-
Notifications
You must be signed in to change notification settings - Fork 49
/
Copy pathchangelog.upstream
17254 lines (11449 loc) · 490 KB
/
changelog.upstream
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
commit df9d058ed9635b168508ded20277c174a24cf3f5
Author: Patrick Schleizer <[email protected]>
Date: Mon Jan 20 06:28:16 2025 -0500
usrmerge
commit 8ff5f3b22125488f64cd384ffbfcbd8f2ecd61a6
Author: Patrick Schleizer <[email protected]>
Date: Mon Jan 20 10:11:43 2025 +0000
bumped changelog version
commit 4e0d5a196ccb8ef3fdf2b67d974f28d02a532f91
Author: Patrick Schleizer <[email protected]>
Date: Mon Jan 20 04:30:26 2025 -0500
delete comment only configuration file (moved to user-sysmaint-split)
commit 1b4d1edfc316f125ff5039bf17897802205750e2
Author: Patrick Schleizer <[email protected]>
Date: Mon Jan 20 04:29:42 2025 -0500
comments
commit 51c7010e8f47ce6e6a28e6267c735e897dcfb053
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 17 13:35:28 2025 +0000
bumped changelog version
commit 876d596a071ac916f7d220ee2449358aedba7efe
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 17 07:55:54 2025 -0500
comment
commit c9e2f82bd01813682998c775f75bac0841239e5e
Merge: 5971869 bf73f1f
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 17 07:53:59 2025 -0500
Merge remote-tracking branch 'ArrayBolt3/master'
commit bf73f1f2b5e429caaf01bfbcdc7d5d032e3c0efb
Author: Aaron Rainbolt <[email protected]>
Date: Wed Jan 15 19:10:41 2025 -0600
Avoid impossible-to-satisfy dependency on helper-scripts, improve string handling robustness in postinst
commit 597186972e463ce7a0b44662f7656f351ddf1030
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 15:02:44 2025 +0000
bumped changelog version
commit ca257164105c4f66576024b64c52a42921455d16
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 09:44:48 2025 -0500
improve permission hardener migration code
commit 2dfd30a44ae332faa50bc4920486cdd9480c7e5d
Merge: a84d3ba 328f747
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 09:33:57 2025 -0500
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/more-permission-hardener'
commit 328f747179ffb2e7705a73bc9a0c5133a17da829
Author: Aaron Rainbolt <[email protected]>
Date: Tue Jan 14 20:35:28 2025 -0600
Restore permission-hardener's notice about how to compare old and new states
commit c6f09748f383fdf7c1b07441c73477b3f18d2768
Author: Aaron Rainbolt <[email protected]>
Date: Tue Jan 14 20:27:53 2025 -0600
Handle de-corruption of new_mode a bit better
commit a0f81958dfb020d311d86cbd00d4f86f678d8be9
Author: Aaron Rainbolt <[email protected]>
Date: Tue Jan 14 19:25:15 2025 -0600
De-corrupt the new_mode permission-hardener statoverride database too
commit 396372c1295e2a09d596f3e23fccc26794a26f05
Author: Aaron Rainbolt <[email protected]>
Date: Tue Jan 14 18:50:24 2025 -0600
Avoid scanning unnecessary packages for modified permission-hardener config
commit a84d3ba732bcbd2fb93ea2bc145a0db0f33f1b77
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 14:32:13 2025 +0000
bumped changelog version
commit 709036c79f8efc9fefa9e7709780a75f9f5004d2
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:31:58 2025 -0500
debconf-updatepo
commit 659c7037c6956f6d905e55a1ebb13ebe6a273dee
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 14:30:58 2025 +0000
bumped changelog version
commit 86d3db15bf94dc0f4547105e18ef5f26ca124fa8
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:30:46 2025 -0500
output
commit 876c0b618785fc71d1d399ff7ab649382104a714
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:29:35 2025 -0500
output
commit c46178dee46f88e8d0007a12a48addc2493faab7
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:27:37 2025 -0500
output
commit f3c07a2451fd2818daca6bc248cbbcba213516e7
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:24:06 2025 -0500
update link
commit bbc4ad7c2a0827d079ccbb18dce4aaae042a2253
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 14:16:45 2025 +0000
bumped changelog version
commit 9bb92e91a8f364a9d9e5d69e907fe8ed8a3c58a2
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:16:25 2025 -0500
debhelper
commit 95dd8f419fc7e9832d8ce6f74d35af9b36752f3f
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 14:07:50 2025 +0000
bumped changelog version
commit 0a2f06b456854f1cec3ff93952edef928ac7a184
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:07:32 2025 -0500
use pre.bsh
