Patrick Schleizer
|
284a491100
|
disable vm.unprivileged_userfaultfd=0 for now
because broken
https://forums.whonix.org/t/kernel-hardening/7296/406
reverts "Restrict the userfaultfd() syscall to root as it can make heap sprays easier."
https://duasynt.com/blog/linux-kernel-heap-spray
|
2020-03-08 08:07:10 -04:00 |
|
Patrick Schleizer
|
44351ec9b7
|
remove no longer needed code for installation of apparmor profiles
|
2020-03-07 21:44:19 -05:00 |
|
Patrick Schleizer
|
71ae623916
|
bumped changelog version
|
2020-03-05 08:36:27 -05:00 |
|
Patrick Schleizer
|
76eb9579a3
|
readme
|
2020-03-05 08:33:00 -05:00 |
|
Patrick Schleizer
|
15dde15a36
|
typo
|
2020-03-03 09:42:24 -05:00 |
|
Patrick Schleizer
|
8887af26d6
|
bumped changelog version
|
2020-03-03 09:19:49 -05:00 |
|
Patrick Schleizer
|
1dea4dbcf6
|
readme
|
2020-03-03 09:18:38 -05:00 |
|
Patrick Schleizer
|
cd19c2da00
|
fix lintian warning
|
2020-03-03 09:18:24 -05:00 |
|
Patrick Schleizer
|
7e3fedefb2
|
bumped changelog version
|
2020-03-03 09:12:50 -05:00 |
|
Patrick Schleizer
|
201d6b5efc
|
readme
|
2020-03-03 09:07:42 -05:00 |
|
Patrick Schleizer
|
63c6405ab7
|
Merge remote-tracking branch 'origin/master'
|
2020-02-29 07:34:46 -05:00 |
|
Patrick Schleizer
|
453aa8a4eb
|
Merge pull request #65 from madaidan/userfaultfd
Restrict the userfaultfd() syscall to root
|
2020-02-29 12:28:32 +00:00 |
|
Patrick Schleizer
|
e3e39f2235
|
Merge remote-tracking branch 'origin/master'
|
2020-02-29 05:01:41 -05:00 |
|
Patrick Schleizer
|
649ec5dfa1
|
pkexec wrapper: fix gdebi / synaptic
but at cost of checking for passwordless sudo /etc/suders /etc/sudoers.d
exceptions.
http://forums.whonix.org/t/cannot-use-pkexec/8129/53
|
2020-02-29 04:59:56 -05:00 |
|
Patrick Schleizer
|
32269d32b6
|
description
|
2020-02-29 04:59:15 -05:00 |
|
Patrick Schleizer
|
b31caefdeb
|
description
|
2020-02-29 04:59:02 -05:00 |
|
Patrick Schleizer
|
bd7678c574
|
Merge pull request #66 from madaidan/mce
Fix docs
|
2020-02-28 12:04:05 +00:00 |
|
madaidan
|
42d3b986c4
|
Update control
|
2020-02-27 17:41:14 +00:00 |
|
Patrick Schleizer
|
d04d4bf095
|
description
|
2020-02-25 02:08:10 -05:00 |
|
Patrick Schleizer
|
4043d2af3f
|
description
|
2020-02-25 02:06:48 -05:00 |
|
Patrick Schleizer
|
0e5187ff24
|
description
|
2020-02-25 02:00:27 -05:00 |
|
madaidan
|
60fbf8b0de
|
Update control
|
2020-02-24 18:24:07 +00:00 |
|
madaidan
|
6b64b36b01
|
Restrict the userfaultfd() syscall to root
|
2020-02-24 18:23:15 +00:00 |
|
Patrick Schleizer
|
221000db5b
|
Merge remote-tracking branch 'origin/master'
|
2020-02-17 03:17:11 -05:00 |
|
Patrick Schleizer
|
c7f2537930
|
Merge pull request #64 from madaidan/extra_latent_entropy
