Kernel Hardening
[Prev Page][Next Page]
- Re: [PATCH 00/22] add support for Clang LTO, (continued)
- [PATCH v2 00/28] Add support for Clang LTO, Sami Tolvanen
- [PATCH v2 01/28] x86/boot/compressed: Disable relocation relaxation, Sami Tolvanen
- [PATCH v2 02/28] x86/asm: Replace __force_order with memory clobber, Sami Tolvanen
- [PATCH v2 03/28] lib/string.c: implement stpcpy, Sami Tolvanen
- [PATCH v2 04/28] RAS/CEC: Fix cec_init() prototype, Sami Tolvanen
- [PATCH v2 05/28] objtool: Add a pass for generating __mcount_loc, Sami Tolvanen
- [PATCH v2 06/28] objtool: Don't autodetect vmlinux.o, Sami Tolvanen
- [PATCH v2 07/28] kbuild: add support for objtool mcount, Sami Tolvanen
- [PATCH v2 08/28] x86, build: use objtool mcount, Sami Tolvanen
- [PATCH v2 09/28] kbuild: add support for Clang LTO, Sami Tolvanen
- [PATCH v2 10/28] kbuild: lto: fix module versioning, Sami Tolvanen
- [PATCH v2 11/28] kbuild: lto: postpone objtool, Sami Tolvanen
- [PATCH v2 12/28] kbuild: lto: limit inlining, Sami Tolvanen
- [PATCH v2 13/28] kbuild: lto: merge module sections, Sami Tolvanen
- [PATCH v2 14/28] kbuild: lto: remove duplicate dependencies from .mod files, Sami Tolvanen
- [PATCH v2 15/28] init: lto: ensure initcall ordering, Sami Tolvanen
- [PATCH v2 16/28] init: lto: fix PREL32 relocations, Sami Tolvanen
- [PATCH v2 17/28] PCI: Fix PREL32 relocations for LTO, Sami Tolvanen
- [PATCH v2 18/28] modpost: lto: strip .lto from module names, Sami Tolvanen
- [PATCH v2 19/28] scripts/mod: disable LTO for empty.c, Sami Tolvanen
- [PATCH v2 20/28] efi/libstub: disable LTO, Sami Tolvanen
- [PATCH v2 21/28] drivers/misc/lkdtm: disable LTO for rodata.o, Sami Tolvanen
- [PATCH v2 22/28] arm64: export CC_USING_PATCHABLE_FUNCTION_ENTRY, Sami Tolvanen
- [PATCH v2 23/28] arm64: vdso: disable LTO, Sami Tolvanen
- [PATCH v2 24/28] KVM: arm64: disable LTO for the nVHE directory, Sami Tolvanen
- [PATCH v2 25/28] arm64: allow LTO_CLANG and THINLTO to be selected, Sami Tolvanen
- [PATCH v2 26/28] x86, vdso: disable LTO only for vDSO, Sami Tolvanen
- [PATCH v2 27/28] x86, relocs: Ignore L4_PAGE_OFFSET relocations, Sami Tolvanen
- [PATCH v2 28/28] x86, build: allow LTO_CLANG and THINLTO to be selected, Sami Tolvanen
- Re: [PATCH v2 00/28] Add support for Clang LTO, Kees Cook
- Re: [PATCH v2 00/28] Add support for Clang LTO, Kees Cook
- Re: [PATCH v2 00/28] Add support for Clang LTO, Sedat Dilek
- Re: [PATCH v2 00/28] Add support for Clang LTO, peterz
- Re: [PATCH v2 00/28] Add support for Clang LTO, Masahiro Yamada
- [PATCH v2 0/5] Improvements of the stackleak gcc plugin,
Alexander Popov
- [PATCH v3 00/10] Function Granular KASLR,
Kristen Carlson Accardi
- [PATCH v3 01/10] objtool: Do not assume order of parent/child functions, Kristen Carlson Accardi
- [PATCH v3 02/10] x86: tools/relocs: Support >64K section headers, Kristen Carlson Accardi
- [PATCH v3 03/10] x86/boot: Allow a "silent" kaslr random byte fetch, Kristen Carlson Accardi
- [PATCH v3 04/10] x86: Makefile: Add build and config option for CONFIG_FG_KASLR, Kristen Carlson Accardi
- [PATCH v3 05/10] x86: Make sure _etext includes function sections, Kristen Carlson Accardi
- [PATCH v3 06/10] x86/tools: Add relative relocs for randomized functions, Kristen Carlson Accardi
- [PATCH v3 07/10] x86/boot/compressed: change definition of STATIC, Kristen Carlson Accardi
- [PATCH v3 08/10] x86: Add support for function granular KASLR, Kristen Carlson Accardi
