Patrick Schleizer
|
ef0eb5f7a0
|
refactoring
|
2024-10-28 05:06:26 -04:00 |
|
Patrick Schleizer
|
fdd1f4b7f8
|
refactoring
|
2024-10-28 05:06:05 -04:00 |
|
Patrick Schleizer
|
d00235897d
|
hide-hardware-info: also parse /usr/local/etc/hide-hardware-info.d/*.conf
|
2024-10-28 05:03:59 -04:00 |
|
Patrick Schleizer
|
6c2e808b9f
|
refactoring
|
2024-10-28 05:03:20 -04:00 |
|
Patrick Schleizer
|
566cda5e4b
|
output
|
2024-10-21 05:47:38 -04:00 |
|
Patrick Schleizer
|
5991a23049
|
comment
|
2024-10-21 05:47:25 -04:00 |
|
Aaron Rainbolt
|
690e8dd826
|
Avoid faillock lock/tally reset on reboot or timeout
|
2024-10-19 23:52:51 -05:00 |
|
Patrick Schleizer
|
b6433309fd
|
use end-of-options
|
2024-10-18 12:45:02 -04:00 |
|
raja-grewal
|
09fe46adc9
|
Clarify KSPP compliance header for the undocumented case
|
2024-10-14 02:54:30 +00:00 |
|
raja-grewal
|
0c0774f6c0
|
Merge branch 'master' into text_2
|
2024-10-06 10:48:52 +00:00 |
|
Patrick Schleizer
|
0e3ffa3f11
|
no longer set kernel.unprivileged_userns_clone=0
because it breaks too much
fixes https://github.com/Kicksecure/security-misc/issues/274
|
2024-10-03 02:58:58 -04:00 |
|
Patrick Schleizer
|
f401d94d5e
|
expand documentation on kernel.unprivileged_userns_clone=0 sysctl
https://github.com/Kicksecure/security-misc/issues/274
|
2024-10-03 02:44:06 -04:00 |
|
raja-grewal
|
f3b50a23c9
|
Add reference on unprivileged_userns_restriction
|
2024-09-26 13:10:01 +00:00 |
|
raja-grewal
|
39d063d494
|
Add KSPP=no definition
|
2024-09-26 13:09:21 +00:00 |
|
raja-grewal
|
870ff88605
|
Comment on Flatpak requiring unprivileged user namespaces
|
2024-09-25 10:01:45 +10:00 |
|
Patrick Schleizer
|
563a898013
|
Merge pull request #265 from raja-grewal/mmap_min_addr
Set `sysctl vm.mmap_min_addr=65536`
|
2024-09-04 10:11:48 -04:00 |
|
Patrick Schleizer
|
175945ec9a
|
Merge pull request #268 from raja-grewal/panic_on_warn
Enable `panic_on_warn=1`
|
2024-09-04 10:05:47 -04:00 |
|
raja-grewal
|
7393ba1591
|
Typo
|
2024-09-04 23:23:24 +10:00 |
|
Raja Grewal
|
6294729c8e
|
Follow-up on f70fe308a9
|
2024-08-29 15:34:24 +10:00 |
|
Raja Grewal
|
3101035a3f
|
Enable panic_on_warn=1
|
2024-08-29 01:57:32 +10:00 |
|
Patrick Schleizer
|
f70fe308a9
|
no longer set sysctl fs.binfmt_misc.status=0 /
no longer disallow registering interpreters for miscellaneous binary formats
causing file/folder permissions issue `d????????? ? ? ? ? ? .`
Firefox no longer starting (probably not not a Firefox issue)
https://github.com/Kicksecure/security-misc/issues/267
|
2024-08-28 06:49:50 -04:00 |
|
Raja Grewal
|
9e91c98cc9
|
Add details on BPF hardening and split the sysctl s
|
2024-08-26 12:40:04 +10:00 |
|
Raja Grewal
|
2c356e8b0e
|
Add KSPP notice definitions
|
2024-08-26 11:34:12 +10:00 |
|
Raja Grewal
|
ac6602ac35
|
Add detail on disabling user namespaces breaking UPower
|
2024-08-26 11:19:20 +10:00 |
|
