forked from Kicksecure/security-misc
-
Notifications
You must be signed in to change notification settings - Fork 0
/
changelog.upstream
6829 lines (4526 loc) · 194 KB
/
changelog.upstream
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
commit 1f6ed2cc7047e1144e811d94dddc7306ee93b61e
Author: Patrick Schleizer <[email protected]>
Date: Mon Feb 3 08:55:20 2020 -0500
add support for passing parameters to usr/lib/security-misc/apt-get-update
commit 2291b7f787bcec5f64f632c6f3e8dfb12c67b4ee
Author: Patrick Schleizer <[email protected]>
Date: Mon Feb 3 08:43:31 2020 -0500
bumped changelog version
commit 8627c9f76d1bdf26a423a92506d3d8c0eb1afc2e
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 31 12:18:02 2020 -0500
/usr/lib/security-misc/apt-get-update increase default timeout_after="600"
commit 829e28aa90ff5cb38edcc3cfab8ec91939ae5844
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 31 12:17:07 2020 -0500
/usr/lib/security-misc/apt-get-update environment variable timeout_after kill_after support
commit 0bd0a4a647aef9899e1cbb5671ccfa3ca36efe18
Author: Patrick Schleizer <[email protected]>
Date: Thu Jan 30 06:14:34 2020 -0500
bumped changelog version
commit 85d2aa1365ae5dfc43944a938794954452c26fe0
Author: Patrick Schleizer <[email protected]>
Date: Thu Jan 30 06:13:42 2020 -0500
hide stdout (but not stderr) by sysctl during initramfs
commit d69c1839cd30145c30247e0962a97cfd38f79d60
Author: Patrick Schleizer <[email protected]>
Date: Thu Jan 30 06:02:26 2020 -0500
bumped changelog version
commit b9d65338bcc76552e4d2169106cd04e6276eb320
Author: Patrick Schleizer <[email protected]>
Date: Thu Jan 30 05:55:13 2020 -0500
unconditionally enable all CPU bugs (spectre, meltdown, L1TF, ...)
this might reduce performance
* `spectre_v2=on`
* `spec_store_bypass_disable=on`
* `tsx=off`
* `tsx_async_abort=full,nosmt`
Thanks to @madaidan for the suggestion!
https://forums.whonix.org/t/should-all-kernel-patches-for-cpu-bugs-be-unconditionally-enabled-vs-performance-vs-applicability/7647
commit 2711d0f7f08362f97383fbae81ce9d520b19dcbc
Author: Patrick Schleizer <[email protected]>
Date: Thu Jan 30 01:22:32 2020 -0500
bumped changelog version
commit 4df0d6c01cc91139dc9eef1dc4265e8cacde8cdf
Author: Patrick Schleizer <[email protected]>
Date: Thu Jan 30 01:22:06 2020 -0500
readme
commit c1a0da60beacd027c1c7c94ae44a9d7b1ab708b9
Author: Patrick Schleizer <[email protected]>
Date: Thu Jan 30 00:46:48 2020 -0500
set kernel boot parameter `l1tf=full,force` and `nosmt=force`
https://forums.whonix.org/t/should-all-kernel-patches-for-cpu-bugs-be-unconditionally-enabled-vs-performance-vs-applicability/7647/17
commit efc40da4fb1fffcc760685cda0e49dc04da4c5fe
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 12:02:27 2020 -0500
bumped changelog version
commit 07dcb32fc28abf33eaf0425c67cc5cf9ee1f5a5b
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 11:55:38 2020 -0500
readme
commit f4c54881ac21ed095f54a59f9c0baf582ef76d9b
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 04:49:19 2020 -0500
description
commit 25317f23e3a80fdd9f6965990cd397ddcab11a4b
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 04:41:16 2020 -0500
bumped changelog version
commit be79f0688a47dca129ac61dd78b18a2638e8650c
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 04:40:20 2020 -0500
readme
commit c0d3726b002d136e602c6bdaf07c5d94c5591ee4
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 04:40:03 2020 -0500
comment
commit a37da1c96880b14a8271712801e6da3d3ea766eb
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 04:39:06 2020 -0500
add digits to drop-in file names
commit 2ab940c60311ae38079d2ceb09e04eedac2aad90
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 04:34:18 2020 -0500
bumped changelog version
commit bac6cd601baaca7453c55719e9dfa84d5109135d
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 04:33:54 2020 -0500
readme
commit 3a4d283169b381bdc93c4ff5ce7b08c11a0830b3
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 04:33:30 2020 -0500
description
commit e0aa67677d3561cae6544c24e12021dd04f26133
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 04:30:36 2020 -0500
merge the many modprobe.d config files into 1
and use a name starting with double digits
