Patrick Schleizer
b9d65338bc
unconditionally enable all CPU bugs (spectre, meltdown, L1TF, ...)
...
this might reduce performance
* `spectre_v2=on`
* `spec_store_bypass_disable=on`
* `tsx=off`
* `tsx_async_abort=full,nosmt`
Thanks to @madaidan for the suggestion!
https://forums.whonix.org/t/should-all-kernel-patches-for-cpu-bugs-be-unconditionally-enabled-vs-performance-vs-applicability/7647
2020-01-30 05:55:13 -05:00
Patrick Schleizer
2711d0f7f0
bumped changelog version
2020-01-30 01:22:32 -05:00
Patrick Schleizer
4df0d6c01c
readme
2020-01-30 01:22:06 -05:00
Patrick Schleizer
c1a0da60be
set kernel boot parameter l1tf=full,force
and nosmt=force
...
https://forums.whonix.org/t/should-all-kernel-patches-for-cpu-bugs-be-unconditionally-enabled-vs-performance-vs-applicability/7647/17
2020-01-30 00:46:48 -05:00
Patrick Schleizer
efc40da4fb
bumped changelog version
2020-01-24 12:02:27 -05:00
Patrick Schleizer
07dcb32fc2
readme
2020-01-24 11:55:38 -05:00
Patrick Schleizer
f4c54881ac
description
2020-01-24 04:49:19 -05:00
Patrick Schleizer
25317f23e3
bumped changelog version
2020-01-24 04:41:16 -05:00
Patrick Schleizer
be79f0688a
readme
2020-01-24 04:40:20 -05:00
Patrick Schleizer
c0d3726b00
comment
2020-01-24 04:40:03 -05:00
Patrick Schleizer
a37da1c968
add digits to drop-in file names
2020-01-24 04:39:06 -05:00
Patrick Schleizer
2ab940c603
bumped changelog version
2020-01-24 04:34:18 -05:00
Patrick Schleizer
bac6cd601b
readme
2020-01-24 04:33:54 -05:00
Patrick Schleizer
3a4d283169
description
2020-01-24 04:33:30 -05:00
Patrick Schleizer
e0aa67677d
merge the many modprobe.d config files into 1
...
and use a name starting with double digits
to make it easier to disable settings using a lexically higher config file
2020-01-24 04:30:36 -05:00
Patrick Schleizer
6a4c493213
merge the many sysctl config files into 1
...
and use a name starting with double digits
to make it easier to disable settings using a lexically higher config file
2020-01-24 04:26:36 -05:00
Patrick Schleizer
f653b94e77
bumped changelog version
2020-01-24 03:49:02 -05:00
Patrick Schleizer
ca057713e2
readme
2020-01-24 03:39:04 -05:00
Patrick Schleizer
8616728ce0
remove duplicate
2020-01-24 03:35:15 -05:00
Patrick Schleizer
d4a37b6df2
remove-system.map: source /usr/lib/helper-scripts/pre.bsh
2020-01-24 03:18:17 -05:00
Patrick Schleizer
3b283ec00f
bumped changelog version
2020-01-22 07:10:47 -05:00
Patrick Schleizer
531f17cb68
add update initramfs trigger
...
https://github.com/Whonix/security-misc/pull/53
2020-01-22 07:08:31 -05:00
Patrick Schleizer
df0b2afda1
bumped changelog version
2020-01-21 10:12:32 -05:00
Patrick Schleizer
18041efa2f
fix pam tally2 check when read-only disk boot without ro-mode-init or grub-live
2020-01-21 10:01:17 -05:00
Patrick Schleizer
627b95e0b3
bumped changelog version
2020-01-20 08:51:25 -05:00
Patrick Schleizer
fbe9b60d95
fix Whonix / Kicksecure
...
/var/lib/dpkg/tmp.ci/preinst: ERROR: No user is a member of group 'console'. Installation aborted.
/var/lib/dpkg/tmp.ci/preinst: ERROR: You probably want to run:
sudo adduser user console
2020-01-20 08:49:02 -05:00
Patrick Schleizer
960e1ff6e8
bumped changelog version
2020-01-17 03:32:57 -05:00
Patrick Schleizer
1304341868
readme
2020-01-17 03:10:56 -05:00
Patrick Schleizer
6f8d89c6c5
error handling
2020-01-15 15:54:06 -05:00
Patrick Schleizer
7211f6e019
Merge remote-tracking branch 'origin/master'
2020-01-15 15:53:36 -05:00
Patrick Schleizer
f6cc76acd7
Merge pull request #55 from madaidan/sysctl.conf
...
Process sysctl.conf in initramfs
2020-01-15 20:52:33 +00:00
madaidan
1df48a226d
Update control
2020-01-15 20:30:17 +00:00
madaidan
f7fde60b67
Process sysctl.conf too
2020-01-15 20:28:32 +00:00
Patrick Schleizer
e110ea0b84
bumped changelog version
2020-01-15 11:37:52 -05:00
Patrick Schleizer
0f17596aac
readme
2020-01-15 11:35:41 -05:00
Patrick Schleizer
0618b53464
fix lintian warning
2020-01-15 11:35:07 -05:00
Patrick Schleizer
47ce3bec75
bumped changelog version
2020-01-15 11:05:54 -05:00
Patrick Schleizer
73e830d0ac
readme
2020-01-15 10:08:57 -05:00
Patrick Schleizer
8ab4623f8e
Merge remote-tracking branch 'origin/master'
2020-01-15 06:06:39 -05:00
Patrick Schleizer
087465a0cd
Merge pull request #53 from madaidan/sysctl-initramfs
...
Set sysctl values in initramfs
2020-01-15 11:02:30 +00:00
Patrick Schleizer
528c5fc4c4
Merge branch 'master' into sysctl-initramfs
2020-01-15 11:02:03 +00:00
Patrick Schleizer
80159545a5
fix xfce4-power-manager xfpm-power-backlight-helper pkexec lxsudo popup
...
https://forums.whonix.org/t/xfce4-power-manager-xfpm-power-backlight-helper-pkexec-lxsudo-popup/8764
do show lxqt-sudo password prompt if there is a sudoers exceptoin
improved pkexec wrapper logging
2020-01-15 02:42:10 -05:00
Patrick Schleizer
d90ca4b1ad
refactoring
2020-01-14 15:12:13 -05:00
Patrick Schleizer
082f04f2d4
add logging to pkexec wrapper
2020-01-14 15:04:58 -05:00
Patrick Schleizer
1059ccf225
bumped changelog version
2020-01-14 09:28:28 -05:00
Patrick Schleizer
660837dc38
fix case when user "user" does not exists
2020-01-14 09:25:32 -05:00
Patrick Schleizer
18c726c3ee
comment
2020-01-14 09:23:02 -05:00
Patrick Schleizer
b8652681e7
fix legacy
2020-01-14 09:21:47 -05:00
Patrick Schleizer
cc21f912a3
bumped changelog version
2020-01-14 09:20:36 -05:00
Patrick Schleizer
2078cd237f
readme
2020-01-14 09:18:30 -05:00