Commit Graph

58 Commits

Author SHA1 Message Date
7cf51a1b43 Checking job queue instead of dbus 2023-01-06 21:32:57 -05:00
4b7053a635 Update wipe-ram.sh 2023-01-06 13:53:28 -05:00
779ad24b57 Update wipe-ram-needshutdown.sh 2023-01-06 13:53:18 -05:00
d45ba826bc Update module-setup.sh 2023-01-06 13:53:10 -05:00
b3d4314a06 Update wipe-ram.sh 2023-01-06 13:52:51 -05:00
3387725017 Update wipe-ram-needshutdown.sh 2023-01-06 13:52:42 -05:00
ec68ee6ded Update module-setup.sh 2023-01-06 13:52:32 -05:00
37a5264696 Update wipe-ram.sh 2023-01-06 13:47:34 -05:00
7ac45acd0f Update wipe-ram-needshutdown.sh 2023-01-06 13:47:23 -05:00
114a37fcd3 Update module-setup.sh 2023-01-06 13:47:14 -05:00
1eeb32b7b9 Update wipe-ram.sh 2023-01-06 13:47:01 -05:00
c5accc5ad1 Update wipe-ram-needshutdown.sh 2023-01-06 13:46:51 -05:00
f9ebc3cfa8 Update module-setup.sh 2023-01-06 13:46:40 -05:00
d67d3c1d7d Update wipe-ram.sh 2023-01-06 12:51:18 -05:00
7fa64d6842 Update wipe-ram-needshutdown.sh 2023-01-06 12:50:58 -05:00
14c7239681 Update module-setup.sh 2023-01-06 12:50:42 -05:00
73913ea5af Added checks 2023-01-06 12:49:34 -05:00
a7015f4ddf added files 2023-01-06 10:50:34 -05:00
82da4ed18f comments 2022-07-28 09:56:24 -04:00
a6bee1493d cold-boot-attack-defense wait longer to make messages readable by user 2022-07-28 09:55:12 -04:00
053142cdb5 fix 2022-07-26 10:00:21 -04:00
69af8be7b8 drop_caches before and after sdmem 2022-07-02 19:10:55 -04:00
67bdd58bf2 sync 2022-07-02 19:07:06 -04:00
973f117aa6 wipe RAM at shutdown: Ensure any remaining disk cache is erased by Linux' memory poisoning
by running:
`echo 3 > /proc/sys/vm/drop_caches`

Inspired by Tails:
https://gitlab.tails.boum.org/tails/tails/-/blob/master/config/chroot_local-includes/usr/local/lib/initramfs-pre-shutdown-hook
2022-07-02 18:12:36 -04:00
95187bd357 fix 2022-07-02 17:21:33 -04:00
148a050468 fix 2022-07-02 16:03:45 -04:00
82e7863d5b improvement 2022-07-02 16:02:28 -04:00
1144b39e5e debugging 2022-07-02 15:50:59 -04:00
c29b21c08a output 2022-07-02 15:45:19 -04:00
d34fe21963 fix 2022-07-02 15:32:42 -04:00
32fdcf522b - introduce wiperam=skip kernel parameter to skip wipe ram
- introduce `wiperam=force` kernel parameter to force wipe ram inside VMs
2022-06-30 14:47:45 -04:00
036f518ddc improvement 2022-06-30 13:56:29 -04:00
0e2fae2b69 skip ram wipe inside VMs
https://forums.whonix.org/t/is-ram-wipe-possible-inside-whonix-cold-boot-attack-defense/5596/40
2022-06-30 13:50:18 -04:00
e06405c7be undo 2022-06-29 16:56:16 -04:00
1b97d9cb76 fix 2022-06-29 16:30:31 -04:00
92c543e71f output 2022-06-29 16:24:52 -04:00
d4161b2748 output 2022-06-29 16:23:42 -04:00
1ce7b27297 improvement 2022-06-29 16:23:12 -04:00
f5e0c1742a credits 2022-06-29 16:02:05 -04:00
42e24f3c24 update file names 2022-06-29 15:54:49 -04:00
52aaac9b6d rename 2022-06-29 15:53:52 -04:00
619bb3cf4d rename 2022-06-29 15:53:24 -04:00
2a8504cf1b move 2022-06-29 15:51:14 -04:00
af8b211c23 improvements 2022-06-29 15:50:20 -04:00
e9cd5d934b copyright 2022-06-29 15:24:27 -04:00
9ab81d4581 do not power off too fast so wipe ram messages can be read 2022-06-29 15:22:00 -04:00
19439033de copyright 2022-06-29 15:19:56 -04:00
fc202ede16 delete no longer required usr/lib/dracut/modules.d/40sdmem-security-misc/README.md 2022-06-29 15:18:28 -04:00
6d3a08a936 improvements 2022-06-29 15:17:40 -04:00
8a072437cc ram wipe on shutdown: fix, added need_shutdown hook
Otherwise dracut does not run on shutdown.

Without `need_shutdown` file `/run/initramfs/.need_shutdown` does not get created.
And without that file `/usr/lib/dracut/dracut-initramfs-restore`,
which itself is started by `/lib/systemd/system/dracut-shutdown.service` does nothing.
2022-06-29 14:13:30 -04:00