- [PATCH v3 09/10] kallsyms: Hide layout, Kristen Carlson Accardi
- [PATCH v3 10/10] module: Reorder functions, Kristen Carlson Accardi
- Re: [PATCH v3 00/10] Function Granular KASLR, Kees Cook
- [RFC PATCH v2] arm64/acpi: disallow AML memory opregions to access kernel memory,
Ard Biesheuvel
- Kernel hardening project suggestion: Normalizing ->ctor slabs and TYPESAFE_BY_RCU slabs,
Jann Horn
- [PATCH v4 0/5] Optionally randomize kernel stack offset each syscall,
Kees Cook
- [RFC PATCH] arm64/acpi: disallow AML memory opregions to access kernel memory,
Ard Biesheuvel
- [kvm-unit-tests PATCH v2] x86: Add control register pinning tests, John Andersen
- [kvm-unit-tests RESEND PATCH] x86: Add control register pinning tests, John Andersen
- [kvm-unit-tests PATCH] x86: Add control register pinning tests,
John Andersen
- [PATCH] tracing: Use linker magic instead of recasting ftrace_ops_list_func(),
Steven Rostedt
- [PATCH 0/4] Paravirtualized Control Register pinning,
John Andersen
- lockdown bypass on mainline kernel for loading unsigned modules,
Jason A. Donenfeld
- Re: [RFC] io_uring: add restrictions to support untrusted applications and guests,
Jann Horn
- [PATCH] ata: Eliminate usage of uninitialized_var() macro, Jason Yan
- [PATCH] f2fs: Eliminate usage of uninitialized_var() macro,
Jason Yan
- [PATCH] erofs: Eliminate usage of uninitialized_var() macro,
Jason Yan
- [PATCH] ACPI: Eliminate usage of uninitialized_var() macro,
Jason Yan
- [PATCH] block: Eliminate usage of uninitialized_var() macro, Jason Yan
- [PATCH] kernel/trace: Remove function callback casts,
Oscar Carter
- [PATCH AUTOSEL 5.6 103/606] gcc-common.h: Update for GCC 10, Sasha Levin
- [PATCH 0/5] Improvements of the stackleak gcc plugin,
Alexander Popov
- [PATCH 0/5] Use per-CPU temporary mappings for patching,
Christopher M. Riedl
- [PATCH v5 0/3] drivers/acpi: Remove function callback casts,
Oscar Carter
- [PATCH v4 0/3] drivers/acpi: Remove function callback casts,
Oscar Carter
- [PATCH v3] firewire: Remove function callback casts,
Oscar Carter
- [PATCH v3 0/2] drivers/irqchip: Remove function callback casts,
Oscar Carter
- [PATCH v18 00/12] Landlock LSM,
Mickaël Salaün
- [PATCH v18 01/12] landlock: Add object management, Mickaël Salaün
- [PATCH v18 02/12] landlock: Add ruleset and domain management, Mickaël Salaün
- [PATCH v18 03/12] landlock: Set up the security framework and manage credentials, Mickaël Salaün
- [PATCH v18 04/12] landlock: Add ptrace restrictions, Mickaël Salaün
- [PATCH v18 05/12] LSM: Infrastructure management of the superblock, Mickaël Salaün
- [PATCH v18 06/12] fs,security: Add sb_delete hook, Mickaël Salaün
- [PATCH v18 07/12] landlock: Support filesystem access-control, Mickaël Salaün
- [PATCH v18 08/12] landlock: Add syscall implementation, Mickaël Salaün
- [PATCH v18 09/12] arch: Wire up landlock() syscall, Mickaël Salaün
- [PATCH v18 10/12] selftests/landlock: Add initial tests, Mickaël Salaün
- [PATCH v18 11/12] samples/landlock: Add a sandbox manager example, Mickaël Salaün
- [PATCH v18 12/12] landlock: Add user and kernel documentation, Mickaël Salaün
- [PATCH v2] drivers/irqchip: Remove function callback casts,
Oscar Carter
- [PATCH v2] firewire-core: remove cast of function callback,
Takashi Sakamoto
- [PATCH] staging/rtl8192e: Remove function callback casts, Oscar Carter
- [PATCH] drivers/irqchip: Remove function callback casts,