commit 6a4f9c1bd8c48bb1a711eee077ea7a05646b0598
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 14:06:50 2025 +0000
bumped changelog version
commit e60183ec073d278f8d69a5475aa52d75870cd9b0
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:06:41 2025 -0500
output
commit a812961beabacca052b4b25b78ecd2c35184d5d5
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:06:12 2025 -0500
verbose
commit 0e4dfc59dd9c06dd732affd8ca7f72a1a70a95b0
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 13:53:49 2025 +0000
bumped changelog version
commit cdf179f1277bcae3ef681d35aeca6289d55b3a6a
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 08:53:38 2025 -0500
fix
commit 41cd09933a506d55bab1f8bf101840cf4bbbf028
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:26:05 2025 +0000
bumped changelog version
commit eec2e2c8ee621c6ebb152abbfe3951fa0322a0d0
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 04:13:39 2025 -0500
comment
commit 6d282226ef653accf1de32582b999ff31775f60f
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 04:12:12 2025 -0500
comment
commit 466308e4f9ebd496ff54dd9f77881ce10a558802
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 04:09:57 2025 -0500
permission hardener: disable SUID for `chrome-sandbox`
commit 7a5f8b87af7142ce973bd88abf98279ce15559a9
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 04:06:44 2025 -0500
permission hardener: disable SUID for `ssh-agent`, `ssh-keysign`, `/lib/openssh/*`
This might break SSH host-based authentication.
commit d89ffcde30f6115c25c1bc807eb30b18c21e2b6e
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 04:04:09 2025 -0500
comment
commit 9f1759ba0ea7ecee87c8777226eb8a56482deeb5
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 03:56:55 2025 -0500
comment
commit 0ac85ea9f56abdf621ec1b4f2acf08a2450067ba
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 03:54:35 2025 -0500
comment
commit fce6a5f8303cd891efd8bbfef861e357dc90e88e
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 03:51:43 2025 -0500
comment
commit 1e9940481318d8d7a443b98f0906089759f27a5d
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 03:50:16 2025 -0500
comment
commit b198591537a01f5b35c9301ca28a24c70864bcbd
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 03:49:42 2025 -0500
comment
commit 7d44db2cb268c4eb31b50bbd44b87b8001dc068c
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 03:49:15 2025 -0500
usrmerge
commit 7e7632a55396e10e20a6e9d8d563011694cccc85
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 08:24:05 2025 +0000
bumped changelog version
commit 420cb3f86f69c4505702a8f38271fb095316cb6f
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 03:19:21 2025 -0500
refactoring
commit b7e7b2767eb957dd1401f5abcff07bfcb47a4c00
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 03:18:17 2025 -0500
refactoring
commit b2a1a0ec9f8db1d84c222e734737b7ed149f6d92
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 03:17:00 2025 -0500
refactoring
commit 69ae2d9ea0826aa81c70e957bb5a9241a84346ad
Merge: de1f31e de9ebab
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 03:15:45 2025 -0500
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/permission-hardener-migrate'
commit de9ebabd46798ff2afa259907b6a7b976070e7f0
Author: Aaron Rainbolt <[email protected]>
Date: Mon Jan 13 21:57:10 2025 -0600
Fix minor migration bugs, don't run the migration code on new image builds
commit a9e87e9d308f5e61a2d2054fa038dae6faadad3a
Author: Aaron Rainbolt <[email protected]>
Date: Sun Jan 12 21:13:43 2025 -0600
Prevent installation failures when installing non-interactively
commit 5570d3e5b9f97f14c772facff16dc45df66d42e9
Author: Aaron Rainbolt <[email protected]>
Date: Sun Jan 12 20:40:41 2025 -0600
Add a forgotten set -e
commit 07786de03953b91310588e0b37b9e150bf1b4736
Author: Aaron Rainbolt <[email protected]>
Date: Sun Jan 12 19:34:41 2025 -0600
Enable smooth migration from permission-hardener-v1 to permission-hardener-v2
commit de1f31e3df1a0fba0a4c6e41b9b46e076266cfd4
Author: Patrick Schleizer <[email protected]>
Date: Sun Jan 12 11:47:18 2025 +0000
bumped changelog version
commit b0baa8baa57937358dc988b88adab4858a1d8cae
Author: Patrick Schleizer <[email protected]>
Date: Sun Jan 12 05:38:35 2025 -0500
add link
commit d6a7cd3e0d1e677c1fa8c1fb3b307cdbe0f45031
Author: Patrick Schleizer <[email protected]>
Date: Sun Jan 12 05:36:16 2025 -0500
formatting.
