Commit Graph

709 Commits

Author SHA1 Message Date
071c64dc41 enable 'set -e' 2019-12-20 06:01:49 -05:00
b97c66707c minor 2019-12-20 05:59:05 -05:00
17b4f12276 output 2019-12-20 05:58:42 -05:00
918cbb4e25 output 2019-12-20 05:51:25 -05:00
c8cf09a4cb output 2019-12-20 05:50:16 -05:00
46466c12ad parse drop-in config folder rather than only one config file 2019-12-20 05:49:11 -05:00
66fd31189d improve output if set-user-id / set-group-id is set 2019-12-20 05:37:33 -05:00
6dd6530fa5 remove hardening-enable
please invent package security-paranoid instead

https://forums.whonix.org/t/security-hardening-tool-usr-bin-hardening-enable-by-security-misc/8609
2019-12-20 05:32:26 -05:00
af0f074987 remount /lib with nosuid,nodev
https://forums.whonix.org/t/re-mount-home-and-other-with-noexec-and-nosuid-among-other-useful-mount-options-for-better-security/7707/22
2019-12-20 05:27:11 -05:00
a135ae9400 use must manually enable permission-hardening.service
until development finished
2019-12-20 05:22:59 -05:00
fa6f1e1568 output 2019-12-20 05:19:39 -05:00
a26cb94bfd globstar no longer required 2019-12-20 04:49:21 -05:00
c66e9abe18 comment 2019-12-20 04:48:57 -05:00
d1d0afff34 fix
fso: /lib/
usr/lib/security-misc/permission-hardening: line 19: /usr/bin/stat: Argument list too long

https://forums.whonix.org/t/kernel-hardening/7296/326
2019-12-20 04:48:02 -05:00
e74d2e4f94 output 2019-12-20 04:23:14 -05:00
eb86359033 refactoring 2019-12-20 04:20:05 -05:00
bb84fca184 refactoring 2019-12-20 04:08:46 -05:00
f92b414195 refactoring 2019-12-20 04:06:28 -05:00
4c44871e9d comment 2019-12-20 04:02:05 -05:00
6876a2eaa8 comment 2019-12-20 04:01:40 -05:00
35c4fce61b fix "dpkg-statoverride: warning: stripping trailing /" 2019-12-20 03:54:46 -05:00
9bd9012ab1 refactoring 2019-12-20 03:46:50 -05:00
55933f8876 refactoring 2019-12-20 03:43:36 -05:00
9e493a9f48 refactoring 2019-12-20 03:42:09 -05:00
b92a690c16 refactoring 2019-12-20 03:40:47 -05:00
98535e3a2b refactoring 2019-12-20 03:39:25 -05:00
ecbba2fd61 refactoring 2019-12-20 03:38:39 -05:00
20b8a407ac refactoring 2019-12-20 03:25:17 -05:00
6cd9eb44fb refactoring 2019-12-20 03:24:07 -05:00
706dba104d code simplification 2019-12-20 03:19:12 -05:00
01dd567f8b fix, if fso has exactly the mode we want (not 3 instead of 4 string length), not need to reset it 2019-12-20 03:16:43 -05:00
4f65b0fc1e refactoring 2019-12-20 03:13:27 -05:00
bfee6b60cb comment 2019-12-20 03:11:11 -05:00
d64cdc1247 refactoring 2019-12-20 03:04:41 -05:00
7c5c65a6c1 comment 2019-12-20 03:04:13 -05:00
b31d8cd3fc fix 2019-12-20 03:03:40 -05:00
c626290673 refactoring 2019-12-20 03:02:26 -05:00
d5ff1d6f28 refactoring 2019-12-20 03:00:39 -05:00
640ca1d24d skip symlinks
https://forums.whonix.org/t/kernel-hardening/7296/323?
2019-12-20 02:57:57 -05:00
cc8f795799 comment 2019-12-20 02:47:04 -05:00
4e5b222a08 comment 2019-12-20 02:43:33 -05:00
fa895ee11e refactoring 2019-12-20 02:40:42 -05:00
2c163bf439 check string length of permission variable
https://forums.whonix.org/t/kernel-hardening/7296/322
2019-12-20 02:39:53 -05:00
a89befd902 code simplification 2019-12-20 02:20:54 -05:00
72812da63f comment 2019-12-20 02:16:32 -05:00
39a41cc27b refactoring 2019-12-20 02:14:45 -05:00
2ed6452590 downgrade to info 2019-12-20 02:12:43 -05:00
a5e55dfcfc quotes 2019-12-20 02:11:39 -05:00
3187cee4fb output 2019-12-20 02:10:13 -05:00
5160b4c781 disable xtrace 2019-12-20 02:08:05 -05:00