Oscar Carter
- [PATCH v2 0/9] Function Granular KASLR,
Kristen Carlson Accardi
- [PATCH v2 1/9] objtool: Do not assume order of parent/child functions, Kristen Carlson Accardi
- [PATCH v2 2/9] x86: tools/relocs: Support >64K section headers, Kristen Carlson Accardi
- [PATCH v2 3/9] x86/boot: Allow a "silent" kaslr random byte fetch, Kristen Carlson Accardi
- [PATCH v2 4/9] x86: Makefile: Add build and config option for CONFIG_FG_KASLR, Kristen Carlson Accardi
- [PATCH v2 5/9] x86: Make sure _etext includes function sections, Kristen Carlson Accardi
- [PATCH v2 6/9] x86/tools: Add relative relocs for randomized functions, Kristen Carlson Accardi
- [PATCH v2 7/9] x86: Add support for function granular KASLR, Kristen Carlson Accardi
- [PATCH v2 8/9] kallsyms: Hide layout, Kristen Carlson Accardi
- [PATCH v2 9/9] module: Reorder functions, Kristen Carlson Accardi
- Re: [PATCH v2 0/9] Function Granular KASLR, Kees Cook
- Re: [PATCH v2 0/9] Function Granular KASLR, Thomas Gleixner
- [PATCH 0/2] firewire: obsolete cast of function callback toward CFI,
Takashi Sakamoto
- [PATCH v2] firewire: Remove function callback casts,
Oscar Carter
- [PATCH] firewire: Remove function callback casts,
Oscar Carter
- [PATCH AUTOSEL 4.9 02/27] gcc-common.h: Update for GCC 10, Sasha Levin
- [PATCH AUTOSEL 4.14 02/39] gcc-common.h: Update for GCC 10, Sasha Levin
- [PATCH AUTOSEL 4.19 02/31] gcc-common.h: Update for GCC 10, Sasha Levin
- [PATCH AUTOSEL 5.4 04/49] gcc-common.h: Update for GCC 10, Sasha Levin
- [PATCH AUTOSEL 5.6 04/62] gcc-common.h: Update for GCC 10, Sasha Levin
- [PATCH v17 00/10] Landlock LSM,
Mickaël Salaün
- [PATCH v17 01/10] landlock: Add object management, Mickaël Salaün
- [PATCH v17 02/10] landlock: Add ruleset and domain management, Mickaël Salaün
- [PATCH v17 03/10] landlock: Set up the security framework and manage credentials, Mickaël Salaün
- [PATCH v17 04/10] landlock: Add ptrace restrictions, Mickaël Salaün
- [PATCH v17 05/10] fs,landlock: Support filesystem access-control, Mickaël Salaün
- [PATCH v17 06/10] landlock: Add syscall implementation, Mickaël Salaün
- [PATCH v17 07/10] arch: Wire up landlock() syscall, Mickaël Salaün
- [PATCH v17 08/10] selftests/landlock: Add initial tests, Mickaël Salaün
- [PATCH v17 09/10] samples/landlock: Add a sandbox manager example, Mickaël Salaün
- [PATCH v17 10/10] landlock: Add user and kernel documentation, Mickaël Salaün
- Re: [PATCH v17 00/10] Landlock LSM, Mickaël Salaün
- Open source a new kernel harden project,
wzt wzt
- [PATCH] gcc-plugins: remove always false $(if ...) in Makefile,
Masahiro Yamada
- Get involved in the KSPP,
Oscar Carter
- FYI: NGI POINTER OSS Funding, Dmitry Vyukov
- [PATCH v5 0/6] Add support for O_MAYEXEC,
Mickaël Salaün
- [PATCH] security/keys: rewrite big_key crypto to use Zinc,
Jason A. Donenfeld
- [PATCH v4 0/5] Add support for O_MAYEXEC,
Mickaël Salaün
- [RFC PATCH v2 0/5] Use per-CPU temporary mappings for patching,
Christopher M. Riedl
- [PATCH v3 0/5] Add support for RESOLVE_MAYEXEC,
Mickaël Salaün
- Re: [PATCH] nsproxy: attach to namespaces via pidfds,
Jann Horn
- [PATCH v13 0/8] proc: modernize proc to support multiple private instances,
Alexey Gladkov
- Re: gcc extended format checking plugin, Masahiro Yamada
- [PATCH v12 0/7] proc: modernize proc to support multiple private instances,
Alexey Gladkov
- [PATCH] gcc-plugins: latent_entropy: remove unneeded semicolon, Jason Yan