use chapter to make allow for deep linking
commit 485d9abd1d14e445b48f0fd63290a985b05a5ac7
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 10 15:34:21 2025 +0000
bumped changelog version
commit c17485baa118e76cc8074ce3e72ac3ac38c577cd
Merge: 482960d e9ef360
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 10 10:32:26 2025 -0500
Merge remote-tracking branch 'github-kicksecure/master'
commit e9ef3602dd1661de0c0c3781d7e0246720643354
Merge: 1b33e83 cf435a8
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 10 10:30:34 2025 -0500
Merge pull request #292 from raja-grewal/cpu_table
Add link to tabular comparison of CPU mitigations
commit 1b33e83529d652dab4468e0b386e333b3ca4745b
Merge: 486757b 2e6e170
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 10 10:29:30 2025 -0500
Merge pull request #291 from raja-grewal/drop_gratuitous_arp
Drop gratuitous ARP packets
commit 486757bfae5e7ecc389b16c49704e742fd267565
Merge: 17ff249 c37f4ef
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 10 10:29:12 2025 -0500
Merge pull request #290 from raja-grewal/arp_ignore
Respond to ARP requests only if the target IP address is on-link
commit 17ff24915062736a32d4d54da7163fe34aa70fd3
Merge: 27d19ba 1f8eee4
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 10 10:28:48 2025 -0500
Merge pull request #289 from raja-grewal/arp_filter
Enable ARP filtering
commit 27d19ba568e601c37035a310ae6cdd7d953be286
Merge: 482960d 5e3785d
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 10 10:28:05 2025 -0500
Merge pull request #288 from raja-grewal/shared_media
Deny sending and receiving shared media redirects
commit 482960d056ec8d624f127bfe9b1c69a4c30c7e34
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 10 10:21:12 2025 -0500
permission-hardener: move to new state folder `/var/lib/permission-hardener-v2` without migration
https://github.com/Kicksecure/security-misc/pull/294
commit cf435a8fa8e6f795a25ef004cf44a65d461dd32c
Author: raja-grewal <[email protected]>
Date: Fri Jan 10 13:22:21 2025 +1100
README.md: Note importance of microcode updates
commit 3a31cc99b34617cdd3c5f8e8950a37158849cb56
Merge: c4cfb85 5941195
Author: Patrick Schleizer <[email protected]>
Date: Thu Jan 9 09:30:58 2025 -0500
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/usrmerge'
commit 538b312349a97bcecb12e62519d77840afcd6ca3
Author: raja-grewal <[email protected]>
Date: Thu Jan 9 15:28:56 2025 +1100
Add comment about microcode updates
commit 1f8eee47200221e2e38291a31e852e9c222d8c64
Author: raja-grewal <[email protected]>
Date: Wed Jan 8 18:36:00 2025 +1100
Add missing sentence full stop
commit 5e3785d76e616f49407e720b37138f35a50fe4fb
Author: raja-grewal <[email protected]>
Date: Wed Jan 8 18:35:52 2025 +1100
README.md: Remove double space
commit 5941195e96880b8beb2a791d3c21f3a4c6d429eb
Author: Aaron Rainbolt <[email protected]>
Date: Tue Jan 7 14:10:46 2025 -0600
Don't worry about files under /bin anymore, Bookworm uses a merged /usr directory
commit c4cfb8597d1a8631a4cbfa7e88212b798e2bc514
Merge: c6be621 93ebf17
Author: Patrick Schleizer <[email protected]>
Date: Mon Jan 6 08:43:54 2025 -0500
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/permission-hardener-refactor'
commit c6be621968c898f792ef1a450d2e1be5cd6056da
Author: Patrick Schleizer <[email protected]>
