Commit graph

234 commits

Author SHA1 Message Date
Patrick Schleizer
e9e6c12b03
output 2025-11-10 02:08:04 -05:00
Patrick Schleizer
f5db916bf7
fix 2025-11-10 02:06:55 -05:00
Patrick Schleizer
bb0a23fcc8
chmod +x 2025-11-10 02:05:47 -05:00
Aaron Rainbolt
5fbd42bbec
Add kill-vboxdrmclient-on-shutdown.service 2025-11-09 18:38:54 -06:00
Aaron Rainbolt
9d86379f56
Prevent non-sysmaint logins in sysmaint mode and unsafe passwordless logins in user mode 2025-11-09 17:50:28 -06:00
Patrick Schleizer
d50e6afc8f
sanity test 2025-11-08 01:34:32 -05:00
Patrick Schleizer
1267960842
comments 2025-11-08 01:32:45 -05:00
Patrick Schleizer
1e48886c7e
long option name 2025-11-08 01:31:02 -05:00
Aaron Rainbolt
fa32ba6c4f
Suppress usbguard startup unless a USB controller is visible to lspci 2025-11-07 17:09:34 -06:00
Patrick Schleizer
cb70f19837
more robust, standardized kernel_cmdline variable detection 2025-10-26 08:06:26 -04:00
Aaron Rainbolt
718772ea78
Remove unsafe sanitizer compiler flags from emerg-shutdown 2025-10-06 15:03:31 -05:00
Aaron Rainbolt
60f8153f64
Fix emerg-shutdown gcc build, remove AddressSanitizer from hardening options since it is incompatible with static builds 2025-09-28 15:05:21 -05:00
Aaron Rainbolt
58cc6731f2
Additional hardening on emerg-shutdown 2025-09-26 00:13:59 -05:00
Aaron Rainbolt
2a39d5997c
security-misc split string changes 2025-09-21 16:06:11 -05:00
Patrick Schleizer
ca90feb8d5
security-misc-server placeholder
https://github.com/Kicksecure/security-misc/issues/187
2025-09-19 11:54:04 -04:00
Patrick Schleizer
f70550d015
Split the security-misc into security-misc-shared, security-misc-desktop and security-misc-server: rename files
https://github.com/Kicksecure/security-misc/issues/187
2025-09-17 14:49:28 -04:00
Patrick Schleizer
5898a6457a
typo 2025-08-21 06:45:04 -04:00
raja-grewal
e48897cc44
Merge branch 'master' into panic_limits 2025-08-21 10:27:44 +10:00
raja-grewal
add054933b
Update docs on instant reboot when kernel panic 2025-08-21 00:24:28 +00:00
Patrick Schleizer
31fd316e72
comments 2025-08-20 09:48:20 -04:00
Aaron Rainbolt
b5a36e02f1
Merge remote-tracking branch 'raja/panic_limits' into arraybolt3/trixie 2025-08-17 13:52:01 -05:00
raja-grewal
247015bcc6
Set sysctl kernel.panic=-1 2025-08-17 06:27:44 +00:00
raja-grewal
f1de0da69b
Clarify description on panics on oopses and warns 2025-08-16 04:01:12 +00:00
raja-grewal
fce86dccb6
Typo 2025-08-13 10:44:40 +10:00
Aaron Rainbolt
c33ea7be6d
Move security-misc/apt-get-update* to helper-scripts 2025-08-10 15:23:48 -05:00
Aaron Rainbolt
5f2425ba6f
Merge branch 'arraybolt3/emerg-shutdown' into arraybolt3/trixie 2025-08-06 20:21:01 -05:00
Aaron Rainbolt
3a77abe5c9
Port hardening options from kloak to emerg-shutdown, fix new compiler warnings 2025-08-06 20:11:02 -05:00
Aaron Rainbolt
44e7d3059a
Integrate emerg-shutdown into the initramfs 2025-08-06 19:10:14 -05:00
Aaron Rainbolt
86f44063eb
Port to Trixie. 2025-08-05 22:58:06 -05:00
raja-grewal
45d20dd972
Upgrade sysctls and docs on kernel panics 2025-08-06 02:35:15 +00:00
Aaron Rainbolt
63f2909341
Fix emerg-shutdown and ensure-shutdown libexec scripts, start emerg-shutdown and ensure-shutdown earlier 2025-08-03 15:00:14 -05:00
Patrick Schleizer
92bcd824e4
also parse /usr/local/etc 2025-08-03 07:17:25 -04:00
Patrick Schleizer
b9416fa77a
validate configuration file 2025-08-03 07:15:41 -04:00
Aaron Rainbolt
1a60da71ed
emerg-shutdown: Add shutdown timeout for preventing stuck shutdowns, briefly document feature set and usage 2025-07-29 21:16:51 -05:00
Aaron Rainbolt
e42078e90d
emerg-shutdown: fix the hang-on-shutdown bug, add autodetection of new keyboards, shutdown key configuration, and instant shutdown option 2025-07-28 20:43:54 -05:00
Aaron Rainbolt
e387086de4
Allow specifying alternative keys in panic key combo, fix optical disk eject handling 2025-07-15 00:01:50 -05:00
Aaron Rainbolt
2a7071055f
Merge branch 'master' into arraybolt3/emerg-shutdown 2025-07-13 15:21:34 -05:00
Aaron Rainbolt
109c013467
Add comment related to approx package caching proxy 2025-06-12 01:08:34 -05:00
Patrick Schleizer
3e102df765
fix 2025-05-28 08:37:03 -04:00
Patrick Schleizer
142ea21189
fix 2025-05-21 12:42:16 -04:00
Patrick Schleizer
a969fa350e
fix 2025-05-21 12:40:27 -04:00
Patrick Schleizer
f023651c98
nounset 2025-05-21 12:35:37 -04:00
Patrick Schleizer
f086787464
fix 2025-05-21 12:35:23 -04:00
Patrick Schleizer
d7643954d1
minor 2025-05-21 12:33:50 -04:00
Patrick Schleizer
aa905fc887
further validation of output of faillock 2025-05-21 12:32:16 -04:00
Patrick Schleizer
92d3a36a0f
fix 2025-05-21 12:29:01 -04:00
Patrick Schleizer
2c1abb23e0
output 2025-05-21 12:26:46 -04:00
Patrick Schleizer
0801b96ae7
output 2025-05-21 12:25:49 -04:00
Patrick Schleizer
ef8515ba82
improve error handling 2025-05-21 12:23:45 -04:00
Patrick Schleizer
784867e24b
fix 2025-05-21 12:21:45 -04:00