projects
/
kconfig-hardened-check.git
/ shortlog
commit
grep
author
committer
pickaxe
?
search:
re
summary
| shortlog |
log
|
commit
|
commitdiff
|
tree
first
⋅
prev
⋅
next
kconfig-hardened-check.git
2022-04-22
Alexander Popov
Add the STACKPROTECTOR check from KSPP
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-22
Alexander Popov
Drop the ARM64_MTE check for userspace hardening
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-22
Alexander Popov
Separate out checking SECURITY_WRITABLE_HOOKS and SECUR...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-22
Alexander Popov
Fix the arch condition for the SCHED_CORE check
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-22
Alexander Popov
Add the KSPP recommendation of ZERO_CALL_USED_REGS
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-22
Alexander Popov
Disabling X86_MSR is recommended by KSPP
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-20
Alexander Popov
Fix the bug in the verdict description for ComplexOptCheck
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-20
Alexander Popov
Additional check for TYPES_OF_CHECKS
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-20
Alexander Popov
Drop PresenceCheck; OptCheck without 'expected' paramet...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-20
Alexander Popov
Update the KSPP recommendations in the config_files
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-20
Alexander Popov
Add the KSPP recommendation of SCHED_CORE
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-20
Alexander Popov
Add the KSPP recommendation of IOMMU_DEFAULT_DMA_STRICT
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-20
Alexander Popov
Add the KSPP recommendation of WERROR
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-20
Alexander Popov
Add the KSPP recommendation of KFENCE
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-08
Alexander Popov
No need in BPF_UNPRIV_DEFAULT_OFF if BPF_SYSCALL is...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-08
Alexander Popov
Merge branch 'from-martin-rowe'
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-04-07
Alexander Popov
Add defconfigs for Linux v5.17
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-28
Alexander Popov
Drop unneeded return values (refactoring)
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-26
Martin Rowe
UBSAN_SANITIZE_ALL not available on ARM
60/head
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-20
Alexander Popov
Add HARDEN_BRANCH_HISTORY for arm
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-20
Alexander Popov
Add MITIGATE_SPECTRE_BRANCH_HISTORY for arm64
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-18
Alexander Popov
THREAD_INFO_IN_TASK is available for ARM since v5.16
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-18
Alexander Popov
Merge branch 'from-martin-rowe'
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-15
Martin Rowe
EFI mitigations can't be enabled if EFI is not set
59/head
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-13
Alexander Popov
Fix the BPF_UNPRIV_DEFAULT_OFF check (it is enabled...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-13
Alexander Popov
Add CONFIG_SLS vs CVE-2021-26341 in Straight-Line-Specu...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-13
Alexander Popov
Add the comment that l1d_flush is a part of the l1tf...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-13
Alexander Popov
Add BPF_UNPRIV_DEFAULT_OFF to cut_attack_surface
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-05
Alexander Popov
Use the option type instead of calling hasattr()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-03-05
Alexander Popov
Merge branch 'refactoring'
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-02-14
Alexander Popov
Introduce the json_dump() class method
refactoring
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-02-14
Alexander Popov
Improve 'type' for ComplexOptCheck and PresenceCheck...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-02-14
Alexander Popov
Make populate_with_data() aware of data type
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-02-14
Alexander Popov
Add 'type' for PresenceCheck and VersionCheck
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-02-14
Alexander Popov
Rename VerCheck to VersionCheck
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-02-14
Alexander Popov
Add more ComplexOptCheck validation
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-02-14
Alexander Popov
Improve print_unknown_options()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-02-14
Alexander Popov
Remove 'CONFIG_' hardcoding
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-02-11
Alexander Popov
Merge branch 'refactoring'
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-02-11
Alexander Popov
Refactor the OR logic code
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-02-11
Alexander Popov
Rename config to kconfig where needed (part II)
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-01-22
Alexander Popov
Extract populate_with_data() from perform_checks()
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-01-22
Alexander Popov
Rename config to kconfig where needed
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-01-22
Alexander Popov
Print the type of a check in the json mode
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-01-22
Alexander Popov
ComplexOptCheck type has the type of the first opt...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-01-21
Alexander Popov
Update the example output in the README (yes, now I...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-01-21
Alexander Popov
Do more output tuning
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-01-21