to make it easier to disable settings using a lexically higher config file
commit 6a4c493213929b354a3c8d2acf2325473ae63cfd
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 04:26:36 2020 -0500
merge the many sysctl config files into 1
and use a name starting with double digits
to make it easier to disable settings using a lexically higher config file
commit f653b94e7747436323e2083d416ab86560e3cd71
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 03:49:02 2020 -0500
bumped changelog version
commit ca057713e2e1f3c4a47216aadb51ba0ca012e39e
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 03:39:04 2020 -0500
readme
commit 8616728ce0a6e5eaa799949abb5bfccd0a7effa7
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 03:35:15 2020 -0500
remove duplicate
commit d4a37b6df2a2de4822e3e4bac93ca3e10712af7c
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 24 03:18:17 2020 -0500
remove-system.map: source /usr/lib/helper-scripts/pre.bsh
commit 3b283ec00f03b580d2f8b76f95449240a163dd48
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 22 07:10:47 2020 -0500
bumped changelog version
commit 531f17cb68b331beb19a6e6c8b76575ebe38f95e
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 22 07:08:08 2020 -0500
add update initramfs trigger
https://github.com/Whonix/security-misc/pull/53
commit df0b2afda1e1d5a3fddfd8c48b62a5de8295d687
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 21 10:12:32 2020 -0500
bumped changelog version
commit 18041efa2f704d2a177b033ff8008aacdb7dde3f
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 21 10:01:17 2020 -0500
fix pam tally2 check when read-only disk boot without ro-mode-init or grub-live
commit 627b95e0b363e2e46a5de8a7aa5065bc66242293
Author: Patrick Schleizer <[email protected]>
Date: Mon Jan 20 08:51:25 2020 -0500
bumped changelog version
commit fbe9b60d95d43452bf661461197efced431806a5
Author: Patrick Schleizer <[email protected]>
Date: Mon Jan 20 08:49:02 2020 -0500
fix Whonix / Kicksecure
/var/lib/dpkg/tmp.ci/preinst: ERROR: No user is a member of group 'console'. Installation aborted.
/var/lib/dpkg/tmp.ci/preinst: ERROR: You probably want to run:
sudo adduser user console
commit 960e1ff6e82f8593c2d242a6a0f1e1cf5805c85b
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 17 03:32:57 2020 -0500
bumped changelog version
commit 130434186811930d40407115af99116d4982da49
Author: Patrick Schleizer <[email protected]>
Date: Fri Jan 17 03:10:56 2020 -0500
readme
commit 6f8d89c6c5609ed83d9dcd174375cb1ccfca91d8
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 15:54:06 2020 -0500
error handling
commit 7211f6e0199d2ccb50437c7a5b0842050590b5dc
Merge: e110ea0 f6cc76a
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 15:53:36 2020 -0500
Merge remote-tracking branch 'origin/master'
commit f6cc76acd729428f83d3497a2e83bfc4b14f1ff8
Merge: e110ea0 1df48a2
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 20:52:33 2020 +0000
Merge pull request #55 from madaidan/sysctl.conf
Process sysctl.conf in initramfs
commit 1df48a226d83b98dadc8bfb8dbc479dd656e2313
Author: madaidan <[email protected]>
Date: Wed Jan 15 20:30:17 2020 +0000
Update control
commit f7fde60b67a7ef44658cde3b835565407aafd133
Author: madaidan <[email protected]>
Date: Wed Jan 15 20:28:32 2020 +0000
Process sysctl.conf too
commit e110ea0b84329dfbe0175298b21e7732f7105436
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 11:37:52 2020 -0500
bumped changelog version
commit 0f17596aacb86afb7abcdd4781a9995dde23d3bb
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 11:35:41 2020 -0500
readme
commit 0618b5346493723865cc6f2a632822c8b6fa690a
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 11:35:07 2020 -0500
fix lintian warning
commit 47ce3bec75f9aeb808993a70579ba93d2527a371
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 11:05:54 2020 -0500
bumped changelog version
commit 73e830d0ac1ece338b0e80ca1a020d84a15d1774
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 10:08:57 2020 -0500
readme
commit 8ab4623f8e81ad1b67858b458f2ae4085e7c8e65
Merge: 8015954 087465a
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 06:06:39 2020 -0500
Merge remote-tracking branch 'origin/master'
commit 087465a0cdecc4765f7b659256cdd5e8cdef73ab
Merge: 8015954 528c5fc
