projects
/
kconfig-hardened-check.git
/ history
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
first ⋅ prev ⋅
next
Add the "MAGIC_SYSRQ_SERIAL" check
[kconfig-hardened-check.git]
/
kernel_hardening_checker
/
checks.py
2024-06-16
Alexander Popov
Add the "MAGIC_SYSRQ_SERIAL" check
blob
|
commitdiff
|
raw
2024-06-16
Alexander Popov
Add the "kernel.sysrq" check
blob
|
commitdiff
|
raw
|
diff to current
2024-06-15
Alexander Popov
Add the MAGIC_SYSRQ_DEFAULT_ENABLE check
blob
|
commitdiff
|
raw
|
diff to current
2024-06-15
Alexander Popov
Sync with KSPP: update the `decision` for some checks
blob
|
commitdiff
|
raw
|
diff to current
2024-06-15
Alexander Popov
ruff: Fix EXE001 "Shebang is present but file is not...
blob
|
commitdiff
|
raw
|
diff to current
2024-06-10
Alexander Popov
Add the comment about 'if arch' for the 'cut_attack_sur...
blob
|
commitdiff
|
raw
|
diff to current
2024-06-09
Alexander Popov
Merge branch 'scs-pac'
blob
|
commitdiff
|
raw
|
diff to current
2024-06-09
Alexander Popov
Merge branch 'page-table-check'
blob
|
commitdiff
|
raw
|
diff to current
2024-06-02
Alexander Popov
Merge branch 'master' into open-check
blob
|
commitdiff
|
raw
|
diff to current
2024-06-02
Alexander Popov
Check MITIGATION_SPECTRE_BHI and spectre_bhi
blob
|
commitdiff
|
raw
|
diff to current
2024-06-02
Alexander Popov
Check MITIGATION_RFDS and reg_file_data_sampling
blob
|
commitdiff
|
raw
|
diff to current
2024-06-02
Alexander Popov
Add the new name of SPECULATION_MITIGATIONS
blob
|
commitdiff
|
raw
|
diff to current
2024-06-02
Alexander Popov
Add the new names of RETPOLINE, CPU_SRSO, SLS
blob
|
commitdiff
|
raw
|
diff to current
2024-06-02
Alexander Popov
Add the new name of PAGE_TABLE_ISOLATION
blob
|
commitdiff
|
raw
|
diff to current
2024-05-22
jvoisin
Add two PAGE_TABLE_CHECK related checks from kspp
140/head
blob
|
commitdiff
|
raw
|
diff to current
2024-05-19
Julien Voisin
Merge branch 'master' into scs_pac
131/head
blob
|
commitdiff
|
raw
|
diff to current
2024-05-14
Alexander Popov
Merge remote-tracking branch 'origin/pylint'
blob
|
commitdiff
|
raw
|
diff to current
2024-05-14
Alexander Popov
Don't use TODO to avoid pylint warnings
136/head
blob
|
commitdiff
|
raw
|
diff to current
2024-05-14
Alexander Popov
Drop 'disable=invalid-name' for pylint
blob
|
commitdiff
|
raw
|
diff to current
2024-05-13
Alexander Popov
Merge branch 'typing'
blob
|
commitdiff
|
raw
|
diff to current
2024-05-13
Alexander Popov
Style fixes for engine import
blob
|
commitdiff
|
raw
|
diff to current
2024-05-13
Alexander Popov
Add more precise typing for checklist: List[ChecklistOb...
blob
|
commitdiff
|
raw
|
diff to current
2024-05-12
Alexander Popov
Add more typing annotations to checks.py
blob
|
commitdiff
|
raw
|
diff to current
2024-05-03
jvoisin
Add a check for CONFIG_UNWIND_PATCH_PAC_INTO_SCS
blob
|
commitdiff
|
raw
|
diff to current
2024-05-03
Julien Voisin
Merge branch 'master' into typing
blob
|
commitdiff
|
raw
|
diff to current
2024-05-02
Alexander Popov
Merge branch 'skip_sysctl'
blob
|
commitdiff
|
raw
|
diff to current
2024-05-02
Alexander Popov
Style fixes, should be no functional changes
125/head
blob
|
commitdiff
|
raw
|
diff to current
2024-05-02
Alexander Popov
Fix the reason and decision of the KEXEC_CORE check
blob
|
commitdiff
|
raw
|
diff to current
2024-05-02
Alexander Popov
Fix the reason and decision of the BPF_JIT check
blob
|
commitdiff
|
raw
|
diff to current
2024-05-02
Alexander Popov
Restore the `dev.tty.legacy_tiocsti` check
blob
|
commitdiff
|
raw
|
diff to current
2024-05-02
Alexander Popov
Use CONFIG_LOCALVERSION instead of CONFIG_DEFAULT_INIT...
