 |
|
Patrick Schleizer
|
725118c575
|
Merge pull request #243 from raja-grewal/namespaces
Restrict unprivileged user namespaces
|
2024-08-04 16:19:52 -04:00 |
|
Patrick Schleizer
|
06f0c27128
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-08-04 16:15:01 -04:00 |
|
Patrick Schleizer
|
6d97408a6d
|
Merge pull request #255 from raja-grewal/SLUB
Restore option to enable `slub_debug=FZ`
|
2024-08-04 16:11:46 -04:00 |
|
Patrick Schleizer
|
8abc5ae8f0
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-08-04 16:09:52 -04:00 |
|
Patrick Schleizer
|
eab66dad09
|
Merge pull request #254 from raja-grewal/patch
Updates to kernel and `sysctl` hardening
|
2024-08-04 16:08:32 -04:00 |
|
Raja Grewal
|
6f14d68cdc
|
Update legacy name slub_debug -> slab_debug
|
2024-08-03 15:12:15 +10:00 |
|
Raja Grewal
|
22b6cee80c
|
Add details about slub_debug
|
2024-08-03 15:11:14 +10:00 |
|
Raja Grewal
|
b77d1a2b98
|
Revert "Remove the optional slub_debug parameter since it is no longer recommended"
This reverts commit 48e1ac4163 .
|
2024-08-03 14:49:48 +10:00 |
|
Raja Grewal
|
ca2179bb6a
|
Provide the option to disable legacy TIOCSTI operation
|
2024-08-03 00:25:49 +10:00 |
|
Raja Grewal
|
52aeacb4da
|
Provide option to disable 32 bit vDSO mappings
|
2024-08-03 00:13:38 +10:00 |
|
Raja Grewal
|
9099ecce8a
|
Provide option to enable the kernel Electric-Fence
|
2024-08-03 00:12:50 +10:00 |
|
Raja Grewal
|
f6a16258a1
|
Add references to KSPP
|
2024-08-03 00:11:06 +10:00 |
|
Raja Grewal
|
e53d24fc48
|
Add missing GRUB command lines for disabled boot parameters
|
2024-08-03 00:09:42 +10:00 |
|
Patrick Schleizer
|
de6f3ea74a
|
bumped changelog version
|
2024-07-28 20:50:22 +00:00 |
|
Patrick Schleizer
|
d036094089
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-07-28 15:44:40 -04:00 |
|
Patrick Schleizer
|
0f86fbd8ce
|
Merge pull request #242 from raja-grewal/ptrace
Disable the usage of `ptrace()` by all processes
|
2024-07-28 15:43:54 -04:00 |
|
Patrick Schleizer
|
e60ce50d30
|
bumped changelog version
|
2024-07-27 16:13:35 +00:00 |
|
Patrick Schleizer
|
e86b2e7f8f
|
output
|
2024-07-27 12:13:18 -04:00 |
|
Raja Grewal
|
73979d4342
|
Link to ptrace() discussion
|
2024-07-27 13:28:59 +10:00 |
|
Raja Grewal
|
1c9f33f906
|
Revert "Disable the usage of ptrace() by all processes"
This reverts commit b04828f858 .
|
2024-07-27 13:24:08 +10:00 |
|
Patrick Schleizer
|
330cf14eab
|
bumped changelog version
|
2024-07-26 15:40:24 +00:00 |
|
Patrick Schleizer
|
62bb4bc626
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-07-26 11:10:25 -04:00 |
|
Patrick Schleizer
|
886f6095db
|
Merge pull request #250 from raja-grewal/Panik-Kalm
Add details on "oopes" and kernel panics
|
2024-07-26 11:08:30 -04:00 |
|
Patrick Schleizer
|
7969e86071
|
Merge remote-tracking branch 'github-kicksecure/master'
|
2024-07-26 11:06:13 -04:00 |
|
Patrick Schleizer
|
0318f577ab
|
Merge pull request #246 from raja-grewal/cfi
Provide the option to change the default CFI implementation in the future
|
2024-07-26 11:04:29 -04:00 |
|
Patrick Schleizer
|
e2ae93a957
|
port to safe_echo
|
2024-07-26 10:30:45 -04:00 |
|
Patrick Schleizer
|
8ec23ed712
|
echo does not support end-of-options
|
2024-07-26 10:28:57 -04:00 |
|
Patrick Schleizer
|
6096ed1109
|
comment
|
2024-07-26 10:26:43 -04:00 |
|
Patrick Schleizer
|
ac41d1cfff
|
comment
|
2024-07-26 10:25:59 -04:00 |
|
Patrick Schleizer
|
3b033ceba2
|
shellcheck
|
2024-07-26 10:17:24 -04:00 |
|
Patrick Schleizer
|
04d9ca1ebe
|
use find with safe_echo_nonewline
|
2024-07-26 10:16:20 -04:00 |
|
Patrick Schleizer
|
6bbf176e3b
|
consider end-of-options for find
|
2024-07-26 09:33:45 -04:00 |
|
Patrick Schleizer
|
794f6a25fa
|
comment
|
2024-07-26 09:08:29 -04:00 |
|
Patrick Schleizer
|
7e0f1a8701
|
dpkg-statoverride can actually handle '--file-name'.
|
2024-07-26 09:08:04 -04:00 |
|
Patrick Schleizer
|
ee037c01a1
|
Skip file names starting with '--',
because this would be interpreted by dpkg-statoverride as an option.
|
2024-07-26 08:58:44 -04:00 |
|
Patrick Schleizer
|
82d401a7de
|
sanity test
|
2024-07-26 08:52:42 -04:00 |
|
Patrick Schleizer
|
0e661bc688
|
output
|
2024-07-26 08:49:14 -04:00 |
|