Alexander Popov
Update the example output in the README
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-01-21
Alexander Popov
Add check type
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-01-21
Alexander Popov
Update the example output in the README
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-01-21
Alexander Popov
Print compactly
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-01-21
Alexander Popov
Introduce KconfigCheck class
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2022-01-21
Alexander Popov
Fix TRIM_UNUSED_KSYMS check
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-12-24
Alexander Popov
Add l1d_flush (for future reference)
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-12-05
Alexander Popov
Add ARM64_PTR_AUTH_KERNEL extracted from ARM64_PTR_AUTH
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-11-21
Alexander Popov
Document the output modes specified by the `-m` parameter
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-11-21
Alexander Popov
TODO: RISC-V
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-11-09
Alexander Popov
Update the README (a lot of new checks appeared)
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-11-09
Alexander Popov
Keep the old X86_PTDUMP check as a backup
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-11-09
Alexander Popov
Simplify the check about PTDUMP_DEBUGFS (I was correct)
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-11-09
Alexander Popov
Add more checks from grsecurity for cutting attack...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-11-09
Alexander Popov
Fix the 'decision' field of the IO_URING check
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-11-09
Alexander Popov
Add more checks from grsecurity for cutting attack...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-11-09
Alexander Popov
Fix the 'decision' field of the KPROBES check
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-11-09
Alexander Popov
Add the comment
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-23
Alexander Popov
Improve the README
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-23
Alexander Popov
Get a bit more coverage
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-23
Alexander Popov
Update the README
v0.5.14
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-22
Alexander Popov
Move 'self_protection' & 'maintainer' higher
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-21
Alexander Popov
Add HARDENED_USERCOPY_PAGESPAN check from KSPP
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-21
Alexander Popov
Add comments about the maintainer recommendations
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-21
Alexander Popov
Fix UBSAN_BOUNDS recommendations
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-21
Alexander Popov
RANDOMIZE_KSTACK_OFFSET_DEFAULT is recommended by KSPP
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-16
Alexander Popov
Update the KSPP recommendations
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-16
Alexander Popov
Add defconfigs for Linux v5.14
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-10
Alexander Popov
Merge pull request #54 from evdenis/master
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-10
Denis Efremov
Add BLK_DEV_FD
54/head
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-09-10
Alexander Popov
Add RANDOMIZE_KSTACK_OFFSET_DEFAULT
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-08-29
Alexander Popov
Add CFI_CLANG
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-08-29
Alexander Popov
Add ARM64_EPAN
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-08-20
Alexander Popov
Merge pull request #51 from Hacks4Snacks/master
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-08-20
Mark D. Gray
Added Linux/x86_64 kernel config link for CBL-Mariner
51/head
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-08-19
Mark D. Gray
Added cbl-mariner kernel configuration file.
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-08-14
Alexander Popov
Add hardware tag-based KASAN with arm64 Memory Tagging...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-08-14
Alexander Popov
Add the command line parameters that should NOT be set
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-08-08
Alexander Popov
Document the changes of vm.unprivileged_userfaultfd...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-08-08
Alexander Popov
Add the news about PAGE_POISONING
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-07-02
Alexander Popov
Improve wording
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
Update the README.
v0.5.10
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
Fix pylint warning
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
Remember that SHADOW_CALL_STACK depends on clang
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
STACKPROTECTOR_PER_TASK is also available for ARM64
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
INTEL_IOMMU_SVM is available only for X86_64
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
Reorder arch checks
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
SECURITY_DMESG_RESTRICT is recommended by KSPP now
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
Think about kptr_restrict later (KSPP recommends to...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
Mention that nosmt is slow
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
More info on init_on_free and init_on_alloc
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
SLUB_DEBUG_ON is very slow, leave it for the kernel...
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
2021-06-19
Alexander Popov
Update KSPP recommendations
commit
|
commitdiff
|
tree
| snapshot (
zip
tar.gz
)
next