-
Notifications
You must be signed in to change notification settings - Fork 51
/
changelog.upstream
16318 lines (10822 loc) · 462 KB
/
changelog.upstream
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
commit c7e9460b2ae8dcb96196fef69a7e0ed992c1b43b
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Nov 14 16:31:12 2024 -0500
output
commit 31804e30ecc9c5a1c5a8e1e014d3dcb85cee4f36
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Nov 14 20:46:26 2024 +0000
bumped changelog version
commit ef95b3f9a5aed9652c541cf4bf05b20011718466
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Nov 14 14:41:14 2024 -0500
Revert "fix `panic-on-oops.service`"
This reverts commit 862d23cb10b7687084f8e7e207d1e2c9c1ef6751.
commit 57e1edde23aa3f313ce087e00ebc14d158356d6c
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Nov 12 09:11:57 2024 +0000
bumped changelog version
commit 7987a3914d364e674eb7479b15708c450041af02
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Nov 12 02:29:42 2024 -0500
deleted no longer used and out-commented `/etc/sudoers.d/xfce-security-misc` leftover
commit 8c2e8e69798e5255529ab3dbee6ca07b8b293100
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Nov 12 01:41:12 2024 -0500
deleted no longer used and out-commented `etc/sudoers.d/pkexec-security-misc` leftover
commit 65fc0419a84d62e07c61d7e37ef27d144b6b6794
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Nov 11 11:07:57 2024 +0000
bumped changelog version
commit 50161f5d79eea2ab796863e4eb30eccc17e0b41d
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Nov 11 05:48:11 2024 -0500
moved /etc/dkms/framework.conf.d/30_security-misc.conf (renamed) to usability-misc
commit 7c06e22c7d11c345428f3ad42ba43805ebc8d810
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Nov 11 05:43:25 2024 -0500
deleted `/usr/bin/pkexec.security-misc`
This was not used anymore for anything. In the past, we used to `config-package-dev` `replace` `/usr/bin/pkexec` with `/usr/bin/pkexec.security-misc` for the purpose of:
> Redirect calls for pkexec to lxqt-sudo because pkexec is incompatible with hidepid.
* https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860040
* https://forums.whonix.org/t/cannot-use-pkexec/8129
This was a worthwhile effort, interesting approach but ultimately a dead-end.
commit ef05b1a160b24d5aa42da9cc15009d94a37cf120
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Nov 11 05:40:41 2024 -0500
disable legacy matroxfb_base framebuffer driver
fix typo matroxfb_bases -> matroxfb_base
Thanks to @ArrayBolt3 for the bug report!
commit 862d23cb10b7687084f8e7e207d1e2c9c1ef6751
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Nov 11 05:36:41 2024 -0500
fix `panic-on-oops.service`
remove `After=multi-user.target` because already using `WantedBy=multi-user.target`
Thanks to @ArrayBolt3 for the bug report!
commit 29ae5f5980d521f6a4b468f5bf41210f78fdf10a
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Nov 11 05:28:31 2024 -0500
fix optional opt-in `harden-module-loading.service`
by making `/usr/libexec/security-misc/disable-kernel-module-loading` executable
Thanks to @ArrayBolt3 for the bug report!