blob
|
commitdiff
|
raw
|
diff to current
2024-05-02
Eneas U de Queiroz
skip kernel.modules_disabled if MODULES not set
blob
|
commitdiff
|
raw
|
diff to current
2024-05-02
Eneas U de Queiroz
Skip unprivileged_userfaultfd if USERFAULTFD unset
blob
|
commitdiff
|
raw
|
diff to current
2024-05-02
Eneas U de Queiroz
Don't fail if dev.tty.legacy_tiocsti not found
blob
|
commitdiff
|
raw
|
diff to current
2024-05-02
Eneas U de Queiroz
Skip unprivileged_bpf_disabled if BPF_SYSCALL not set
blob
|
commitdiff
|
raw
|
diff to current
2024-05-02
Eneas U de Queiroz
Skip kexec_load_disabled if KEXEC_CORE is not set
blob
|
commitdiff
|
raw
|
diff to current
2024-05-02
Eneas U de Queiroz
Skip bpf_jit_harden sysctl if BPF_JIT is not set
blob
|
commitdiff
|
raw
|
diff to current
2024-04-30
Alexander Popov
Merge branch 'cpu_depend'
blob
|
commitdiff
|
raw
|
diff to current
2024-04-30
jvoisin
Add some lightweight typing
blob
|
commitdiff
|
raw
|
diff to current
2024-04-30
Alexander Popov
Fix the reason and decision for CPU_SUP_INTEL
123/head
blob
|
commitdiff
|
raw
|
diff to current
2024-04-30
Alexander Popov
Style fixes
blob
|
commitdiff
|
raw
|
diff to current
2024-04-23
Eneas U de Queiroz
Skip CPU-dependent checks if CPU is not supported
blob
|
commitdiff
|
raw
|
diff to current
2024-04-18
Alexander Popov
Add the BLK_DEV_WRITE_MOUNTED/bdev_allow_write_mounted...
blob
|
commitdiff
|
raw
|
diff to current
2024-04-17
Alexander Popov
Merge branch 'shstk'
blob
|
commitdiff
|
raw
|
diff to current
2024-04-17
Alexander Popov
Fix 'decision' for the X86_USER_SHADOW_STACK check
120/head
blob
|
commitdiff
|
raw
|
diff to current
2024-04-15
jvoisin
Add a check for X86_USER_SHADOW_STACK
blob
|
commitdiff
|
raw
|
diff to current
2024-03-30
Alexander Popov
Add a comment that 'user.max_user_namespaces=0' may...
blob
|
commitdiff
|
raw
|
diff to current
2024-03-25
Alexander Popov
Improve the CONFIG_CFI_CLANG checks (add the CONFIG_CC_...
blob
|
commitdiff
|
raw
|
diff to current
2024-03-25
Alexander Popov
Drop the GCC_PLUGINS check (checking CC_IS_GCC is enough)
blob
|
commitdiff
|
raw
|
diff to current
2024-03-25
Alexander Popov
Add the CONFIG_CC_IS_GCC dependency for gcc plugins
blob
|
commitdiff
|
raw
|
diff to current
2024-03-25
Alexander Popov
Don't require GCC_PLUGINS separately
blob
|
commitdiff
|
raw
|
diff to current
2024-03-24
Alexander Popov
Rename the 'my' check decision to 'a13xp0p0v'
blob
|
commitdiff
|
raw
|
diff to current
2024-03-11
Alexander Popov
Improve the DEBUG_CREDENTIALS check
blob
|
commitdiff
|
raw
|
diff to current
2024-03-10
Alexander Popov
Fix the false result of the REFCOUNT_FULL check for...
blob
|
commitdiff
|
raw
|
diff to current
2024-03-09
Alexander Popov
Use 3 numbers in the VersionCheck constructor
blob
|
commitdiff
|
raw
|
diff to current
2024-03-04
Alexander Popov
Add the ia32_emulation check
blob
|
commitdiff
|
raw
|
diff to current
2024-02-19
Alexander Popov
Add MODULE_SIG_SHA3_512 as a valid option
blob
|
commitdiff
|
raw
|
diff to current
2024-02-17
Alexander Popov
Make LOCKDOWN_LSM 'self_protection', not 'security_policy'
blob
|
commitdiff
|
raw
|
diff to current
2024-01-16
Alexander Popov
Improve the check of DEBUG_NOTIFIERS feature (part 2)
blob
|
commitdiff
|
raw
|
diff to current
2024-01-16
Alexander Popov
Improve the check of DEBUG_NOTIFIERS feature
blob
|
commitdiff
|
raw
|
diff to current
2024-01-16
Alexander Popov
Improve the check of SCHED_STACK_END_CHECK.
blob
|
commitdiff
|
raw
|
diff to current
2024-01-16
Alexander Popov
Disable pylint too-many-locals, it's not useful for...