Date: Mon Jan 6 10:31:40 2025 +0000
bumped changelog version
commit 6e0787957b53a64132b64e2a29bafe3e4b66d178
Author: Patrick Schleizer <[email protected]>
Date: Mon Jan 6 05:29:40 2025 -0500
increase priority of pam wheel so it is checked even before faillock
in case of attemtping to use `su` without being a member of the required group `sudo`, it's useful to abort the PAM stack as early as possible to avoid needlessly propmting for a password to later
be rejected tu to lack of group membership
commit d4767b75206b46f1a006cd91b00239a7b828fc89
Author: Patrick Schleizer <[email protected]>
Date: Mon Jan 6 04:24:44 2025 -0500
fix: apply PAM wheal only to `su` PAM service
commit 93ebf176c5f38bd268e5394e01421e46b9ae7dff
Author: Aaron Rainbolt <[email protected]>
Date: Thu Jan 2 20:41:40 2025 -0500
Make the main field count check in permission-hardener a bit more elegant
commit 895c0f541fb34f9ebfee9c7ef79c053d5af4a7cc
Merge: 717e6fc 40b23cf
Author: Aaron Rainbolt <[email protected]>
Date: Wed Jan 1 15:04:01 2025 -0600
Merge branch 'master' into arraybolt3/permission-hardener-refactor
commit 40b23cfad40825eefc3686e562d78250b58bbc82
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 31 18:42:01 2024 +0000
bumped changelog version
commit 33114f771aaeb4dccb0b465861d1239129deb8b2
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 31 13:26:21 2024 -0500
copyright
commit bb24bff2965ca31de6337820eafd787a11a44a2b
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 31 14:09:34 2024 +0000
bumped changelog version
commit 0640964c35b0d977ba718629d4a8791e67700202
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 31 06:14:29 2024 -0500
readme
commit 717e6fcfbea38cef9d3e201cf2e2b725e3da2267
Author: Aaron Rainbolt <[email protected]>
Date: Mon Dec 30 19:23:20 2024 -0600
Post-review improvements to permission-hardener
commit dbcb612517abbf8d162cfb31ba0585c518df8817
Author: Aaron Rainbolt <[email protected]>
Date: Wed Dec 25 19:48:28 2024 -0600
Polish permission-hardener refactor
commit 397b476a822c9f7e41ec911f5d689b67026660ad
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 26 04:12:02 2024 +0000
bumped changelog version
commit 66f8c18c65f33676d242b57ebb1d4410876461b3
Merge: aa82202 6602fb1
Author: Patrick Schleizer <[email protected]>
Date: Wed Dec 25 22:43:04 2024 -0500
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/sysmaint'
commit 83d386795940099e0835c51f3522aae3d9217dc8
Author: Aaron Rainbolt <[email protected]>
Date: Tue Dec 24 20:14:57 2024 -0600
Refactor permission-hardener to be more idempotent
commit 6602fb102dedc21300ae4c4519f3d9ef4e668045
Author: Aaron Rainbolt <[email protected]>
Date: Tue Dec 24 20:52:34 2024 -0600
Adjust pam-info messaging for sysmaint mode
commit aa82202e701167eacb63eac208469844e983ca43
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 24 05:16:22 2024 +0000
bumped changelog version
commit 27d015d58ebc5e750d9d06f042b761720473941d
Merge: 3c73c0c 2f3a2bc
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 24 00:08:58 2024 -0500
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/sysmaint'
commit 2f3a2bce7756efe75cd8aaf5066b599b4c49bbdc
Author: Aaron Rainbolt <[email protected]>
Date: Fri Dec 20 11:04:22 2024 -0600
Add warning about using non-sysmaint accounts in sysmaint mode
commit 3c73c0cd3a845d1a484551ff50f59e5f2ef56a68