commit 4c649577f053af12bcd02c20576bf2d8aec1476d
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Sun Nov 10 11:52:42 2024 +0000
bumped changelog version
commit 29b1f1ec5f3a4bf3991fc1b862751c8eb9769ecd
Merge: 5bd0a27 238f32e
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Sun Nov 10 06:32:30 2024 -0500
Merge remote-tracking branch 'github-kicksecure/master'
commit 5bd0a277bf39812c6adf40a7a3ef6390935fa08e
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Sun Nov 10 06:29:17 2024 -0500
fix permission-hardener issue "Removing capabilities failed. File: '/bin/ping'"
no longer user end-of-options marker (`--`) for `setcap`
since setcap does not support it
Fixes https://github.com/QubesOS/qubes-issues/issues/9569
https://forums.whonix.org/t/permission-hardener-error/20719
commit 238f32e81d835e5b9d3bc43a0654d05efa4c4313
Merge: 3af2684 8107782
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Fri Nov 8 07:39:40 2024 -0500
Merge pull request #280 from raja-grewal/ssbd
Enable `ssbd=force-on`
commit 8107782fa54ec0e21893e6bd4a6baabb71eb864b
Author: raja-grewal <rg_public@proton.me>
Date: Fri Nov 8 15:36:04 2024 +1100
Enable `ssbd=force-on`
commit 3af2684134279ba6f5b18b40986f02a50baa5604
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Oct 30 09:43:05 2024 +0000
bumped changelog version
commit 71c58442ca6d57cd95b72a76ed87f8c248cdbd98
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Oct 28 05:10:19 2024 -0400
minor
commit cfe19e31d858d7899f4d95e21117c992d236d328
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Oct 28 05:09:53 2024 -0400
shell options
commit 0d506156587f87a303184f22259ffb57dd92cbc8
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Oct 28 05:07:00 2024 -0400
local
commit ef0eb5f7a0c5a62c5d26bf6dc534f6aa3decc4b0
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Oct 28 05:06:26 2024 -0400
refactoring
commit fdd1f4b7f88efc22bb57c2ad3e83c0c2e8cbb064
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Oct 28 05:06:05 2024 -0400
refactoring
commit d00235897d686895a7e2e7da7435832fee008164
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Oct 28 05:03:59 2024 -0400
hide-hardware-info: also parse `/usr/local/etc/hide-hardware-info.d/*.conf`
commit 6c2e808b9f34900840bd2857fed10d1ffd4cc4c2
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Oct 28 05:03:20 2024 -0400
refactoring
commit b44e507900defe3db68f31f3e110b1c3e5aa684c
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Oct 23 09:56:05 2024 +0000
bumped changelog version
commit 566cda5e4bc69f54d63d72f1e30703074fdf0ce8
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Oct 21 05:47:38 2024 -0400
output
commit 5991a23049491dd04c19d9ea80f7d7381dd494a0
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Oct 21 05:47:25 2024 -0400
comment
commit fd34baff8ff17ed572469d9d6d884e6c0d881d20
Merge: b643330 690e8dd
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Mon Oct 21 05:43:53 2024 -0400
Merge remote-tracking branch 'ArrayBolt3/master'
commit 690e8dd826d1cb39c0c12c03792781862cc2dd23
Author: Aaron Rainbolt <arraybolt3@ubuntu.com>
Date: Sat Oct 19 23:49:07 2024 -0500
Avoid faillock lock/tally reset on reboot or timeout
commit b6433309fd7d6839cfba89e1197590e1ff62ef58
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Fri Oct 18 12:45:02 2024 -0400
use end-of-options
commit 0cfcdf4f89dc75f2a8e3f8a9e8c69dc3ba3da78a
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Oct 16 10:57:20 2024 +0000
bumped changelog version
commit 0adb9b7c0609a51d503b61ab40ae7d8e55635043
Merge: 263335f e50ad80
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Oct 16 06:31:09 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit e50ad807c01b5753c67d579126d7b79d38070c0a
Merge: 263335f eb72163
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Oct 16 06:29:25 2024 -0400
Merge pull request #276 from raja-grewal/KSPP_header
Clarify KSPP compliance header
commit eb72163d5707c7673db1f12405d2e04261bd43c8
Author: raja-grewal <rg_public@proton.me>