- [PATCH] gcc-plugins: structleak: remove unneeded variable 'ret', Jason Yan
- [PATCH v16 00/10] Landlock LSM,
Mickaël Salaün
- [PATCH v16 01/10] landlock: Add object management, Mickaël Salaün
- [PATCH v16 02/10] landlock: Add ruleset and domain management, Mickaël Salaün
- [PATCH v16 03/10] landlock: Set up the security framework and manage credentials, Mickaël Salaün
- [PATCH v16 04/10] landlock: Add ptrace restrictions, Mickaël Salaün
- [PATCH v16 05/10] fs,landlock: Support filesystem access-control, Mickaël Salaün
- [PATCH v16 07/10] arch: Wire up landlock() syscall, Mickaël Salaün
- [PATCH v16 06/10] landlock: Add syscall implementation, Mickaël Salaün
- [PATCH v16 08/10] selftests/landlock: Add initial tests, Mickaël Salaün
- [PATCH v16 09/10] samples/landlock: Add a sandbox manager example, Mickaël Salaün
- [PATCH v16 10/10] landlock: Add user and kernel documentation, Mickaël Salaün
- [PATCH 0/9] Function Granular Kernel Address Space Layout Randomization,
Kristen Carlson Accardi
- [PATCH 1/9] objtool: do not assume order of parent/child functions, Kristen Carlson Accardi
- [PATCH 2/9] x86: tools/relocs: Support >64K section headers, Kristen Carlson Accardi
- [PATCH 3/9] x86/boot: Allow a "silent" kaslr random byte fetch, Kristen Carlson Accardi
- [PATCH 4/9] x86: Makefile: Add build and config option for CONFIG_FG_KASLR, Kristen Carlson Accardi
- [PATCH 5/9] x86: make sure _etext includes function sections, Kristen Carlson Accardi
- [PATCH 6/9] x86/tools: Adding relative relocs for randomized functions, Kristen Carlson Accardi
- [PATCH 7/9] x86: Add support for function granular KASLR, Kristen Carlson Accardi
- [PATCH 8/9] kallsyms: hide layout, Kristen Carlson Accardi
- [PATCH 9/9] module: Reorder functions, Kristen Carlson Accardi
- Re: [PATCH 0/9] Function Granular Kernel Address Space Layout Randomization, Kees Cook
- [PATCH v3 0/5] hardening : prevent write to proces's read-only pages,
Lev Olshvang
- [PATCH v1 0/1] hardening : prevent write to proces's read-only pages, Lev Olshvang
- [PATCH v1] prevent write to proces's read-only pages, Lev Olshvang
- [PATCH RESEND v11 0/8] proc: modernize proc to support multiple private instances,
Alexey Gladkov
- [PATCH RESEND v11 1/8] proc: rename struct proc_fs_info to proc_fs_opts, Alexey Gladkov
- [PATCH RESEND v11 3/8] proc: move hide_pid, pid_gid from pid_namespace to proc_fs_info, Alexey Gladkov
- [PATCH RESEND v11 2/8] proc: allow to mount many instances of proc in one pid namespace, Alexey Gladkov
- [PATCH RESEND v11 4/8] proc: instantiate only pids that we can ptrace on 'hidepid=4' mount option, Alexey Gladkov
- [PATCH RESEND v11 5/8] proc: add option to mount only a pids subset, Alexey Gladkov
- [PATCH RESEND v11 6/8] docs: proc: add documentation for "hidepid=4" and "subset=pid" options and new mount behavior, Alexey Gladkov
- [PATCH RESEND v11 8/8] proc: use named enums for better readability, Alexey Gladkov
- [PATCH RESEND v11 7/8] proc: use human-readable values for hidepid, Alexey Gladkov
- Re: [PATCH RESEND v11 0/8] proc: modernize proc to support multiple private instances, Eric W. Biederman
- Re: [Cocci] Coccinelle rule for CVE-2019-18683,
Markus Elfring
- Coccinelle rule for CVE-2019-18683,
Alexander Popov
[Index of Archives]
[Linux Samsung SoC]
[Linux Actions SoC]
[Linux Rockchip SoC]
[Linux for Synopsys ARC Processors]
[Linux USB Devel]
[Video for Linux]
[Linux SCSI]
[Yosemite Forum]