Author: Patrick Schleizer <[email protected]>
Date: Fri Dec 20 06:01:27 2024 +0000
bumped changelog version
commit a4c76c617a18a49168e0ffdba2d8b0ae834f2877
Author: Patrick Schleizer <[email protected]>
Date: Fri Dec 20 01:01:13 2024 -0500
syntax fix
commit b40bc0a2c9b17b3569918a6839bce1c67af5c9df
Author: Patrick Schleizer <[email protected]>
Date: Fri Dec 20 05:58:24 2024 +0000
bumped changelog version
commit b21c394ea52401c0d77b6ec396af6a49335f5e0b
Author: Patrick Schleizer <[email protected]>
Date: Fri Dec 20 00:56:20 2024 -0500
Trigger permission hardener when new configuration files are being installed.
commit cd027b86e710b6f6b8fac6dd0ebcdcd691e86dd3
Author: Patrick Schleizer <[email protected]>
Date: Fri Dec 20 05:48:48 2024 +0000
bumped changelog version
commit ad6e1f5ad490e12fc5e69b82da5dc1830cc41c96
Author: Patrick Schleizer <[email protected]>
Date: Fri Dec 20 00:41:06 2024 -0500
move from `/etc/permission-hardener.d` to `/usr/lib/permission-hardener.d`
commit a2c1e8c218117a47ef70dd767d753be5d084adfa
Author: Patrick Schleizer <[email protected]>
Date: Fri Dec 20 00:39:51 2024 -0500
clean up old files in `/etc/permission-hardener.d`
because will be moved to `/usr/lib/permission-hardener.d`
commit 6de5d2d0763539d6d0d4b19b501bb316ed3b2c94
Author: Patrick Schleizer <[email protected]>
Date: Fri Dec 20 00:37:44 2024 -0500
permission hardener: also parse `/usr/lib/permission-hardener.d/*.conf` folder
commit 721b100fb64136b7c36c8d43c90c716a1fed42d0
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 19 10:58:50 2024 +0000
bumped changelog version
commit 642b4eeedc43e69bb82ea259b52c0946ce638983
Author: raja-grewal <[email protected]>
Date: Thu Dec 19 21:57:25 2024 +1100
Add link to tabular comparison of CPU mitigations
commit 175b442d5bb9dfcb4e9b524ec2077e72c74598cc
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 19 05:56:50 2024 -0500
use long option name
commit c99021bb0c1d5b6bf361cc483449330cdd218ee6
Merge: 95b5357 9d69cd1
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 19 05:56:01 2024 -0500
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/sysmaint'
commit 2e6e1701a052ef32711f6c3abaad693a773323f6
Author: raja-grewal <[email protected]>
Date: Thu Dec 19 10:35:08 2024 +0000
Set `net.ipv4.conf.*.drop_gratuitous_arp=1`
commit c37f4efadf8f046168732871172cb66f58eb7c78
Author: raja-grewal <[email protected]>
Date: Thu Dec 19 10:33:49 2024 +0000
Set `net.ipv4.conf.*.arp_ignore=2`
commit af1d06973bdd46af3e39b0bdfda81b950ccac996
Author: raja-grewal <[email protected]>
Date: Thu Dec 19 10:31:43 2024 +0000
Set `net.ipv4.conf.*.arp_filter=1`
commit 750367a9066ca2a0ff819b438a92cb1f6c325edb
Author: raja-grewal <[email protected]>
Date: Thu Dec 19 10:29:56 2024 +0000
Set `net.ipv4.conf.*.shared_media=0`
commit 95b535764c8a98b67a71ee1fd57b7f01da464106
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 19 09:43:26 2024 +0000
bumped changelog version
commit daf0a0900b780a9d44d0d9b49b3fca6ddbd20d18
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 19 04:39:34 2024 -0500
fix apt-get-update for non-English locale
https://forums.kicksecure.com/t/systemcheck-reports-warning-debian-package-update-check-result-apt-get-reports-that-packages-can-be-updated-but-system-is-already-fully-upgraded/785
commit e9a5b14a0db6f071424c19e6f4b006386afb6ab4