Date: Mon Oct 14 03:01:15 2024 +0000
README.md: Make line lengths consistent
commit a9f238fe048acfeff49f96c00570acc6ca4c37e8
Author: raja-grewal <rg_public@proton.me>
Date: Mon Oct 14 02:57:31 2024 +0000
README.md: Split optional setting to new line
commit 09fe46adc956e8c6de232f1093c37cdd30933acd
Author: raja-grewal <rg_public@proton.me>
Date: Mon Oct 14 02:54:30 2024 +0000
Clarify KSPP compliance header for the undocumented case
commit 263335f74ea0f050f9c259e20141c3345e7fa789
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Oct 8 11:24:56 2024 +0000
bumped changelog version
commit 9169611645d0cd5a308ff48862f351ef5ea5f7e8
Merge: 8a2d432 8227a3d
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Oct 8 05:54:50 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit 8227a3dde2995ceb113164baf49591d52c2b53e1
Merge: 8a2d432 0c0774f
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Oct 8 05:53:48 2024 -0400
Merge pull request #273 from raja-grewal/text_2
Documentation update 2
commit 0c0774f6c0927ed1cc599f931175985b8f01ec30
Merge: dc470ca 8a2d432
Author: raja-grewal <rg_public@proton.me>
Date: Sun Oct 6 10:48:52 2024 +0000
Merge branch 'master' into text_2
commit dc470cac1d93656354aeaaac0a6f8cbbd39f9f0f
Author: raja-grewal <rg_public@proton.me>
Date: Sun Oct 6 10:46:05 2024 +0000
Remmove deprecated link
commit 8a2d432ffe6d4eb661026b6e7dbf534bb1db971b
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Oct 3 07:22:23 2024 +0000
bumped changelog version
commit 0e3ffa3f11a0049e57803c8f2e75dbb7d8ceb22c
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Oct 3 02:58:58 2024 -0400
no longer set `kernel.unprivileged_userns_clone=0`
because it breaks too much
fixes https://github.com/Kicksecure/security-misc/issues/274
commit f401d94d5e0d0f26e93be55deda440fe565a6b22
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Oct 3 02:44:06 2024 -0400
expand documentation on `kernel.unprivileged_userns_clone=0` sysctl
https://github.com/Kicksecure/security-misc/issues/274
commit ac1378743c7448c9a7e7e02bebcf3270592d42a5
Author: raja-grewal <rg_public@proton.me>
Date: Mon Sep 30 16:56:18 2024 +1000
Consistent formatting
commit eae38e72f30ff9b9f8d0b8b0b33182a918333e48
Author: raja-grewal <rg_public@proton.me>
Date: Thu Sep 26 13:10:36 2024 +0000
README.md: Show the current max_map_count
commit f3b50a23c976ba4feff34eee721c50f698ecc5bf
Author: raja-grewal <rg_public@proton.me>
Date: Thu Sep 26 13:10:01 2024 +0000
Add reference on unprivileged_userns_restriction
commit 39d063d494cb540f45747f6253ab896200ba03c3
Author: raja-grewal <rg_public@proton.me>
Date: Thu Sep 26 13:09:21 2024 +0000
Add KSPP=no definition
commit 5572eb897a10455041df8abec6b6be6de29431a0
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Sep 25 01:03:42 2024 +0000
bumped changelog version
commit e04f9cd4c17305d5201aa973c34778e81508734b
Merge: 18d426f 65aa910
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Sep 24 20:16:06 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit 65aa910503c07f708abf20f78be2f519ef58764a
Merge: 18d426f 870ff88
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Sep 24 20:15:03 2024 -0400
Merge pull request #272 from raja-grewal/text
Documentation update
commit 870ff88605b8167c8882162cc3da005d71ca0cd3
Author: raja-grewal <rg_public@proton.me>
Date: Wed Sep 25 10:01:45 2024 +1000
Comment on Flatpak requiring unprivileged user namespaces
commit 769767a96a5de2a8bc05e70ca490d8340b553061
Author: raja-grewal <rg_public@proton.me>
Date: Wed Sep 25 09:54:49 2024 +1000
Update mmap ASLR docs
commit 18d426f521b2b1369fe68e143dc8a0be064d0dcc
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Sat Sep 14 02:56:09 2024 +0000
bumped changelog version
commit 3280dbd5d562d7f6b50118ac0da36c3285493be6
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Fri Sep 13 22:52:47 2024 -0400
Fix VirtualBox audio device ICH AC97.
no longer `blacklist snd_intel8x0`
Breaks VirtualBox audio device ICH AC97, which is unfortunately still required by some users.
