projects
/
kconfig-hardened-check.git
/ shortlog
commit
grep
author
committer
pickaxe
?
search:
re
summary
| shortlog |
log
|
commit
|
commitdiff
|
tree
first ⋅ prev ⋅
next
kconfig-hardened-check.git
2023-08-27
Alexander Popov
Support separate sysctl checking (without kconfig)
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-14
Alexander Popov
Improve coverage of the functional test a bit
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-14
Alexander Popov
Clean .gitignore
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-14
Alexander Popov
Show git information in the functional test
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-14
Alexander Popov
Test an invalid sysctl file
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-14
Alexander Popov
Test an unexpected line in the sysctl file
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-14
Alexander Popov
Test an unexpected line in the Kconfig file
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-14
Alexander Popov
Drop `if __name__ == "__main__"` from ./bin/kconfig...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-14
Alexander Popov
Turn the warning about unexpected line in Kconfig file...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-14
Alexander Popov
Update the README (add the --sysctl mode)
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-13
Alexander Popov
Add the Kconfig file of Fedora 38
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-13
Alexander Popov
Use example_sysctls.txt in the functional test
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-13
Alexander Popov
Add an example sysctl output file
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-13
Alexander Popov
Add the / symbol to the sysctl parsing pattern
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-13
Alexander Popov
Add --sysctl to functional testing
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-13
Alexander Popov
Improve checking the combinations of flags in the funct...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-13
Alexander Popov
Fix syntax to run on the Woodpecker 1.0.0 CI (part II)
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-13
Alexander Popov
Fix syntax to run on the Woodpecker 1.0.0 CI
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-13
Alexander Popov
Report that --print and --generate can't be used together
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-08-13
Alexander Popov
Enable sysctl checking
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-23
Alexander Popov
Check the kernel.unprivileged_bpf_disabled sysctl
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-23
Alexander Popov
Check the dev.tty.ldisc_autoload sysctl
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-23
Alexander Popov
Check the user.max_user_namespaces sysctl
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-23
Alexander Popov
Check the kernel.kexec_load_disabled sysctl
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-23
Alexander Popov
Check the kernel.perf_event_paranoid sysctl
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-23
Alexander Popov
Check the kernel.dmesg_restrict sysctl
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-23
Alexander Popov
Check the net.core.bpf_jit_harden sysctl
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-23
Alexander Popov
test_engine: use SysctlCheck in test_value_overriding()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-23
Alexander Popov
test_engine: use SysctlCheck in test_stdout()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-23
Alexander Popov
test_engine: implement test_simple_sysctl()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-23
Alexander Popov
test_engine: support SysctlCheck
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-22
Alexander Popov
Refactor populate_opt_with_data()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-16
Alexander Popov
Mute warnings in the JSON mode and improve wording
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-16
Alexander Popov
Implement parse_sysctl_file()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-15
Alexander Popov
Drop an obsolete error handling test
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-15
Alexander Popov
Fix the bug in the functional tests
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-15
Alexander Popov
Emit WARNING for the cmdline options that exist multipl...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-15
Alexander Popov
Precise the Kconfig parsing
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-12
Alexander Popov
Get rid of useless regular expressions in detect_compiler()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-12
Alexander Popov
Precise the regular expressions in detect_arch() and...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-12
Alexander Popov
Show error if some cmdline option exists multiple times
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-08
Alexander Popov
Add the basic infrastructure for checking sysctl
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-08
Alexander Popov
Introduce the SysctlCheck class
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-04
Alexander Popov
Check disabling XFS_SUPPORT_V4 for cutting attack surface
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-07-02
Alexander Popov
Print the microarchitecture in --generate mode
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-25
Alexander Popov
Update the README
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-25
Alexander Popov
Add the info about /proc/cmdline to the usage help
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-18
Alexander Popov
setup: fix "The license_file parameter is deprecated"
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-18
Alexander Popov
setup: Don't use the automatic "find_namespace:" discovery
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-18
Alexander Popov
