- 19 Jun, 2021 12 commits
-
-
Alexander Popov authored
-
Alexander Popov authored
-
Alexander Popov authored
-
Alexander Popov authored
-
Alexander Popov authored
-
Alexander Popov authored
-
Alexander Popov authored
-
Alexander Popov authored
-
Alexander Popov authored
-
Alexander Popov authored
-
Made with updated https://github.com/a13xp0p0v/kernel-build-containers Excellent!
Alexander Popov authored -
Alexander Popov authored
-
- 18 Jun, 2021 3 commits
-
-
Alexander Popov authored
-
Alexander Popov authored
-
Alexander Popov authored
-
- 30 Oct, 2020 2 commits
-
-
Ready for the release 0.5.9.
Alexander Popov authored -
Alexander Popov authored
-
- 29 Oct, 2020 1 commit
-
-
Alexander Popov authored
-
- 23 Oct, 2020 2 commits
-
-
Alexander Popov authored
-
Alexander Popov authored
-
- 22 Oct, 2020 7 commits
-
-
Alexander Popov authored
-
Alexander Popov authored
-
Enable UBSAN_BOUNDS and UBSAN_TRAP. But keep UBSAN_MISC disabled to avoid useless reports.
Alexander Popov authored -
In fact, KSPP recommends PAGE_POISONING_ZERO.
Alexander Popov authored -
Alexander Popov authored
-
In fact HARDEN_EL2_VECTORS was included in RANDOMIZE_BASE in v5.9. Use new nested ComplexOptChecks for this rule. Refers to #48.
Alexander Popov authored -
Thanks, @pgils. Refers to #48.
Alexander Popov authored
-
- 21 Oct, 2020 1 commit
-
-
Now we can do things like OR(opt1, AND(opt2, opt3)). Cool! Refers to #48
Alexander Popov authored
-
- 19 Oct, 2020 1 commit
-
-
Pelle van Gils authored
-
- 16 Oct, 2020 4 commits
-
-
Alexander Popov authored
-
Alexander Popov authored
-
Alexander Popov authored
-
CLIP OS wiki and Kees say that BPF interpreter is worse for the kernel security than BPF_JIT. So for now I withdraw my recommendation about BPF_JIT. N.B. LOCKDOWN disables BPF_SYSCALL, but not BPF_JIT.
Alexander Popov authored
-
- 14 Oct, 2020 2 commits
-
-
Alexander Popov authored
-
Alexander Popov authored
-
- 15 Jul, 2020 5 commits
-
-
Ready for release 0.5.7
Alexander Popov authored -
Alexander Popov authored
-
Alexander Popov authored
-
CONFIG_X86_IOPL_IOPERM is also disabled by kernel lockdown
Alexander Popov authored -
Alexander Popov authored
-