https://www.kicksecure.com/wiki/Dev/audio
Fixes https://github.com/Kicksecure/security-misc/issues/271
commit 1bc694fa124eaeb6e1517d2191a8fd97446872c4
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Sun Sep 8 17:41:30 2024 +0000
bumped changelog version
commit 01908d505a59e7ec37cc3de3e1d49ff35ba127aa
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Sep 5 07:00:11 2024 -0400
readme
commit e914028be7a48a3bfdf86e09c029011807f080d7
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Sep 5 06:03:05 2024 -0400
add KSPP compliance status to readme based on comment by @raja-grewal
https://github.com/Kicksecure/security-misc/issues/256#issuecomment-2330376651
commit 40fb14c654df94e9bdfb30ae55fc3bc4f0a0aef4
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Sep 4 14:13:15 2024 +0000
bumped changelog version
commit 5a255d4831470449a26b324a8f16594432bf834b
Merge: d618f9f 563a898
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Sep 4 10:12:34 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit 563a8980133e15e33ac95a631e37ecfff88f6f8f
Merge: 175945e e61027a
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Sep 4 10:11:48 2024 -0400
Merge pull request #265 from raja-grewal/mmap_min_addr
Set `sysctl vm.mmap_min_addr=65536`
commit d618f9f35b8e8c6eee1e164a6ec300d63b1ee797
Merge: 59374ce 175945e
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Sep 4 10:07:50 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit 175945ec9a28bf1e5b0fa0d2ae2bd6546d6c6172
Merge: b0a8544 3101035
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Sep 4 10:05:47 2024 -0400
Merge pull request #268 from raja-grewal/panic_on_warn
Enable `panic_on_warn=1`
commit b0a8544182f6ff3c8c3f1068176ff5e9e4f557ef
Merge: 59374ce 7393ba1
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Sep 4 10:04:45 2024 -0400
Merge pull request #270 from raja-grewal/typo
Small typo
commit 7393ba159192fdfc45ef31a3fa60786f899dbf25
Author: raja-grewal <rg_public@proton.me>
Date: Wed Sep 4 23:23:24 2024 +1000
Typo
commit 59374ce902127e2125addc2ebb57d0d856a63671
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Aug 29 09:49:51 2024 +0000
bumped changelog version
commit 7e2838ec077b53e41d468d5655290152761c8745
Merge: 9c918eb 0762794
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Aug 29 05:06:07 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit 0762794ff684049a62b5b92b61177615a5376ad7
Merge: 9c918eb 6294729
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Aug 29 04:46:26 2024 -0400
Merge pull request #269 from raja-grewal/tidy
Minor correction
commit 6294729c8ef24077cd342b4557653806c3aacd34
Author: Raja Grewal <rg_public@proton.me>
Date: Thu Aug 29 15:34:24 2024 +1000
Follow-up on https://github.com/Kicksecure/security-misc/commit/f70fe308a9f65873d34de2d1906d825f3a56e272
commit 3101035a3fd5fbe87c79e95e51dc2da39fee93d5
Author: Raja Grewal <rg_public@proton.me>
Date: Thu Aug 29 01:57:32 2024 +1000
Enable `panic_on_warn=1`
commit 9c918eb4313b60dc15aa9fa4474a7977602030c1
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Aug 28 11:01:37 2024 +0000
bumped changelog version
commit f70fe308a9f65873d34de2d1906d825f3a56e272
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Aug 28 06:49:50 2024 -0400
no longer set sysctl `fs.binfmt_misc.status=0` /
no longer disallow registering interpreters for miscellaneous binary formats
causing file/folder permissions issue `d????????? ? ? ? ? ? .`
Firefox no longer starting (probably not not a Firefox issue)
https://github.com/Kicksecure/security-misc/issues/267
commit 463aa58f28b6389d0925fed87096b348b652cc16
Merge: cf824dd 328840c
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Aug 28 06:42:49 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit 328840c933a583adc5458aa08c63fb627b31b298
Merge: cf824dd 9e91c98
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Wed Aug 28 06:38:57 2024 -0400
Merge pull request #264 from raja-grewal/kspp_compliance
Add KSPP compliance notices to corresponding parameters and `sysctls`