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 19 06:57:42 2024 +0000
bumped changelog version
commit 3135a03e21f9e5816097e25aaa7f4a1671f8f87d
Merge: f0c611d c7f7196
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 19 00:34:56 2024 -0500
Merge remote-tracking branch 'github-kicksecure/master'
commit c7f7196471b07a580c6d4a5d86739215508142cd
Merge: e5b67e0 3749f8f
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 19 00:31:25 2024 -0500
Merge pull request #287 from raja-grewal/patch
Refactor and add two CPU mitigations
commit f0c611d9edb5fd7a3e00d13b248c65abda2c9d8a
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 19 00:18:25 2024 -0500
comment
commit 4f681be77429984695a1b0f689065051884e7bf7
Merge: 4c3ca68 4cf5757
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 19 00:17:44 2024 -0500
Merge remote-tracking branch 'github-kicksecure/master'
commit e5b67e044bb5011dd667879a73a670f2c5f74057
Merge: 4cf5757 c116796
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 19 00:15:02 2024 -0500
Merge pull request #279 from raja-grewal/arp
Provide network-related hardening options via `sysctl`'s
commit 4cf5757575c1257a14331f0169a9d8d163e1326d
Merge: 9d06341 1708a03
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 19 00:08:56 2024 -0500
Merge pull request #282 from ArrayBolt3/arraybolt3/umask
Enable umask hardening
commit 9d69cd1912ab657e7916b38f56b477c2b7abd0a3
Author: Aaron Rainbolt <[email protected]>
Date: Wed Dec 18 21:34:16 2024 -0600
Add sysmaint account lock detection
commit 3749f8ff097551a843e5ed80de52c6770a32e0c6
Author: raja-grewal <[email protected]>
Date: Wed Dec 18 03:36:09 2024 +0000
Update presentation on user namespaces
commit 0dff2cd28fd769955757cdef1b7f9d637a1180c5
Author: raja-grewal <[email protected]>
Date: Wed Dec 18 03:32:35 2024 +0000
Minor additions
commit 3e96fdd9ccb6268403d6c4f9a061c4a33e6f6dd2
Author: raja-grewal <[email protected]>
Date: Tue Dec 17 11:44:11 2024 +0000
Enable `kvm.mitigate_smt_rsb=1`
commit 45355aabdc180a6a2fdd4a374c6f7d72f4d36240
Author: raja-grewal <[email protected]>
Date: Tue Dec 17 11:42:52 2024 +0000
Enable `kvm-intel.vmentry_l1d_flush=always`
commit defba1f2450b2c8bbc668bf5f6f6f0d101338cc7
Author: raja-grewal <[email protected]>
Date: Tue Dec 17 11:42:03 2024 +0000
Refactor CPU mitigations
commit 943c421889ce5dfe3869380e4587ca22724f2ce7
Author: raja-grewal <[email protected]>
Date: Tue Dec 17 11:40:38 2024 +0000
Minor refactoring
commit ca3a73ac13d805515f71f1be7ecedc33d3a1b519
Author: raja-grewal <[email protected]>
Date: Tue Dec 17 11:37:10 2024 +0000
Typo
commit 4c3ca68453b44074025a1ec9f31451c57344f3cf
Author: Aaron Rainbolt <[email protected]>
Date: Mon Dec 9 12:37:11 2024 -0600
Disable unnecessary sudoers exceptions
commit 9d06341c91b51f9c737fe67457045924323635f0
Merge: a9dd592 5b88e92
Author: Patrick Schleizer <[email protected]>
Date: Sat Dec 14 15:18:56 2024 -0500
Merge pull request #285 from Kicksecure/permission-hardener-mount
Permission Hardener: treat mount same as umount
commit c1167968542a62d0677517e11505f6e9222ec378
Author: raja-grewal <[email protected]>
Date: Thu Dec 12 06:36:47 2024 +0000
`arp_ignore`: Add reference to 2024-12-10 Mullvad VPN audit details
commit a9dd592a8b49226f326e90111178aebba3cc144f
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 10 19:19:10 2024 +0000