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 11:02:30 2020 +0000
Merge pull request #53 from madaidan/sysctl-initramfs
Set sysctl values in initramfs
commit 528c5fc4c41026396a63ac91af7c156dd0d4f191
Merge: 9dc43ea 8015954
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 11:02:03 2020 +0000
Merge branch 'master' into sysctl-initramfs
commit 80159545a580830565ec01a507915add9c44838a
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 15 02:42:10 2020 -0500
fix xfce4-power-manager xfpm-power-backlight-helper pkexec lxsudo popup
https://forums.whonix.org/t/xfce4-power-manager-xfpm-power-backlight-helper-pkexec-lxsudo-popup/8764
do show lxqt-sudo password prompt if there is a sudoers exceptoin
improved pkexec wrapper logging
commit d90ca4b1ad18289d6bcfcef51cfb032a0b4423eb
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 15:12:13 2020 -0500
refactoring
commit 082f04f2d4101828455a4a9b2852376a72ced6ce
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 15:04:58 2020 -0500
add logging to pkexec wrapper
commit 1059ccf2254d0aac40d2c14680fea2a4012a2d66
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:28:28 2020 -0500
bumped changelog version
commit 660837dc380440f6b00d3baf9395222376163b3b
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:25:32 2020 -0500
fix case when user "user" does not exists
commit 18c726c3eebc93f69062f1e4c1d3c7ab394985c3
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:23:02 2020 -0500
comment
commit b8652681e741236af2e20876d7103b2dfb0ae9bf
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:21:47 2020 -0500
fix legacy
commit cc21f912a372faef8322801e9a48882f29159c2d
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:20:36 2020 -0500
bumped changelog version
commit 2078cd237f2aaad8d68c1c5eab3f9942460ecd3c
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:18:30 2020 -0500
readme
commit c377c5ff83437a5447ecc9c873150421f4f1e691
Merge: 8341242 539f24b
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 09:01:38 2020 -0500
Merge remote-tracking branch 'origin/master'
commit 539f24b65ee7739487d8038fcb1fdfb1ed62ab22
Merge: 8341242 0953bbe
Author: Patrick Schleizer <[email protected]>
Date: Tue Jan 14 14:01:17 2020 +0000
Merge pull request #54 from madaidan/panic_on_oops
Document panic_on_oops
commit 0953bbe1d7f3e789aef2218a65c14c586dab4bcb
Author: madaidan <[email protected]>
Date: Mon Jan 13 21:05:35 2020 +0000
Update control
commit 9dc43eae38b55951cae2a9bf93114bcf742f8c8b
Author: madaidan <>
Date: Sun Jan 12 21:42:07 2020 +0000
Description
commit 8c4e0ff1c4d6191dbb40b28cfc23a8185cc0cbdb
Author: madaidan <[email protected]>
Date: Sun Jan 12 21:37:37 2020 +0000
Set sysctl values in initramfs
commit 8341242abc342d9cbd82afe12f512daf73a9e59a
Author: Patrick Schleizer <[email protected]>
Date: Sat Jan 11 15:19:29 2020 -0500
bumped changelog version
commit 130a4cf6d433f4d862e10e31abbc2b1f3b1614d2
Author: Patrick Schleizer <[email protected]>
Date: Sat Jan 11 15:17:06 2020 -0500
readme
commit 61a2d390a7d6195d556898db8afa57822a9bc76a
Author: Patrick Schleizer <[email protected]>
Date: Sat Jan 11 15:15:12 2020 -0500
lintian
commit 3fae8e771ffbdd3023921b296e46cf982034d2ac
Merge: 13a1e13 e9f4dbd
Author: Patrick Schleizer <[email protected]>
Date: Sat Jan 11 15:14:43 2020 -0500
Merge remote-tracking branch 'origin/master'
commit e9f4dbdda579db83f330054253100bc7c5d1e2be
Merge: 13a1e13 6088444
Author: Patrick Schleizer <[email protected]>
Date: Sat Jan 11 20:14:10 2020 +0000
Merge pull request #52 from madaidan/vivid
Blacklist the vivid kernel module
commit 6088444c371f021ca23daa3a0ab1ee431d429a61
Author: madaidan <[email protected]>
Date: Sat Jan 11 18:38:17 2020 +0000
Update control
commit a662a76a52970530a4a3c3d6a284ce9400dc74c6
Author: madaidan <[email protected]>
Date: Sat Jan 11 18:37:00 2020 +0000
Blacklist vivid
commit 13a1e1321e05965ad9449fafa4406c4d3b781dcf
Author: Patrick Schleizer <[email protected]>
Date: Wed Jan 1 05:59:59 2020 -0500
bumped changelog version
commit 5031e7cc4b8bfc4037ba6ea029e20637090ccacb
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 31 08:18:38 2019 -0500
better output if trying to login with non-existing user
commit b2bdeb90957da4ebe38e7f12fba0330b89e0983d
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 31 06:08:32 2019 -0500
