projects
/
kconfig-hardened-check.git
/ history
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
first
⋅
prev
⋅
next
Fix pylint warning: formatting a regular string which could be a f-string (III)
[kconfig-hardened-check.git]
/
kconfig_hardened_check
/
__init__.py
2022-08-13
Alexander Popov
Check hardened_usercopy in the cmdline
blob
|
commitdiff
|
raw
|
diff to current
2022-08-13
Alexander Popov
Add the comment about vm.mmap_min_addr sysctl (for...
blob
|
commitdiff
|
raw
|
diff to current
2022-08-13
Alexander Popov
SECURITY_DMESG_RESTRICT is more about cutting attack...
blob
|
commitdiff
|
raw
|
diff to current
2022-07-21
Alexander Popov
Improve the slab_common.usercopy_fallback check
blob
|
commitdiff
|
raw
|
diff to current
2022-07-21
Alexander Popov
Add the slab_common.usercopy_fallback check
blob
|
commitdiff
|
raw
|
diff to current
2022-07-21
Alexander Popov
Improve the STACKPROTECTOR check
blob
|
commitdiff
|
raw
|
diff to current
2022-07-21
Alexander Popov
Don't mention LKDTM
blob
|
commitdiff
|
raw
|
diff to current
2022-07-17
Alexander Popov
Check ARM64_BTI for userspace hardening
blob
|
commitdiff
|
raw
|
diff to current
2022-07-17
Alexander Popov
Check ARM64_PTR_AUTH for userspace hardening
blob
|
commitdiff
|
raw
|
diff to current
2022-07-17
Alexander Popov
Add rodata check for ARM64
blob
|
commitdiff
|
raw
|
diff to current
2022-07-11
Alexander Popov
Add iommu.passthrough check
blob
|
commitdiff
|
raw
|
diff to current
2022-07-11
Alexander Popov
Add IOMMU_DEFAULT_PASSTHROUGH check
blob
|
commitdiff
|
raw
|
diff to current
2022-07-11
Alexander Popov
Add iommu.strict check
blob
|
commitdiff
|
raw
|
diff to current
2022-07-11
Alexander Popov
Add vsyscall check
blob
|
commitdiff
|
raw
|
diff to current
2022-07-09
Alexander Popov
Don't add CmdlineChecks in add_kconfig_checks() to...
blob
|
commitdiff
|
raw
|
diff to current
2022-07-09
Alexander Popov
Add slub_debug check
blob
|
commitdiff
|
raw
|
diff to current
2022-06-20
Alexander Popov
Add the init_on_free check
blob
|
commitdiff
|
raw
|
diff to current
2022-06-20
Alexander Popov
Add the page_poison check required for PAGE_POISONING_ZERO
blob
|
commitdiff
|
raw
|
diff to current
2022-06-20
Alexander Popov
Rewrite the slab_nomerge check
blob
|
commitdiff
|
raw
|
diff to current
2022-06-20
Alexander Popov
Rewrite the randomize_kstack_offset check
blob
|
commitdiff
|
raw
|
diff to current
2022-06-19
Alexander Popov
Check that a kconfig option value is sane
blob
|
commitdiff
|
raw
|
diff to current
2022-06-19
Alexander Popov
Add a tricky check for init_on_alloc and INIT_ON_ALLOC_...
blob
|
commitdiff
|
raw
|
diff to current
2022-06-19
Alexander Popov
Move the add_cmdline_checks() call earlier
blob
|
commitdiff
|
raw
|
diff to current
2022-06-08
Alexander Popov
Don't check __name__ in __init__.py (it can't run separ...
blob
|
commitdiff
|
raw
|
diff to current
2022-06-08
Alexander Popov
Fix the pylint warning about isinstance
blob
|
commitdiff
|
raw
|
diff to current
2022-06-08
Alexander Popov
Drop unneeded properties of ComplexOptCheck
blob
|
commitdiff
|
raw
|
diff to current
2022-06-08
Alexander Popov
Turn some error conditions into assertions (part 4)
blob
|
commitdiff
|
raw
|
diff to current
2022-06-08
Alexander Popov
Turn some error conditions into assertions (part 3)
blob
|
commitdiff
|
raw
|
diff to current
2022-06-08
Alexander Popov
Turn some error conditions into assertions (part 2)
blob
|
commitdiff
|
raw
|
diff to current
2022-06-08
Alexander Popov
Turn some error conditions into assertions (part 1)
blob
|
commitdiff
|
raw
|
diff to current
2022-06-08
Alexander Popov
Drop useless checks, the ComplexOptCheck constructor...