raja-grewal
|
9dbd200be4
|
Merge branch 'Kicksecure:master' into kspp_compliance
|
2024-08-26 11:08:21 +10:00 |
|
Patrick Schleizer
|
73900b59db
|
Merge pull request #263 from raja-grewal/max_user_namespaces
Provide option to disable user namespaces
|
2024-08-25 11:00:51 -04:00 |
|
Patrick Schleizer
|
43d13b70f1
|
Merge remote-tracking branch 'raja/syntax'
|
2024-08-25 10:55:52 -04:00 |
|
Raja Grewal
|
32de5e7c49
|
Add details on oopses and warnings
|
2024-08-25 12:57:22 +10:00 |
|
Raja Grewal
|
e4909b5e28
|
Add details on kernel panics
|
2024-08-25 12:47:04 +10:00 |
|
Raja Grewal
|
56b28e3826
|
Typo
|
2024-08-19 11:50:08 +10:00 |
|
Raja Grewal
|
e61027a40e
|
Set sysctl vm.mmap_min_addr=65536
|
2024-08-19 11:32:20 +10:00 |
|
Raja Grewal
|
94dab1b7c5
|
Partial compliance with the KSPP on kernel panics
|
2024-08-19 10:53:05 +10:00 |
|
Raja Grewal
|
1f51d4eeb2
|
Add details on user namespaces
|
2024-08-18 13:53:11 +10:00 |
|
Raja Grewal
|
248e094b8e
|
Include KSPP compliance notices
|
2024-08-17 01:06:21 +10:00 |
|
Raja Grewal
|
759aee8150
|
Provide option to disable user namespaces
|
2024-08-16 22:54:57 +10:00 |
|
Raja Grewal
|
fae586c3c5
|
Patch bug in existing rp_filter sysctl
|
2024-08-16 19:23:48 +10:00 |
|
Patrick Schleizer
|
305467c652
|
Merge pull request #245 from raja-grewal/blacklist_to_disable
Update `/etc/modprobe.d/*`
|
2024-08-16 04:25:43 -04:00 |
|
raja-grewal
|
81bf7a8f90
|
Merge branch 'Kicksecure:master' into docs
|
2024-08-16 16:57:01 +10:00 |
|
Patrick Schleizer
|
ef60c5b153
|
Merge pull request #249 from raja-grewal/binfmt_misc
Disallow registering interpreters for miscellaneous binary formats
|
2024-08-16 02:43:57 -04:00 |
|
Raja Grewal
|
cea8e75378
|
Consistent formating
|
2024-08-16 14:55:22 +10:00 |
|
Raja Grewal
|
84376d23fc
|
Add details on ASLR and move to user space section
|
2024-08-16 13:39:11 +10:00 |
|
Raja Grewal
|
9212a4e937
|
Typos
|
2024-08-16 13:12:07 +10:00 |
|
Raja Grewal
|
23a77d4973
|
Simplify syntax of some network-related sysctl 's
|
2024-08-16 12:46:51 +10:00 |
|
raja-grewal
|
be9308e490
|
Merge branch 'Kicksecure:master' into docs
|
2024-08-16 11:45:43 +10:00 |
|
Patrick Schleizer
|
dfd1c97168
|
Merge pull request #248 from raja-grewal/secure_redirects
Re-enable (default) `secure_redirects` for ICMP redirect messages
|
2024-08-15 13:46:30 -04:00 |
|
Raja Grewal
|
b552b92401
|
Add references on fs.binfmt_misc.status
|
2024-08-15 11:54:21 +10:00 |
|
Raja Grewal
|
326d82a9be
|
Revert "Provide optional sysctl fs.binfmt_misc.status=0 "
This reverts commit debd7a7b7a .
|
2024-08-15 11:46:56 +10:00 |
|
Raja Grewal
|
f8fa89b245
|
Add details on tcp_timestamps
|
2024-08-09 14:21:59 +10:00 |
|
Raja Grewal
|
077bc48a26
|
Add reference on rp_filter
|
2024-08-09 13:35:33 +10:00 |
|
Raja Grewal
|
d8bcec881f
|
Add some notices for future Debian 13 rebase
|
2024-08-09 13:33:32 +10:00 |
|