Commit graph

2901 commits

Author SHA1 Message Date
Aaron Rainbolt
3d5e659b78
Remove trailing spaces 2025-10-15 19:02:48 -05:00
Aaron Rainbolt
29639fe69e
Merge remote-tracking branch 'raja/bad_ipv6_ra' into arraybolt3/trixie 2025-10-15 19:01:08 -05:00
Aaron Rainbolt
026d55ac41
Typo fixes 2025-10-15 18:30:52 -05:00
Aaron Rainbolt
35fce26476
Merge remote-tracking branch 'raja/stop_ptrace' into arraybolt3/trixie 2025-10-15 18:18:33 -05:00
Aaron Rainbolt
4f63af4200
Allow listing USB devices via usbguard 2025-10-15 17:53:26 -05:00
raja-grewal
2304174171
Insert empty new line 2025-10-12 02:32:45 +00:00
raja-grewal
7161430a60
Seperate ptrace() disabling into own file 2025-10-12 02:27:48 +00:00
Patrick Schleizer
6cc1c27fb3
bumped changelog version 2025-10-10 12:08:28 +00:00
Patrick Schleizer
4d9c3dc357
minor 2025-10-10 08:08:10 -04:00
Patrick Schleizer
968de33c65
Force immediate kernel panic on OOM.
This is to avoid security features such as the screen locker, kloak, emerg-shutdown
from being arbitrarily terminated when the system starts running out of memory.

https://forums.whonix.org/t/screen-locker-in-security-can-we-disable-these-at-least-4-backdoors/8128/14

https://github.com/Kicksecure/security-misc/issues/324

`vm.panic_on_oom=2`

implements https://github.com/Kicksecure/security-misc/issues/324
2025-10-10 08:03:03 -04:00
Patrick Schleizer
98f27c3b2e
comment 2025-10-10 06:53:04 -04:00
Patrick Schleizer
28a88c7091
comment 2025-10-10 06:52:13 -04:00
Patrick Schleizer
f4a87e7748
Merge remote-tracking branch 'github-kicksecure/master' 2025-10-10 06:51:31 -04:00
Patrick Schleizer
6cf8a623fe
Merge pull request #325 from raja-grewal/hash_pointers
Docs detailing future improvements to `slab_debug`
2025-10-10 06:50:46 -04:00
raja-grewal
e89c7ae025
Update docs on slab_debug for future improvements 2025-10-08 02:39:20 +00:00
Patrick Schleizer
685070bd02
bumped changelog version 2025-10-07 08:40:32 +00:00
Patrick Schleizer
ba6ec919f0
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/trixie' 2025-10-07 04:34:51 -04:00
Aaron Rainbolt
718772ea78
Remove unsafe sanitizer compiler flags from emerg-shutdown 2025-10-06 15:03:31 -05:00
raja-grewal
0c8f2f1b44
Add docs about the risks associated with IPv6 RAs 2025-10-02 07:05:00 +00:00
Patrick Schleizer
dd961b8427
bumped changelog version 2025-09-28 21:09:46 +00:00
Patrick Schleizer
e6ba4dad46
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/trixie' 2025-09-28 17:00:24 -04:00
Aaron Rainbolt
60f8153f64
Fix emerg-shutdown gcc build, remove AddressSanitizer from hardening options since it is incompatible with static builds 2025-09-28 15:05:21 -05:00
Aaron Rainbolt
7e016b5632
Allow users in the qubes group to access USBGuard IPC 2025-09-28 14:11:59 -05:00
raja-grewal
194b8fce4e
Disable the usage of ptrace() by all processes 2025-09-28 03:20:24 +00:00
Patrick Schleizer
22c9863493
bumped changelog version 2025-09-26 08:40:20 +00:00
Patrick Schleizer
08199dfe94
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/trixie' 2025-09-26 04:31:02 -04:00
Aaron Rainbolt
58cc6731f2
Additional hardening on emerg-shutdown 2025-09-26 00:13:59 -05:00
Patrick Schleizer
590aaec73d
bumped changelog version 2025-09-24 14:32:35 +00:00
Patrick Schleizer
2536880394
Merge remote-tracking branch 'github-kicksecure/master' 2025-09-24 10:32:12 -04:00
Patrick Schleizer
17ee63aca4
Merge pull request #319 from raja-grewal/release_notice
Notice on public releases
2025-09-24 10:31:31 -04:00
raja-grewal
d31f63fb10
README: Notice on public releases 2025-09-23 05:47:45 +00:00
Patrick Schleizer
275eecc4f8
bumped changelog version 2025-09-22 17:25:48 +00:00
Patrick Schleizer
c45a4ffdd2
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/trixie' 2025-09-22 13:04:33 -04:00
Aaron Rainbolt
2a39d5997c
security-misc split string changes 2025-09-21 16:06:11 -05:00
Patrick Schleizer
5738bb6104
bumped changelog version 2025-09-19 18:43:36 +00:00
Patrick Schleizer
9acdfc741b
description 2025-09-19 14:42:35 -04:00
Patrick Schleizer
62ea7e5041
security-misc -> security-misc-shared package migration
https://github.com/Kicksecure/security-misc/issues/187
2025-09-19 14:41:05 -04:00
Patrick Schleizer
02d0ba49bb
bumped changelog version 2025-09-19 18:10:09 +00:00
Patrick Schleizer
0c7bee33a7
comment 2025-09-19 14:01:16 -04:00
Patrick Schleizer
3583004796
bumped changelog version 2025-09-19 16:18:37 +00:00
Patrick Schleizer
67b1cb319d
Replaces: security-misc
https://github.com/Kicksecure/security-misc/issues/187
2025-09-19 12:05:29 -04:00
Patrick Schleizer
4bd08f8c81
wrap-and-sort 2025-09-19 12:05:03 -04:00
Patrick Schleizer
068750543a
update link 2025-09-19 11:59:22 -04:00
Patrick Schleizer
ca90feb8d5
security-misc-server placeholder
https://github.com/Kicksecure/security-misc/issues/187
2025-09-19 11:54:04 -04:00
Patrick Schleizer
4eb9ec15e1
packaging
https://github.com/Kicksecure/security-misc/issues/187
2025-09-19 11:51:14 -04:00
Patrick Schleizer
c2594a022e
rename
https://github.com/Kicksecure/security-misc/issues/187
2025-09-19 11:29:55 -04:00
Patrick Schleizer
41ba668d23
rename
https://github.com/Kicksecure/security-misc/issues/187
2025-09-19 11:23:10 -04:00
Patrick Schleizer
1b194f9fd6
adjust lintian overrides file
https://github.com/Kicksecure/security-misc/issues/187
2025-09-19 10:59:23 -04:00
Patrick Schleizer
80562557ef
make install files executable
https://github.com/Kicksecure/security-misc/issues/187
2025-09-19 10:53:25 -04:00
Patrick Schleizer
c99ea95410
genmkfile debinstfile 2025-09-19 10:49:17 -04:00