bumped changelog version
commit 58722324ec0be98c3e44938df8cb60ca9b261210
Merge: 518224b 439fa7f
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 10 14:18:50 2024 -0500
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/no-recovery-mode'
commit 518224b8cf9e99a830b584d8d54b5dea2925c8f5
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 10 19:17:10 2024 +0000
bumped changelog version
commit 439fa7f3be74f5eba4b98f73c0bb50fd37e8b0e1
Author: Aaron Rainbolt <[email protected]>
Date: Sun Dec 8 03:21:27 2024 -0600
Harden/disable recovery mode options
commit 7902311c570edd4286ba36f0cb85223d1e909a03
Author: Patrick Schleizer <[email protected]>
Date: Sat Dec 7 04:54:47 2024 -0500
do not create /etc/sysctl.d/30-lkrg-virtualbox.conf if LKRG is not installed
commit 1ce37d42cd2c132eca8c45ddb04fdb594349d08f
Author: Patrick Schleizer <[email protected]>
Date: Sat Dec 7 04:50:40 2024 -0500
.
commit 5b88e92e5c4b951e659e1574fc248bd11158dfb2
Author: Patrick Schleizer <[email protected]>
Date: Fri Dec 6 09:48:58 2024 -0500
permission hardner: treat `mount` the same way we treat `umount`
Thanks to @the-moog for the bug report!
fixes https://github.com/Kicksecure/security-misc/issues/284
commit 93b51819d4693955936456916188b4118fe68a66
Author: Patrick Schleizer <[email protected]>
Date: Fri Dec 6 09:47:08 2024 -0500
permission hardener mount chmod change from `745` to `755`
https://github.com/Kicksecure/security-misc/issues/284
commit 1708a03e1edda821ef091f10c46d32f740511d38
Author: Aaron Rainbolt <[email protected]>
Date: Thu Nov 28 15:20:57 2024 -0600
Enable umask hardening
commit 59299a6639fef31565b8f3cef857c9faa331e0f7
Author: Patrick Schleizer <[email protected]>
Date: Mon Nov 25 21:07:42 2024 +0000
bumped changelog version
commit 98d7c245ee11f16e566422a17543aaed2c155d88
Author: Patrick Schleizer <[email protected]>
Date: Mon Nov 25 15:57:30 2024 -0500
"|| exit 1" no longer required thanks to errexit
commit f9b5d7d3f4f2ed8d1baae67d8427f13cf26aee8d
Author: Patrick Schleizer <[email protected]>
Date: Mon Nov 25 15:48:01 2024 -0500
use strict shell options
commit d32cb8c95b09721e52c4d682a0ddd39d590a4368
Author: Patrick Schleizer <[email protected]>
Date: Mon Nov 25 15:44:00 2024 -0500
use TMP, sponge, refactoring
commit 62a551cfe39a6a640f32e6e97f3e915aa8673514
Merge: af43472 d7475e2
Author: Patrick Schleizer <[email protected]>
Date: Mon Nov 25 15:38:01 2024 -0500
Merge remote-tracking branch 'ArrayBolt3/arraybolt3/sudoers'
commit d7475e252a64e296913ed8893261e52e72163d55
Author: Aaron Rainbolt <[email protected]>
Date: Thu Nov 21 20:03:42 2024 -0600
Make apt-get-update able to be terminated securely
commit af43472d0ccdecb1725a200d10aeeb1b8d51f31a
Author: Patrick Schleizer <[email protected]>
Date: Thu Nov 14 22:24:50 2024 +0000
bumped changelog version
commit c7e9460b2ae8dcb96196fef69a7e0ed992c1b43b
Author: Patrick Schleizer <[email protected]>
Date: Thu Nov 14 16:31:12 2024 -0500
output
commit 31804e30ecc9c5a1c5a8e1e014d3dcb85cee4f36
Author: Patrick Schleizer <[email protected]>
Date: Thu Nov 14 20:46:26 2024 +0000
bumped changelog version
commit ef95b3f9a5aed9652c541cf4bf05b20011718466
Author: Patrick Schleizer <[email protected]>
Date: Thu Nov 14 14:41:14 2024 -0500
Revert "fix `panic-on-oops.service`"
This reverts commit 862d23cb10b7687084f8e7e207d1e2c9c1ef6751.