blob
|
commitdiff
|
raw
|
diff to current
2022-05-30
Alexander Popov
Check that --config and --print are not used together
blob
|
commitdiff
|
raw
|
diff to current
2022-05-28
Alexander Popov
Merge branch 'cmdline'
blob
|
commitdiff
|
raw
|
diff to current
2022-05-28
Alexander Popov
Check the pti cmdline parameter
blob
|
commitdiff
|
raw
|
diff to current
2022-05-28
Alexander Popov
Check the slab_nomerge cmdline parameter
blob
|
commitdiff
|
raw
|
diff to current
2022-05-28
Alexander Popov
Check the randomize_kstack_offset cmdline parameter
blob
|
commitdiff
|
raw
|
diff to current
2022-05-28
Alexander Popov
Add cmdline file parsing
blob
|
commitdiff
|
raw
|
diff to current
2022-05-28
Alexander Popov
Add the infrastructure for cmdline checks
blob
|
commitdiff
|
raw
|
diff to current
2022-05-28
Alexander Popov
Add '--cmdline' argument for the tool
blob
|
commitdiff
|
raw
|
diff to current
2022-05-28
Alexander Popov
Add cmdline checks to '--print'
blob
|
commitdiff
|
raw
|
diff to current
2022-05-28
Alexander Popov
Add the CmdlineCheck class
blob
|
commitdiff
|
raw
|
diff to current
2022-05-15
Alexander Popov
Add the comment about sysrq_always_enabled
blob
|
commitdiff
|
raw
|
diff to current
2022-05-15
Alexander Popov
Add the comment about rodata
blob
|
commitdiff
|
raw
|
diff to current
2022-05-06
Alexander Popov
Add the comment about arm64.nomte
blob
|
commitdiff
|
raw
|
diff to current
2022-05-06
Alexander Popov
Add the comment about kernel.randomize_va_space
blob
|
commitdiff
|
raw
|
diff to current
2022-05-06
Alexander Popov
Add the KGDB check
blob
|
commitdiff
|
raw
|
diff to current
2022-05-06
Alexander Popov
Add RANDOMIZE_MODULE_REGION_FULL for arm64
blob
|
commitdiff
|
raw
|
diff to current
2022-04-28
Alexander Popov
Merge pull request #62 from evdenis/master
blob
|
commitdiff
|
raw
|
diff to current
2022-04-28
Alexander Popov
Add the type property for OptCheck to fix a pylint...
blob
|
commitdiff
|
raw
|
diff to current
2022-04-27
Denis Efremov
Add BLK_DEV_FD_RAWCMD
62/head
blob
|
commitdiff
|
raw
|
diff to current
2022-04-22
Alexander Popov
Add the STACKPROTECTOR check from KSPP
blob
|
commitdiff
|
raw
|
diff to current
2022-04-22
Alexander Popov
Drop the ARM64_MTE check for userspace hardening
blob
|
commitdiff
|
raw
|
diff to current
2022-04-22
Alexander Popov
Separate out checking SECURITY_WRITABLE_HOOKS and SECUR...
blob
|
commitdiff
|
raw
|
diff to current
2022-04-22
Alexander Popov
Fix the arch condition for the SCHED_CORE check
blob
|
commitdiff
|
raw
|
diff to current
2022-04-22
Alexander Popov
Add the KSPP recommendation of ZERO_CALL_USED_REGS
blob
|
commitdiff
|
raw
|
diff to current
2022-04-22
Alexander Popov
Disabling X86_MSR is recommended by KSPP
blob
|
commitdiff
|
raw
|
diff to current
2022-04-20
Alexander Popov
Fix the bug in the verdict description for ComplexOptCheck
blob
|
commitdiff
|
raw
|
diff to current
2022-04-20
Alexander Popov
Additional check for TYPES_OF_CHECKS
blob
|
commitdiff
|
raw
|
diff to current
2022-04-20
Alexander Popov
Drop PresenceCheck; OptCheck without 'expected' paramet...
blob
|
commitdiff
|
raw
|
diff to current
2022-04-20
Alexander Popov
Add the KSPP recommendation of SCHED_CORE
blob
|
commitdiff
|
raw
|
diff to current
2022-04-20
Alexander Popov
Add the KSPP recommendation of IOMMU_DEFAULT_DMA_STRICT
blob
|
commitdiff
|
raw
|
diff to current
2022-04-20
Alexander Popov
Add the KSPP recommendation of WERROR
blob
|
commitdiff
|
raw
|
diff to current
2022-04-20
Alexander Popov
Add the KSPP recommendation of KFENCE
blob
|
commitdiff
|
raw
|
diff to current
2022-04-08
Alexander Popov
No need in BPF_UNPRIV_DEFAULT_OFF if BPF_SYSCALL is...
