X-Git-Url: https://jxself.org/git/?a=blobdiff_plain;f=README.md;h=714bb4af1431f2d5c8bb93d674ad1643b0bf5918;hb=bfb9a61d90a5198b08380b7fb4383426528956f9;hp=735a89120ca51692f42c1606bfa271dc87344546;hpb=eec17478288683baa6f3b54ccf5862414f767e18;p=kconfig-hardened-check.git diff --git a/README.md b/README.md index 735a891..714bb4a 100644 --- a/README.md +++ b/README.md @@ -79,12 +79,13 @@ options: (also supports *.gz files) -l CMDLINE, --cmdline CMDLINE check the security hardening options in the kernel cmdline file + (contents of /proc/cmdline) -p {X86_64,X86_32,ARM64,ARM}, --print {X86_64,X86_32,ARM64,ARM} print the security hardening recommendations for the selected microarchitecture -g {X86_64,X86_32,ARM64,ARM}, --generate {X86_64,X86_32,ARM64,ARM} - generate a Kconfig fragment with the security hardening options for - the selected microarchitecture + generate a Kconfig fragment with the security hardening options + for the selected microarchitecture ``` ## Output modes @@ -344,7 +345,7 @@ sysrq_always_enabled |cmdline| is not set | my |cut_att ## Generating a Kconfig fragment with the security hardening options -With the `-g` argument the tool generates a Kconfig fragment with the security hardening options for the selected microarchitecture. +With the `-g` argument, the tool generates a Kconfig fragment with the security hardening options for the selected microarchitecture. This Kconfig fragment can be merged with the existing Linux kernel config: ```