bumped changelog version
commit 2a3aae62b1cf97313b925fac94261e28af7ea3d1
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 31 06:06:52 2019 -0500
fix
commit 427deec3f50664f2fbb244b6cf060bb5b9e821b6
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 31 06:03:48 2019 -0500
bumped changelog version
commit e89552c9846f85b4bbf73595080d71dcd873fe29
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 31 05:55:44 2019 -0500
add user "user" to group "console" in Whonix and Kicksecure
enable Console Lockdown in Whonix and Kicksecure
commit b5a2d1dc581b53974aaa148f6d8f3054c9d1c5fe
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 31 02:54:58 2019 -0500
bumped changelog version
commit 20697db3ee5d227176c4d31e6c96454a64f47797
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 31 02:53:02 2019 -0500
improve console lockdown info output
commit 788914de95ee9299d685e8b65466feee1085cf18
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 31 02:46:32 2019 -0500
group ssh check was removed
https://forums.whonix.org/t/etc-security-hardening-console-lockdown-pam-access-access-conf/8592/27
commit 06ed728d791abe0ad3c93091fd8ebc088f73c4ef
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 30 06:42:14 2019 -0500
bumped changelog version
commit f3ff32ddbb8a7cf7555b9f1b2154e83154532a3d
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 30 06:39:24 2019 -0500
Protect /bin/mount from 'chmod -x'.
/bin/mount exactwhitelist
/usr/bin/mount exactwhitelist
Remove SUID from 'mount' but keep executable.
/bin/mount 745 root root
/usr/bin/mount 745 root root
https://forums.whonix.org/t/disable-suid-binaries/7706/61
commit e4e9c4e3b09138af25e94a6db81b0f759ddb4d1b
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 30 05:59:43 2019 -0500
bumped changelog version
commit 9c0d6b605707dbcb7db9cd227257a5dcd612f784
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 05:09:07 2019 -0500
copyright
commit edc08988f26532daf90bc4a4f007aef53e62eeaf
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 05:08:53 2019 -0500
copyright
commit 9156d3584cd7ba9064d5af54afd95b6d8e73907b
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 04:59:05 2019 -0500
Description
commit 3ea946b365d8b05cabce63f4d26b3153559aa465
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 04:56:51 2019 -0500
RemainAfterExit=yes
commit 2787ae976580d20ea4da5213c7f624f984510934
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 04:56:35 2019 -0500
copyright
commit 6d56eb9ef0e2cfbba46df2294deb9c8e6b9aa2b7
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 04:56:18 2019 -0500
minor
commit 0e14706f32728123f1d345b73266934fe454a989
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 04:45:26 2019 -0500
copyright
commit 1a0f7a77335940a11e33ca519d8f64429b8ee966
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 04:43:32 2019 -0500
debugging
commit 5271892cb1e4646b79388d064227d4662b682583
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 04:42:54 2019 -0500
debugging
commit 683028049c46516ba105b1b73364960b3b87efd6
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 04:41:23 2019 -0500
debugging
commit e3e1ff2a310c46fab67309edd88e73096843edcb
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 04:35:46 2019 -0500
exit with error if a config line cannot be processed rather than skipping
https://forums.whonix.org/t/disable-suid-binaries/7706/59
commit d5c99f3a60372a00ded4b1b4340775aab1421d31
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 04:27:21 2019 -0500
output
commit e5623fcd2b32b58e72c2ef80955072f013672e0d
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 29 04:21:52 2019 -0500
comment
commit d7f58db52c926c11157671c4555ca97f02929a76
Author: Patrick Schleizer <[email protected]>
Date: Fri Dec 27 05:30:12 2019 -0500
bumped changelog version
commit 674840e6f9fb362dc713da3edde07132b5ae17d4
Author: Patrick Schleizer <[email protected]>
Date: Thu Dec 26 05:44:35 2019 -0500
/fusermount matchwhitelist
unbreak AppImages such as electrum Bitcoin wallet
https://forums.whonix.org/t/disable-suid-binaries/7706/57
commit 507a30d6e39f17fcb09b92033fe1d831e7d4baf4
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 24 18:35:49 2019 -0500
bumped changelog version
commit 04f438f75d4566822026373e78988e9d4e42b8b5