blob
|
commitdiff
|
raw
|
diff to current
2024-01-16
Alexander Popov
Fix pylint W0613: Unused argument 'arch'
blob
|
commitdiff
|
raw
|
diff to current
2024-01-14
Alexander Popov
UBSAN_SANITIZE_ALL is now available for ARM
blob
|
commitdiff
|
raw
|
diff to current
2023-12-30
Alexander Popov
Fix the order in the vdso32 check (part II)
blob
|
commitdiff
|
raw
|
diff to current
2023-12-30
Alexander Popov
Fix the order in the vdso32 check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-30
Alexander Popov
Fix the 'decision' for the 'AIO' check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-29
Alexander Popov
Fix the 'decision' for the 'vdso32' check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-29
Alexander Popov
Improve the comment for the 'slab_common.usercopy_fallb...
blob
|
commitdiff
|
raw
|
diff to current
2023-12-28
Alexander Popov
Fix the arch condition for the SCHED_CORE check (III)
blob
|
commitdiff
|
raw
|
diff to current
2023-12-28
Alexander Popov
Fix the arch for the CPU_SRSO check (it's available...
blob
|
commitdiff
|
raw
|
diff to current
2023-12-28
Alexander Popov
Split the HW_RANDOM_TPM check (it's enabled by default...
blob
|
commitdiff
|
raw
|
diff to current
2023-12-28
Alexander Popov
Change the 'decision' of the INIT_STACK_ALL_ZERO check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-16
Alexander Popov
Add the RANDOM_KMALLOC_CACHES check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-16
Alexander Popov
Add the SECURITY_SELINUX_DEBUG check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-16
Alexander Popov
Fix the 'decision' for the LEGACY_TIOCSTI check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-16
Alexander Popov
Add the CONFIG_LIST_HARDENED check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-09
Alexander Popov
Add the gather_data_sampling check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-09
Alexander Popov
Add the CPU_SRSO check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-09
Alexander Popov
Add the SPECULATION_MITIGATIONS check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-09
Alexander Popov
Add the spec_rstack_overflow check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-09
Alexander Popov
Add the MODULE_FORCE_LOAD check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-02
Alexander Popov
Add the check for dis_ucode_ldr
blob
|
commitdiff
|
raw
|
diff to current
2023-12-02
Alexander Popov
Add the MICROCODE_INTEL and MICROCODE_AMD checks
blob
|
commitdiff
|
raw
|
diff to current
2023-12-02
Alexander Popov
Add a check for the 'kfence.sample_interval' boot parameter
blob
|
commitdiff
|
raw
|
diff to current
2023-12-02
Alexander Popov
Add the KFENCE_SAMPLE_INTERVAL check
blob
|
commitdiff
|
raw
|
diff to current
2023-12-02
Alexander Popov
Keep the recommendation to disable kernel modules
blob
|
commitdiff
|
raw
|
diff to current
2023-12-02
Alexander Popov
Add a comment about 'kernel.modules_disabled'
blob
|
commitdiff
|
raw
|
diff to current
2023-10-18
Alexander Popov
Fix the reason for the 'kernel.yama.ptrace_scope' check
blob
|
commitdiff
|
raw
|
diff to current
2023-10-17
Alexander Popov
Fix the reason for the nosmt check
blob
|
commitdiff
|
raw
|
diff to current
2023-10-17
Alexander Popov
Add the 'dev.tty.legacy_tiocsti' check
blob
|
commitdiff
|
raw
|
diff to current
2023-10-17
Alexander Popov
Add the 'kernel.randomize_va_space' check
blob
|
commitdiff
|
raw
|
diff to current
2023-10-17
Alexander Popov
Add the 'fs.suid_dumpable' check
blob
|
commitdiff
|
raw
|
diff to current
2023-10-17
Alexander Popov
Change the reason of the COREDUMP check
blob
|
commitdiff
|
raw
|
diff to current
2023-10-17
Alexander Popov
Add the 'fs.protected_regular' check
blob
|
commitdiff
|
raw
|
diff to current
2023-10-17
Alexander Popov
Add the 'fs.protected_fifos' check
blob
|
commitdiff
|
raw
|
diff to current
2023-10-17
Alexander Popov
Add the 'fs.protected_hardlinks' check
blob
|
commitdiff
|
raw
|
diff to current
2023-10-17
Alexander Popov
Add the 'fs.protected_symlinks' check
blob
|
commitdiff
|
raw
|
diff to current
2023-10-17
Alexander Popov
Add the 'vm.unprivileged_userfaultfd' check
blob
|
commitdiff
|
raw
|
diff to current
2023-10-17
Alexander Popov
Add the 'kernel.yama.ptrace_scope' check
blob
|
commitdiff
|
raw
|
diff to current
next