projects
/
kconfig-hardened-check.git
/ shortlog
commit
grep
author
committer
pickaxe
?
search:
re
summary
| shortlog |
log
|
commit
|
commitdiff
|
tree
first ⋅ prev ⋅
next
kconfig-hardened-check.git
2021-06-19
Alexander Popov
Reorder arch checks
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
SECURITY_DMESG_RESTRICT is recommended by KSPP now
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
Think about kptr_restrict later (KSPP recommends to...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
Mention that nosmt is slow
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
More info on init_on_free and init_on_alloc
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
SLUB_DEBUG_ON is very slow, leave it for the kernel...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
Update KSPP recommendations
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
Add defconfigs for v5.10
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
HARDEN_BRANCH_PREDICTOR for ARM64 is enabled by default...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-18
Alexander Popov
Add ARM64_MTE for userspace
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-18
Alexander Popov
Maybe SHADOW_CALL_STACK should be alternative to STACKP...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-18
Alexander Popov
Save 'debugfs=no-mount' for future
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-30
Alexander Popov
Update the README.
v0.5.9
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-30
Alexander Popov
Fix indentation (thanks to pylint)
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-29
Alexander Popov
Add a Q&A about spectre-meltdown-checker maintained...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-23
Alexander Popov
INIT_STACK_ALL -> INIT_STACK_ALL_ZERO (was renamed)
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-23
Alexander Popov
Add SHADOW_CALL_STACK for ARM64
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-22
Alexander Popov
Add the recommendation about TRIM_UNUSED_KSYMS
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-22
Alexander Popov
Add ARM64_BTI_KERNEL
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-22
Alexander Popov
Add the recommendation about UBSAN_BOUNDS
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-22
Alexander Popov
PAGE_POISONING -> PAGE_POISONING_ZERO
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-22
Alexander Popov
Improve AND check reports
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-22
Alexander Popov
Improve HARDEN_EL2_VECTORS check
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-22
Alexander Popov
Merge remote-tracking branch 'pgils/el2_vectors'
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-21
Alexander Popov
Add nested ComplexOptChecks support
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-19
Pelle van Gils
Do not check CONFIG_HARDEN_EL2_VECTORS for v5.9+
48/head
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-16
Alexander Popov
Add TODO about SLUB_DEBUG_ON
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-16
Alexander Popov
Add CLIP OS recommendation about EFI_CUSTOM_SSDT_OVERLAYS
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-16
Alexander Popov
Disabling ACPI_TABLE_UPGRADE is now recommended by...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-16
Alexander Popov
Withdraw my recommendation about BPF_JIT
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-14
Alexander Popov
Use cross compiler to build defconfigs
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-10-14
Alexander Popov
Add defconfigs for Linux kernel v5.9
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-15
Alexander Popov
Update the README
v0.5.7
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-15
Alexander Popov
Fix relevant pylint warnings
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-15
Alexander Popov
Fix 'decision' priority order ('lockdown' vs 'clipos...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-15
Alexander Popov
Add CLIP OS recommendations about CONFIG_IO_URING and...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-15
Alexander Popov
Add CONFIG_EFI_DISABLE_PCI_DMA recommended by CLIP OS
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-15
Alexander Popov
Fix 'decision' -- CONFIG_INTEGRITY is not enabled by...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-15
Alexander Popov
Add defconfigs for Linux kernel v5.7
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-15
Alexander Popov
Take new AND use case for X86_PTDUMP / PTDUMP_DEBUGFS
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-15
Alexander Popov
Improve ComplexOptCheck use cases
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-15
Alexander Popov
Add 'show_ok' and 'show_fail' print modes
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-13
Alexander Popov
Declare variables closer to their usage
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-13
Alexander Popov
Get rid of 'kernel_version' global variable
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-13
Alexander Popov
Big rework of the report modes
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-13
Alexander Popov
Add another link about user namespaces to Q&A
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-10
Alexander Popov
Add ARM64_PAN
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-09
Alexander Popov
Use += instead of append() for checklist
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-09
Alexander Popov
Reorder some checking rules for better looking code
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-09
Alexander Popov
Change the order of arguments in OptCheck constructor
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-09
Alexander Popov
Drop unused 'state' property from ComplexOptCheck
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-09
Alexander Popov
Don't return self.result in check() method -- it's...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-06
Alexander Popov
ARM64_PTR_AUTH is now supported for the kernel (from...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-07-03
Alexander Popov
Add the link to huldufolk project by @tych0
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-05-30
Alexander Popov
Add the link to @BlackIkeEagle article
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-05-06
Alexander Popov
Merge branch 'ubuntu20'
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-05-05
HacKurx
Upgrading to Ubuntu 20.04 kernel config
43/head
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-04-09
Alexander Popov
Merge branch 'evbug'
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-04-09
Alexander Popov
Merge branch 'pylint'
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-04-09
HacKurx
Updating the number of failures in the README
41/head
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-04-09
HacKurx
Add CONFIG_INPUT_EVBUG
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-04-08
shamilbi
pylint some code
40/head
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-04-06
Alexander Popov
Improve versioning
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-04-03
Alexander Popov
Add DRM_LEGACY, FB, and VT checks
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-31
Alexander Popov
Implement PresenceCheck and use it for LDISC_AUTOLOAD
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-31
Alexander Popov
Fix ComplexOptCheck result printing
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-31
Alexander Popov
Newline should be printed by print_checklist() that...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-31
Alexander Popov
Add more tests to increase coverage - IV
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-31
Alexander Popov
Create polymorphism for printing, add table_print(...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-31
Alexander Popov
Revisit special behavior in checking and printing that...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-31
Alexander Popov
Rename some workflow steps
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-30
Alexander Popov
Add more tests to increase coverage - III
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-30
Alexander Popov
Add more tests to increase coverage - II
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-30
Alexander Popov
Add more tests to increase coverage - I
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-30
Alexander Popov
Collect coverage
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-30
Alexander Popov
Count checked configs
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-30
Alexander Popov
Check all configs automatically
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-30
Alexander Popov
Revisit return values
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-30
Alexander Popov
Create the github workflow for functional tests
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-28
Alexander Popov
Fix the shebang to allow `./get-nix-kconfig.py`
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-27
Alexander Popov
Add NixOS hardened kernel config
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-26
Alexander Popov
Fix typo in README
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-26
Alexander Popov
Add vim swp files to gitignore
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-26
Alexander Popov
Merge branch 'nix'
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-26
Jörg Thalheim
add script to download linux kernel configs from nix
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-26
Jörg Thalheim
add gitignore
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-26
Jörg Thalheim
add default.nix for installation via nix
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-26
Alexander Popov
Update the README (describing installation)
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-26
Alexander Popov
Add a wrapper for using the tool without installation...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-26
Alexander Popov
Enable distribution via pip/setuptools
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-26
Alexander Popov
Call it a tool
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-26
Alexander Popov
Uh, setuptools doesn't like package names that contain...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-25
Alexander Popov
Add main() and clean up working with globals
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-25
Alexander Popov
Rename to kconfig-hardened-check/__init__.py
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-25
Alexander Popov
Move files to kconfig-hardened-check folder
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-25
Alexander Popov
Rename LICENSE file
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-24
Alexander Popov
Version 0.5.5 (supports Linux kernel v5.5)
v0.5.5
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-24
Alexander Popov
Update the README
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-24
Alexander Popov
CLIP OS recommends disabling Intel TSX
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2020-03-24
Alexander Popov
Small syctl cleanup
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
next