setup: Fix the warning "Package would be ignored"
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-18
Alexander Popov
setup: Drop obsolete zip_safe flag
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-17
Alexander Popov
Move the draft of the security hardening sysctls to...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-17
Alexander Popov
Improve normalize_cmdline_options()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-12
Alexander Popov
GitHub Actions: decrease the max-parallel to 1 to avoid...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-12
Alexander Popov
Add functional tests for --generate
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-12
Alexander Popov
Update the README
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-12
Alexander Popov
Add a new feature --generate
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-12
Alexander Popov
Refactoring of the argument parsing
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-12
Alexander Popov
Improve the comments and README (part II)
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-12
Alexander Popov
Skip normalize_cmdline_options() for the vdso32 and...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-12
Alexander Popov
Skip normalize_cmdline_options() for the vsyscall cmdli...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-12
Alexander Popov
Skip normalize_cmdline_options() for the iommu cmdline...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-12
Alexander Popov
Skip normalize_cmdline_options() for the slub_debug...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-12
Alexander Popov
Improve the comments and README
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-05
Alexander Popov
Skip normalize_cmdline_options() for the rodata cmdline...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-06-05
Alexander Popov
Skip normalize_cmdline_options() for the ssbd cmdline...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-28
Alexander Popov
Add a comment about cfi boot parameter
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-28
Alexander Popov
Add the X86_KERNEL_IBT check
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-28
Alexander Popov
Add a comment about `kernel.oops_limit` and `kernel...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-27
Alexander Popov
Add a comment about `kernel.unprivileged_userns_clone...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-27
Alexander Popov
Add the comments about HARDENED_USERCOPY features
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-09
Alexander Popov
Fix CI output style and move `pip install coverage...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-08
Alexander Popov
Use .github/workflows/functional_test.sh in GitHub...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-08
Alexander Popov
Run the functional tests and collect the coverage in...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-08
Alexander Popov
Check all configs with the installed tool the functiona...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-08
Alexander Popov
Test the package installation in the functional test...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-07
Alexander Popov
Run the engine unit-test in Woodpecker-CI
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-07
Alexander Popov
Create multiple pipelines for Woodpecker-CI at Codeberg
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-07
Alexander Popov
Create a configuration template for Codeberg CI (.woodp...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-05-01
Alexander Popov
Add the checks for vdso32 and vdso on X86_64 and X86_32
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-30
Alexander Popov
Improve the COMPAT_VDSO check
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-30
Alexander Popov
Improve the vsyscall checks
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-30
Alexander Popov
Add the comment about kernel.sysrq=0
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-22
Alexander Popov
Make hackish refinement of the CONFIG_ARCH_MMAP_RND_BIT...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-22
Alexander Popov
test_engine: add test_value_overriding()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-22
Alexander Popov
engine: implement override_expected_value()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-22
Alexander Popov
Require one of major LSMs implementing MAC
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-22
Alexander Popov
Add the norandmaps check
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-22
Alexander Popov
Check that CoreSight Tracing Support is disabled (to...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-09
Alexander Popov
Drop the INTEGRITY check
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-09
Alexander Popov
Add the DEBUG_ALIGN_RODATA check for ARM
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-09
Alexander Popov
Add new Android kernel configs from my friends
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-09
Alexander Popov
Add the LEGACY_TIOCSTI check
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-02
Alexander Popov
engine: remove the unused 'type' property from the...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-02
Alexander Popov
test_engine: rename unit-tests
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-02
Alexander Popov
test_engine: increase the unit-test coverage
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-02
Alexander Popov
test_engine: test the non-verbose output mode
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-02
Alexander Popov
test_engine: support the non-verbose output mode in...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-02
Alexander Popov
Fix a pylint warning about f-string
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2023-04-02
Alexander Popov
test_engine: add test_verbose()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
next