commit 9e91c98cc926e7a166458cd78e3c1d1ced23c753
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 26 12:40:04 2024 +1000
Add details on BPF hardening and split the `sysctl`s
commit 2c356e8b0ef7db56e7b453535c8cb6c83fc2e3c6
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 26 11:34:12 2024 +1000
Add KSPP notice definitions
commit 2841d789bebbd43f855b6ffb92a3a6f017007a72
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 26 11:21:26 2024 +1000
README: Update
commit ac6602ac3531ae57603e8a9e5ac2ee1652164b23
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 26 11:19:20 2024 +1000
Add detail on disabling user namespaces breaking UPower
commit 9dbd200be415c86e7039463c6269fad8395a4373
Merge: 32de5e7 cf824dd
Author: raja-grewal <rg_public@proton.me>
Date: Mon Aug 26 11:08:21 2024 +1000
Merge branch 'Kicksecure:master' into kspp_compliance
commit cf824ddb248957fd9e542c1a5adc5e90381f684c
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Sun Aug 25 15:34:55 2024 +0000
bumped changelog version
commit 500568e322b2e3623fc649209d671c7b9d9fa097
Merge: 43d13b7 73900b5
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Sun Aug 25 11:01:58 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit 73900b59db37d77bc24bd5088aae3cc760aacc69
Merge: 43d13b7 1f51d4e
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Sun Aug 25 11:00:51 2024 -0400
Merge pull request #263 from raja-grewal/max_user_namespaces
Provide option to disable user namespaces
commit 43d13b70f12d2198a800054ce4d1ff901cc474f9
Merge: 8353764 fae586c
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Sun Aug 25 10:55:52 2024 -0400
Merge remote-tracking branch 'raja/syntax'
commit 835376418d616699023f8e638666f43d34241863
Merge: ae85fd5 342caf8
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Sun Aug 25 10:48:25 2024 -0400
Merge remote-tracking branch 'raja/mod'
commit ae85fd5b4ce6f4716f95332c19b79d3daa8f7220
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Sun Aug 25 14:33:40 2024 +0000
bumped changelog version
commit 433b15f985545f531b87d09659bbbb89993b5a67
Author: Raja Grewal <rg_public@proton.me>
Date: Wed Aug 21 12:51:51 2024 +1000
README.md: Organise `sysctl`s
commit af87a84b4f40b2ad9ac05dd9bce837665f239454
Author: Raja Grewal <rg_public@proton.me>
Date: Wed Aug 21 12:52:48 2024 +1000
README.md: Organise kernel boot parameters
commit 32de5e7c49d301b62b838ba88550f58b02b6562b
Author: Raja Grewal <rg_public@proton.me>
Date: Sun Aug 25 12:57:22 2024 +1000
Add details on oopses and warnings
commit e4909b5e28e16f09de0e548c9221578ebe1190a3
Author: Raja Grewal <rg_public@proton.me>
Date: Sun Aug 25 12:47:04 2024 +1000
Add details on kernel panics
commit 342caf82b20acc2931563449fafe9a98cbedaba2
Author: Raja Grewal <rg_public@proton.me>
Date: Wed Aug 21 12:52:48 2024 +1000
README.md: Organise kernel boot parameters
commit b87a18d4050bbf2add5cc4920684876a440e65bb
Author: Raja Grewal <rg_public@proton.me>
Date: Wed Aug 21 12:51:51 2024 +1000
README.md: Organise `sysctl`s
commit 18ed77ecc93e9ee759a4990a32edb3dd671b8c26
Author: Raja Grewal <rg_public@proton.me>
Date: Wed Aug 21 12:50:14 2024 +1000
Refactor modprobe.d to minimise potential future merge conflicts
commit 56b28e38264fe742b8d694176f1057c15574fc08
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 19 11:50:08 2024 +1000
Typo
commit e61027a40e2ab82fac3ae4cfd5f91fd0a47f31e5
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 19 11:32:20 2024 +1000
Set `sysctl vm.mmap_min_addr=65536`
commit 94dab1b7c503429e2fa91019a0183b2f36c6693f
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 19 10:53:05 2024 +1000
Partial compliance with the KSPP on kernel panics
commit 683110e7f02fa5fc6415354386552640cdb8758b
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 19 01:34:14 2024 +1000
Correction
commit 1f51d4eeb2b0c6e23ce64fb272eecb97e089324d
Author: Raja Grewal <rg_public@proton.me>
Date: Sun Aug 18 13:53:11 2024 +1000
Add details on user namespaces
commit 248e094b8e0bbf7892f79ad1c3ec77c7ed00d008
Author: Raja Grewal <rg_public@proton.me>
Date: Sat Aug 17 01:06:21 2024 +1000