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 24 18:09:37 2019 -0500
comment
commit 9da0e428ed4635fb5ca98b2d72b56b553404a742
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 24 17:54:31 2019 -0500
debugging
commit e18ec533c3ebb382f974d30db3cd1f5eace648c2
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 24 17:54:02 2019 -0500
comment
commit 0326cd5ee9371213420d2afdcbfb0a05d9a808e6
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 24 08:07:55 2019 -0500
bumped changelog version
commit ede536913daa0c7ddfe55e20c93d7b752daa5de3
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 24 06:00:41 2019 -0500
no longer hardcode amd64
commit d03a3d9ac03bc29ba349107855936dd194e12271
Merge: 9d77d88 27a42a9
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 24 05:57:24 2019 -0500
Merge remote-tracking branch 'origin/master'
commit 27a42a9da82bc1f22135ffa509925f63177f25d9
Merge: ac49c55 79241c5
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 24 10:55:11 2019 +0000
Merge pull request #50 from madaidan/modules
Make /lib/modules unreadable
commit ac49c55d1fafff5f36bd7c595f50db295ff616a2
Merge: 0c3d4ad 98e88d1
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 24 10:55:03 2019 +0000
Merge pull request #49 from madaidan/kver
Detect kernel upgrades
commit 0c3d4ad255de75b57a2e316bf8a7fd77a2fc0d4d
Merge: 9d77d88 d1a0650
Author: Patrick Schleizer <[email protected]>
Date: Tue Dec 24 10:54:23 2019 +0000
Merge pull request #48 from madaidan/kernel-hardening
Use only one slub_debug parameter
commit 79241c5d09c4a7123cf90b45289b53d893135efb
Author: madaidan <[email protected]>
Date: Mon Dec 23 20:28:29 2019 +0000
Make /lib/modules unreadable
commit 98e88d1456ca0e8fa23809115c51c380a4bb2d3b
Author: madaidan <[email protected]>
Date: Mon Dec 23 19:57:43 2019 +0000
Detect kernel upgrades
commit d1a0650fd944973ab614c1da06f8e555b31b73ae
Author: madaidan <[email protected]>
Date: Mon Dec 23 19:44:52 2019 +0000
Use only one slub_debug parameter
commit 9d77d88a4dfd0f42a2a671bbec49f4ebd90af882
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 09:39:50 2019 -0500
comments
commit 7a80837b4f0a7201f3e092ad9b99b4cddb6043b3
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 08:48:04 2019 -0500
bumped changelog version
commit 617c0a0e15f1c113b6e7fd748bb75978e4f23fcd
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 07:21:26 2019 -0500
disable remount-secure.service - Disable for now until development finished / tested.
commit 3e131174d5919303462295cb0852a9254885ae7c
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 05:00:35 2019 -0500
comments
commit bef41a38c26548d50101f7ea636316e1e2107a55
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 03:58:00 2019 -0500
bumped changelog version
commit 046ceeae4df3b45916f35b0789af341c4f3d911a
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 03:57:36 2019 -0500
readme
commit 9f072ce4f99467f82986be348c9cedc2eb7f017d
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 03:46:02 2019 -0500
comment
commit 26fe9394fff2eb5be2f19272ea76ed187a8237e5
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 03:41:54 2019 -0500
disable lockdown for now due to module loading
commit 9ec5b0ee82263e1afb38c44348e69437ddc5c9c2
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 03:38:49 2019 -0500
description: lockdown not enabled yet
commit b05669accfe6fac8070003bbd57939ca2c621445
Merge: 11b4192 1ff51ee
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 03:38:04 2019 -0500
Merge branch 'madaidan-kernel-hardening'
commit 1ff51ee061dcdb1a898ebb68c0267ce926e0fca0
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 03:37:28 2019 -0500
merge
commit 535c258b834028e5638fd2b37b1a6f352e2b4558
Author: madaidan <[email protected]>
Date: Wed Dec 18 20:43:01 2019 +0000
More kernel hardening
commit 11b4192fbdbc02af97e7dc32677bdb3a549b0000
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 03:28:42 2019 -0500
comments
commit 42ff53e9ad26190dcbff154f6cfd039e3f6bdf83
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 02:42:07 2019 -0500
bumped changelog version
commit 2152fa2d61fa72935b70e60b98ccbe2e1b31db43
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 02:38:53 2019 -0500
comment
commit f8f2e6c7041d98572452be2e53094d0c539b1616