Gather more entropy during boot
|
2020-02-17 08:16:34 +00:00 |
|
madaidan
|
8ea4e50c8e
|
Update control
|
2020-02-16 19:52:40 +00:00 |
|
madaidan
|
f6b6ab374e
|
Gather more entropy during boot
|
2020-02-16 19:51:32 +00:00 |
|
Patrick Schleizer
|
01eaee997e
|
bumped changelog version
|
2020-02-15 15:35:44 -05:00 |
|
Patrick Schleizer
|
412a83923d
|
Merge remote-tracking branch 'origin/master'
|
2020-02-15 15:30:32 -05:00 |
|
Patrick Schleizer
|
dce54d5d0f
|
bumped changelog version
|
2020-02-15 15:29:38 -05:00 |
|
Patrick Schleizer
|
3df008f0b9
|
readme
|
2020-02-15 15:28:30 -05:00 |
|
Patrick Schleizer
|
4399a512be
|
Merge pull request #63 from madaidan/ldisc_autoload
Document ldisc_autoload better
|
2020-02-15 19:43:05 +00:00 |
|
madaidan
|
a79ce7fa68
|
Document ldisc_autoload better
|
2020-02-15 17:30:21 +00:00 |
|
Patrick Schleizer
|
757df8fceb
|
Merge remote-tracking branch 'origin/master'
|
2020-02-15 05:43:43 -05:00 |
|
Patrick Schleizer
|
a9a1581720
|
Merge pull request #60 from madaidan/sysrq
Restrict the SysRq key
|
2020-02-15 10:42:20 +00:00 |
|
Patrick Schleizer
|
1e5946c795
|
Merge branch 'master' into sysrq
|
2020-02-15 10:41:52 +00:00 |
|
Patrick Schleizer
|
9bbae903fe
|
remove-system.map: lower verbosity output
|
2020-02-15 05:29:48 -05:00 |
|
Patrick Schleizer
|
cce35e5109
|
Merge remote-tracking branch 'origin/master'
|
2020-02-15 05:27:52 -05:00 |
|
Patrick Schleizer
|
e40351796e
|
Merge pull request #62 from madaidan/shred
Shred System.map files
|
2020-02-15 10:25:15 +00:00 |
|
Patrick Schleizer
|
5124f8cebc
|
Merge pull request #61 from madaidan/disable_early_pci_dma
Avoid holes in IOMMU
|
2020-02-15 10:18:56 +00:00 |
|
Patrick Schleizer
|
ac8757a031
|
Merge pull request #59 from madaidan/ldisc
Restrict loading line disciplines to CAP_SYS_MODULE
|
2020-02-15 10:09:46 +00:00 |
|
madaidan
|
31009f0bfa
|
Shred System.map files
|
2020-02-14 23:46:19 +00:00 |
|
madaidan
|
9b767139ef
|
Avoid holes in IOMMU
|
2020-02-14 18:52:01 +00:00 |
|
madaidan
|
0f49736957
|
Update control
|
2020-02-14 18:18:18 +00:00 |
|
madaidan
|
d251c43344
|
Restrict the SysRq key
|
2020-02-14 18:17:20 +00:00 |
|
madaidan
|
ace6211176
|
Update control
|
2020-02-14 17:51:17 +00:00 |
|
madaidan
|
0ea7dd161b
|
Restrict loading line disciplines to CAP_SYS_MODULE
|
2020-02-14 17:50:19 +00:00 |
|
Patrick Schleizer
|
ad6b766886
|
Merge pull request #57 from madaidan/sysctl
Prevent symlink/hardlink TOCTOU races
|
2020-02-13 18:40:58 +00:00 |
|
Patrick Schleizer
|
14140ad41b
|
bumped changelog version
|
2020-02-13 13:39:45 -05:00 |
|
Patrick Schleizer
|
d1fa191bc0
|
readme
|
2020-02-13 13:38:21 -05:00 |
|