Include KSPP compliance notices
commit 759aee8150a2d1258d73217c071b25432d47496f
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 16 22:54:57 2024 +1000
Provide option to disable user namespaces
commit fae586c3c5e8382ca01c60f810b26d88189a5514
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 16 19:23:48 2024 +1000
Patch bug in existing `rp_filter` `sysctl`
commit e962153f84c4cb8e13fb0cc25d611ae481c7a0c7
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Fri Aug 16 08:38:12 2024 +0000
bumped changelog version
commit 40b12f5a2a4a40d7033569b11ad4e1c228e7389b
Merge: 12296c6 305467c
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Fri Aug 16 04:30:29 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit 305467c652af933bb5aa5a677b10a992a5f19cab
Merge: 12296c6 a5373af
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Fri Aug 16 04:25:43 2024 -0400
Merge pull request #245 from raja-grewal/blacklist_to_disable
Update `/etc/modprobe.d/*`
commit 12296c68dc0aaa3703e1c36f854a02de8db412fe
Merge: 4bc12b0 036bcea
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Fri Aug 16 04:22:43 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit 036bcea4e6757de094fcafdadcf56aaa90729d79
Merge: ef60c5b 81bf7a8
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Fri Aug 16 04:20:32 2024 -0400
Merge pull request #262 from raja-grewal/docs
Miscellaneous updates to presentation
commit 81bf7a8f90098a7107dcb3c783b87a168f5c090f
Merge: cea8e75 ef60c5b
Author: raja-grewal <rg_public@proton.me>
Date: Fri Aug 16 16:57:01 2024 +1000
Merge branch 'Kicksecure:master' into docs
commit ef60c5b153a521e1cfd522ac471a8ca6dc076d90
Merge: 4bc12b0 b552b92
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Fri Aug 16 02:43:57 2024 -0400
Merge pull request #249 from raja-grewal/binfmt_misc
Disallow registering interpreters for miscellaneous binary formats
commit cea8e753786d100ebe961ad74a99925e54d47771
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 16 14:55:22 2024 +1000
Consistent formating
commit 84376d23fc17d2ced890ffca0b05d15907d42a6f
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 16 13:39:11 2024 +1000
Add details on ASLR and move to user space section
commit a13298002350a39491a509d15633edb95a2e3edd
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 16 13:24:25 2024 +1000
Update README.md
commit 9212a4e93754a4505be3fcf0ff4b029c073d2f07
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 16 13:12:07 2024 +1000
Typos
commit 23a77d4973ec20b2aaab6a9c3a9fd8a98034923e
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 16 12:46:51 2024 +1000
Simplify syntax of some network-related `sysctl`'s
commit e3a3207a4447568a17129afe9dde34debc465e21
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 16 12:41:36 2024 +1000
Clarify DMA hardening
commit be9308e490f79a7b7788a744524d1d91cc870726
Merge: 73db68d 4bc12b0
Author: raja-grewal <rg_public@proton.me>
Date: Fri Aug 16 11:45:43 2024 +1000
Merge branch 'Kicksecure:master' into docs
commit 4bc12b07b42def786862b938e3f63c18cf874158
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Aug 15 17:51:18 2024 +0000
bumped changelog version
commit 9e61e37c17524b57f185b796f2ac19ba193205a8
Merge: 89e816d dfd1c97
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Aug 15 13:47:33 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit dfd1c97168249b229495cbd873d4d8493e244663
Merge: 89e816d ec3038c
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Thu Aug 15 13:46:30 2024 -0400
Merge pull request #248 from raja-grewal/secure_redirects
Re-enable (default) `secure_redirects` for ICMP redirect messages
commit b552b92401f67d59e12ac6fda2f7fe1c54b0c8a7
Author: Raja Grewal <rg_public@proton.me>
Date: Thu Aug 15 11:54:21 2024 +1000
Add references on `fs.binfmt_misc.status`
commit 326d82a9beee130956dd817812016a6ee16fccbc
Author: Raja Grewal <rg_public@proton.me>
Date: Thu Aug 15 11:46:56 2024 +1000
Revert "Provide optional `sysctl fs.binfmt_misc.status=0`"
This reverts commit debd7a7b7ae8b03e04d2c8597bcccf2c79000570.