blob
|
commitdiff
|
raw
|
diff to current
2022-04-08
Alexander Popov
Merge branch 'from-martin-rowe'
blob
|
commitdiff
|
raw
|
diff to current
2022-03-28
Alexander Popov
Drop unneeded return values (refactoring)
blob
|
commitdiff
|
raw
|
diff to current
2022-03-26
Martin Rowe
UBSAN_SANITIZE_ALL not available on ARM
60/head
blob
|
commitdiff
|
raw
|
diff to current
2022-03-20
Alexander Popov
Add HARDEN_BRANCH_HISTORY for arm
blob
|
commitdiff
|
raw
|
diff to current
2022-03-20
Alexander Popov
Add MITIGATE_SPECTRE_BRANCH_HISTORY for arm64
blob
|
commitdiff
|
raw
|
diff to current
2022-03-18
Alexander Popov
THREAD_INFO_IN_TASK is available for ARM since v5.16
blob
|
commitdiff
|
raw
|
diff to current
2022-03-18
Alexander Popov
Merge branch 'from-martin-rowe'
blob
|
commitdiff
|
raw
|
diff to current
2022-03-15
Martin Rowe
EFI mitigations can't be enabled if EFI is not set
59/head
blob
|
commitdiff
|
raw
|
diff to current
2022-03-13
Alexander Popov
Fix the BPF_UNPRIV_DEFAULT_OFF check (it is enabled...
blob
|
commitdiff
|
raw
|
diff to current
2022-03-13
Alexander Popov
Add CONFIG_SLS vs CVE-2021-26341 in Straight-Line-Specu...
blob
|
commitdiff
|
raw
|
diff to current
2022-03-13
Alexander Popov
Add the comment that l1d_flush is a part of the l1tf...
blob
|
commitdiff
|
raw
|
diff to current
2022-03-13
Alexander Popov
Add BPF_UNPRIV_DEFAULT_OFF to cut_attack_surface
blob
|
commitdiff
|
raw
|
diff to current
2022-03-05
Alexander Popov
Use the option type instead of calling hasattr()
blob
|
commitdiff
|
raw
|
diff to current
2022-03-05
Alexander Popov
Merge branch 'refactoring'
blob
|
commitdiff
|
raw
|
diff to current
2022-02-14
Alexander Popov
Introduce the json_dump() class method
refactoring
blob
|
commitdiff
|
raw
|
diff to current
2022-02-14
Alexander Popov
Improve 'type' for ComplexOptCheck and PresenceCheck...
blob
|
commitdiff
|
raw
|
diff to current
2022-02-14
Alexander Popov
Make populate_with_data() aware of data type
blob
|
commitdiff
|
raw
|
diff to current
2022-02-14
Alexander Popov
Add 'type' for PresenceCheck and VersionCheck
blob
|
commitdiff
|
raw
|
diff to current
2022-02-14
Alexander Popov
Rename VerCheck to VersionCheck
blob
|
commitdiff
|
raw
|
diff to current
2022-02-14
Alexander Popov
Add more ComplexOptCheck validation
blob
|
commitdiff
|
raw
|
diff to current
2022-02-14
Alexander Popov
Improve print_unknown_options()
blob
|
commitdiff
|
raw
|
diff to current
2022-02-14
Alexander Popov
Remove 'CONFIG_' hardcoding
blob
|
commitdiff
|
raw
|
diff to current
2022-02-11
Alexander Popov
Merge branch 'refactoring'
blob
|
commitdiff
|
raw
|
diff to current
2022-02-11
Alexander Popov
Refactor the OR logic code
blob
|
commitdiff
|
raw
|
diff to current
2022-02-11
Alexander Popov
Rename config to kconfig where needed (part II)
blob
|
commitdiff
|
raw
|
diff to current
2022-01-22
Alexander Popov
Extract populate_with_data() from perform_checks()
blob
|
commitdiff
|
raw
|
diff to current
2022-01-22
Alexander Popov
Rename config to kconfig where needed
blob
|
commitdiff
|
raw
|
diff to current
2022-01-22
Alexander Popov
Print the type of a check in the json mode
blob
|
commitdiff
|
raw
|
diff to current
2022-01-22
Alexander Popov
ComplexOptCheck type has the type of the first opt...
blob
|
commitdiff
|
raw
|
diff to current
2022-01-21
Alexander Popov
Do more output tuning
blob
|
commitdiff
|
raw
|
diff to current
2022-01-21
Alexander Popov
Add check type
blob
|
commitdiff
|
raw
|
diff to current
2022-01-21
Alexander Popov
Print compactly
blob
|
commitdiff
|
raw
|
diff to current
2022-01-21
Alexander Popov
Introduce KconfigCheck class
blob
|
commitdiff
|
raw
|
diff to current
2022-01-21
Alexander Popov
Fix TRIM_UNUSED_KSYMS check
blob
|
commitdiff
|
raw
|
diff to current
2021-12-24
Alexander Popov
Add l1d_flush (for future reference)
blob
|
commitdiff
|
raw
|
diff to current
2021-12-05
Alexander Popov
Add ARM64_PTR_AUTH_KERNEL extracted from ARM64_PTR_AUTH
blob
|
commitdiff
|
raw
|
diff to current
next