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 02:35:13 2019 -0500
fix disablewhitelist feature
commit 47ddcad0c0af27093f61cf77008224bf66572532
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 02:29:47 2019 -0500
rename keyword whitelist to exactwhitelist
add new keyword disablewhitelist
refactoring
commit 175d1c284552a08881286e8c3ca5d8eb9b97a144
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 02:13:13 2019 -0500
bumped changelog version
commit 0409aac3aeb7acc273e19b16e78409994c731f2a
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 02:09:04 2019 -0500
readme
commit 1ff56625a170c392f6099b41f371c56032362ea0
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 01:42:03 2019 -0500
polkit-agent-helper-1 matchwhitelist to match both
- /usr/lib/policykit-1/polkit-agent-helper-1 matchwhitelist
- /lib/policykit-1/polkit-agent-helper-1
commit d484b299ea1a93a401d00a212d675b5837b8aaa9
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 01:38:31 2019 -0500
matchwhitelist /qubes/qfile-unpacker to match both
- /usr/lib/qubes/qfile-unpacker whitelist
- /lib/qubes/qfile-unpacker
commit 34bf2457136db227cc27a5d0fe9282f09780a310
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 01:35:45 2019 -0500
output
commit ba30e45d15ec53b2d0a67ce96f5132d3f59bf870
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 01:32:42 2019 -0500
output
commit ee9c5742da99673785068b0393e3587a77c99a31
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 01:29:48 2019 -0500
output
commit 6d05359abcf460cbec266401530a9ab1aaaaf47f
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 01:21:52 2019 -0500
output
commit a1e78e8515a87ebc8fc2211b3e1e91824fd3865a
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 01:20:56 2019 -0500
fix needlessly re-adding entries
commit 906b3d32e769bbd30ed5698268899a7d2ec71d95
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 01:09:57 2019 -0500
output
commit 4f76867da6ce5710cf486175cd84adcd72640049
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 01:08:02 2019 -0500
lower debugging
commit dc6e5d8508a09bd7f2b9bfed02bc502797c11361
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 01:06:38 2019 -0500
fix
commit 87b999f92aab4f4176f366308c27c4fe5471580c
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 00:59:43 2019 -0500
refactoring
commit 065ff4bd058ab26df3d3af1022da9d6a7405ab61
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 00:59:24 2019 -0500
sanity_tests
commit fef1469fe62bf923ba89077934c8b0e5d8cd0258
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 00:51:14 2019 -0500
exit non-zero if capability removal failed
commit 3670fcf48baecffe098c96eb67cbd601bc3e0069
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 00:49:33 2019 -0500
depend on libcap2-bin for setcap / getcap / capsh
commit 17a8c294702acb30c397abc984d69c356cec2cd7
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 00:47:49 2019 -0500
fix capability removal error handling
https://forums.whonix.org/t/disable-suid-binaries/7706/45
commit b631e2ecd8ae0e08850edd81bf64b02666fb6234
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 00:36:41 2019 -0500
refactoring
commit 7aea304549cea2c885c2d813c7a15f617f4ebf2a
Author: Patrick Schleizer <[email protected]>
Date: Mon Dec 23 00:26:15 2019 -0500
comment
commit f4b1df02ee66309d12724cf7124b14180c855f14
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 22 19:42:40 2019 -0500
Remove suid / gid and execute permission for 'group' and 'others'.
Similar to: chmod og-ugx /path/to/filename
Removing execution permission is useful to make binaries such as 'su' fail closed rather
than fail open if suid was removed from these.
Do not remove read access since no security benefit and easier to manually undo for users.
chmod 744
commit 58a4e0bc7d1b87d4d169f31dc5935c75e929c0b4
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 22 19:12:10 2019 -0500
dbus-daemon-launch-helper matchwhitelist
commit 15e3a2832da603f5caa9aadc6d68aaf503f013c9
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 22 18:57:23 2019 -0500
comment
commit 6eb8fd257aecd84686b4d7a9824a98bace9a705e
Author: Patrick Schleizer <[email protected]>
Date: Sun Dec 22 18:56:36 2019 -0500
suid utempter/utempter matchwhitelist
to cover both:
/usr/lib/x86_64-linux-gnu/utempter/utempter