commit 73db68dbf9a1f9ded95a593db36a4960ce06a173
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 9 14:27:30 2024 +1000
Add details on KFENCE
commit f8fa89b245d929aee9884937fdcf44a6551df4cf
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 9 14:21:59 2024 +1000
Add details on `tcp_timestamps`
commit 3456f1c1d7725846ec201c28dd693bf9b07bab89
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 9 13:39:25 2024 +1000
Minor consistency update in README.md
commit 15c638acad64cc3dcc7b5c43d9a6be2fa2350654
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 9 13:36:47 2024 +1000
Add reference on RDRAND
commit 077bc48a26d1d3f5d1f758d7e251edccba64742b
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 9 13:35:33 2024 +1000
Add reference on `rp_filter`
commit d8bcec881f66604e29d6e0c1426635e2ad4979f1
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 9 13:33:32 2024 +1000
Add some notices for future Debian 13 rebase
commit 0b0683499a6a21e3995a115c377eb19008bc4cd1
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 9 13:30:39 2024 +1000
Consistent line length formatting
commit e5a38fc856c66d2bd6abc35fc08d4f2083ea8e54
Author: Raja Grewal <rg_public@proton.me>
Date: Fri Aug 9 13:30:15 2024 +1000
Typo
commit a5373afc55e789f4657f3d843243e878e4afffa2
Author: Raja Grewal <rg_public@proton.me>
Date: Wed Aug 7 14:44:14 2024 +1000
Details on disabled `fbdev` kernel modules
commit e98dc8c4f8af32dd3b10c034477fd2154df189ac
Author: Raja Grewal <rg_public@proton.me>
Date: Wed Aug 7 14:14:47 2024 +1000
Update notifications for disabled kernel modules
commit 50fa721fd54cd696ae90a35bc7df7c8f1eb17a13
Author: Raja Grewal <rg_public@proton.me>
Date: Wed Aug 7 14:01:49 2024 +1000
Update docs regarding Intel module disabling
commit ec3038c7bc625f6c8eddb753ffe295ff2697a717
Author: Raja Grewal <rg_public@proton.me>
Date: Wed Aug 7 13:48:53 2024 +1000
Clarify `secure_redirects`
commit debd7a7b7ae8b03e04d2c8597bcccf2c79000570
Author: Raja Grewal <rg_public@proton.me>
Date: Wed Aug 7 13:33:44 2024 +1000
Provide optional `sysctl fs.binfmt_misc.status=0`
commit 89e816dda6c5a00512b276071c4d9fe108ee63b5
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Aug 6 14:01:39 2024 +0000
bumped changelog version
commit 967f9e257b09bc73ddb579292d507f7cb9832643
Merge: fa90918 a25aaf9
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Aug 6 09:57:56 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit a25aaf900a12666046278a9fab6933b3d5670679
Merge: 6bc039a 8559079
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Aug 6 09:55:20 2024 -0400
Merge pull request #260 from raja-grewal/vdso32
Enable `vdso32=0`
commit 6bc039a430289342f06857a52a5f13829d6e50f5
Merge: ce60d56 d102ec1
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Aug 6 09:52:56 2024 -0400
Merge pull request #259 from raja-grewal/kfence
Enable `kfence.sample_interval=100`
commit ce60d5615fe99e41c48d459f562d581a688c295a
Merge: b027842 c0d140f
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Aug 6 09:48:08 2024 -0400
Merge pull request #258 from raja-grewal/legacy_tiocsti
Enable `dev.tty.legacy_tiocsti=0`
commit b0278428a73cd3d329aaa36626005e0c593331f0
Merge: fa90918 aa34d86
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Tue Aug 6 09:39:04 2024 -0400
Merge pull request #257 from raja-grewal/slab_debug
Enable `slab_debug=FZ`
commit 8559079312adb4ed92e5f478120b408dfe7a1124
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 5 15:10:02 2024 +1000
Enable `vdso32=0`
commit d102ec19972865032f12f90bffe3e592546f0267
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 5 15:07:56 2024 +1000
Enable `kfence.sample_interval=100`
commit c0d140f2211e6490d13e3cd327005027c668905f
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 5 15:06:34 2024 +1000
Enable `dev.tty.legacy_tiocsti=0`
commit aa34d86598f5b846b007730104e4c99c59f9984d
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 5 14:27:17 2024 +1000
Enable `slab_debug=FZ`
commit 4f7f82016015f61002ac8f778b61968c572dc7dc
Author: Raja Grewal <rg_public@proton.me>
Date: Mon Aug 5 14:16:33 2024 +1000
Add reference
commit fa9091869d417c6494840d0cb32623037d70c8be
Merge: 06f0c27 725118c
Author: Patrick Schleizer <adrelanos@whonix.org>
Date: Sun Aug 4 16:20:36 2024 -0400
Merge remote-tracking branch 'github-kicksecure/master'
commit 725118c5759b45118bbd2804492526ea2a7c1a81