commit 412b371e85044962f6620386b767369b9e25d71e
Merge: 141b84c 57e1edd
Author: raja-grewal <[email protected]>
Date: Wed Nov 13 16:47:57 2024 +1100
Merge branch 'Kicksecure:master' into arp
commit 141b84c40de76988ec78bdccf1c1d67fc4367b3f
Author: raja-grewal <[email protected]>
Date: Wed Nov 13 05:42:56 2024 +0000
Provide option to deny sending and receiving shared media redirects
commit 18aec201bfb0477fee8800ad1388099e11920016
Author: raja-grewal <[email protected]>
Date: Wed Nov 13 05:41:25 2024 +0000
Provide option to harden response to ARP requests
commit a25d4f8df88908e83e56049204aa625f1196a948
Author: raja-grewal <[email protected]>
Date: Wed Nov 13 05:40:21 2024 +0000
Provide option to enable ARP filtering
commit c2aae73ce161811571e4c85609a0b043399c1b65
Author: raja-grewal <[email protected]>
Date: Wed Nov 13 05:38:03 2024 +0000
Add reference and move text
commit 57e1edde23aa3f313ce087e00ebc14d158356d6c
Author: Patrick Schleizer <[email protected]>
Date: Tue Nov 12 09:11:57 2024 +0000
bumped changelog version
commit 7987a3914d364e674eb7479b15708c450041af02
Author: Patrick Schleizer <[email protected]>
Date: Tue Nov 12 02:29:42 2024 -0500
deleted no longer used and out-commented `/etc/sudoers.d/xfce-security-misc` leftover
commit 8c2e8e69798e5255529ab3dbee6ca07b8b293100
Author: Patrick Schleizer <[email protected]>
Date: Tue Nov 12 01:41:12 2024 -0500
deleted no longer used and out-commented `etc/sudoers.d/pkexec-security-misc` leftover
commit 65fc0419a84d62e07c61d7e37ef27d144b6b6794
Author: Patrick Schleizer <[email protected]>
Date: Mon Nov 11 11:07:57 2024 +0000
bumped changelog version
commit 50161f5d79eea2ab796863e4eb30eccc17e0b41d
Author: Patrick Schleizer <[email protected]>
Date: Mon Nov 11 05:48:11 2024 -0500
moved /etc/dkms/framework.conf.d/30_security-misc.conf (renamed) to usability-misc
commit 7c06e22c7d11c345428f3ad42ba43805ebc8d810
Author: Patrick Schleizer <[email protected]>
Date: Mon Nov 11 05:43:25 2024 -0500
deleted `/usr/bin/pkexec.security-misc`
This was not used anymore for anything. In the past, we used to `config-package-dev` `replace` `/usr/bin/pkexec` with `/usr/bin/pkexec.security-misc` for the purpose of:
> Redirect calls for pkexec to lxqt-sudo because pkexec is incompatible with hidepid.
* https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860040
* https://forums.whonix.org/t/cannot-use-pkexec/8129
This was a worthwhile effort, interesting approach but ultimately a dead-end.
commit ef05b1a160b24d5aa42da9cc15009d94a37cf120
Author: Patrick Schleizer <[email protected]>
Date: Mon Nov 11 05:40:41 2024 -0500
disable legacy matroxfb_base framebuffer driver