Commit graph

3063 commits

Author SHA1 Message Date
Aaron Rainbolt
3f097a35f2
Split up a line in README.md 2025-12-14 14:03:33 -06:00
Aaron Rainbolt
e7e6d6d373
Merge remote-tracking branch 'raja/incomplete_cpu_mitigations' into arraybolt3/trixie-raja-merge 2025-12-14 14:01:54 -06:00
raja-grewal
b8f7806267
Update usage of mitigations=auto,nosmt 2025-12-14 12:38:47 +00:00
Aaron Rainbolt
8e56772c2f
README.md typo fix 2025-12-13 19:22:50 -06:00
Aaron Rainbolt
4d0a126955
Merge remote-tracking branch 'raja/modprobe_refresh' into arraybolt3/trixie-raja-merge 2025-12-13 18:44:03 -06:00
Aaron Rainbolt
39ce591976
Merge remote-tracking branch 'raja/amd_encrypt_sev' into arraybolt3/trixie-raja-merge 2025-12-13 18:27:22 -06:00
Patrick Schleizer
b366c5e62a
bumped changelog version 2025-12-12 13:17:09 +00:00
Patrick Schleizer
68de32e43e
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/trixie' 2025-12-12 04:35:53 -05:00
raja-grewal
8040ba7579
Minor fixes to docs 2025-12-12 02:04:38 +00:00
raja-grewal
fe1cfcd1a0
Update docs on CPU MSRs 2025-12-12 02:03:23 +00:00
raja-grewal
ab2d44677a
Correct script addition 2025-12-12 02:01:20 +00:00
raja-grewal
5684a12d9d
Whitelist 9p module 2025-12-12 01:59:23 +00:00
Aaron Rainbolt
135ee80450
Move kernel.panic=-1 setting to sysctl, allow turning panic-on-oops off with systemctl 2025-12-11 18:47:42 -06:00
raja-grewal
7d90121302
Add reference for AMD SEV 2025-12-11 14:12:18 +00:00
raja-grewal
72f295a3f0
Provide option to enable AMD SEV-SNP 2025-12-11 14:11:47 +00:00
raja-grewal
6a17255307
Provide option to enable AMD SEV-ES 2025-12-11 14:11:26 +00:00
raja-grewal
53c4fdbeea
Merge branch 'Kicksecure:master' into modprobe_refresh 2025-12-11 12:52:14 +11:00
Patrick Schleizer
725565c42e
bumped changelog version 2025-12-09 14:06:55 +00:00
Patrick Schleizer
b7b6b6e5fb
output 2025-12-08 09:42:59 -05:00
Patrick Schleizer
8f99672cb2
bumped changelog version 2025-12-05 11:39:12 +00:00
Patrick Schleizer
ac128dd873
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/trixie' 2025-12-05 06:35:03 -05:00
Aaron Rainbolt
85761a4153
permission-hardener: Fix undo warning logic, minor improvements suggested by ChatGPT Codex 2025-12-04 23:27:18 -06:00
Patrick Schleizer
17dd7af7d1
bumped changelog version 2025-12-03 08:31:22 +00:00
Patrick Schleizer
c44678f92d
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/trixie' 2025-12-03 03:22:44 -05:00
Aaron Rainbolt
0534a34ed7
Fix block-unsafe-logins when running as non-root, add swaylock to list of safe auth services 2025-12-02 19:06:30 -06:00
Patrick Schleizer
6f9732be98
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/trixie' 2025-12-02 06:04:07 -05:00
Aaron Rainbolt
b3eb739fe2
Link fix, change some wording 2025-11-30 00:20:21 -06:00
Aaron Rainbolt
5f34b4146e
Merge remote-tracking branch 'raja/docs' into arraybolt3/trixie 2025-11-30 00:12:18 -06:00
Aaron Rainbolt
2c253b1312
Merge remote-tracking branch 'raja/vsyscall32' into arraybolt3/trixie 2025-11-29 21:01:51 -06:00
Aaron Rainbolt
17ab1bb00f
Documentation fix 2025-11-29 20:44:30 -06:00
Aaron Rainbolt
2b2d30afce
Merge remote-tracking branch 'raja/limit_full_force' into arraybolt3/trixie 2025-11-29 20:23:09 -06:00
Aaron Rainbolt
f0d069c796
Minor README.md corrections 2025-11-29 20:15:03 -06:00
Aaron Rainbolt
b73a830b0f
Merge remote-tracking branch 'raja/kpti' into arraybolt3/trixie 2025-11-29 19:59:35 -06:00
Aaron Rainbolt
e54cb007f9
Merge remote-tracking branch 'raja/limit_bdev_writes' into arraybolt3/trixie 2025-11-29 19:54:10 -06:00
Aaron Rainbolt
84e193c44e
Merge remote-tracking branch 'raja/stop_tw_reuse' into arraybolt3/trixie 2025-11-28 14:21:59 -06:00
Aaron Rainbolt
65c45fc3d7
Minor fixes to NMI panic docs 2025-11-28 00:13:45 -06:00
Aaron Rainbolt
37b1d055f1
Merge remote-tracking branch 'raja/panic_nmi' into arraybolt3/trixie 2025-11-28 00:09:43 -06:00
Aaron Rainbolt
7280d8867d
Merge remote-tracking branch 'raja/amd_encrypt_ram' into arraybolt3/trixie 2025-11-27 23:28:53 -06:00
Patrick Schleizer
2089b3a9b8
bumped changelog version 2025-11-24 08:44:10 +00:00
Patrick Schleizer
cbd35502f1
comment 2025-11-24 03:18:25 -05:00
Patrick Schleizer
cac73c3154
minor 2025-11-24 03:17:38 -05:00
Patrick Schleizer
d68988e76c
comments 2025-11-24 03:17:25 -05:00
Patrick Schleizer
c1ca36d758
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/trixie' 2025-11-24 03:11:19 -05:00
Aaron Rainbolt
a3417e997d
Add pkexec remembered permissions fix for permission-hardener, fix some postinst bugs 2025-11-23 16:27:59 -06:00
Aaron Rainbolt
edda37809f
Remove obsolete migration code for permission-hardener, add initial permission-hardener state installation code 2025-11-23 14:54:02 -06:00
Patrick Schleizer
ec11679514
bumped changelog version 2025-11-23 10:26:13 +00:00
Patrick Schleizer
5c4d3162ab
fix 2025-11-23 05:25:13 -05:00
raja-grewal
f75e987337
Relabel some disabled module headings 2025-11-21 13:06:42 +00:00
raja-grewal
79be87ec5f
Move (optional) CPU MSR module disable list 2025-11-21 13:05:13 +00:00
raja-grewal
1a7b0a9122
Disable more file systems 2025-11-21 12:43:05 +00:00