Kernel Hardening
[Prev Page][Next Page]
- Re: [PATCH] tracing: Use linker magic instead of recasting ftrace_ops_list_func(), (continued)
- [PATCH 0/4] Paravirtualized Control Register pinning,
John Andersen
- lockdown bypass on mainline kernel for loading unsigned modules,
Jason A. Donenfeld
- Re: [RFC] io_uring: add restrictions to support untrusted applications and guests,
Jann Horn
- [PATCH] ata: Eliminate usage of uninitialized_var() macro, Jason Yan
- [PATCH] f2fs: Eliminate usage of uninitialized_var() macro,
Jason Yan
- [PATCH] erofs: Eliminate usage of uninitialized_var() macro,
Jason Yan
- [PATCH] ACPI: Eliminate usage of uninitialized_var() macro,
Jason Yan
- [PATCH] block: Eliminate usage of uninitialized_var() macro, Jason Yan
- [PATCH] kernel/trace: Remove function callback casts,
Oscar Carter
- [PATCH AUTOSEL 5.6 103/606] gcc-common.h: Update for GCC 10, Sasha Levin
- [PATCH 0/5] Improvements of the stackleak gcc plugin,
Alexander Popov
- [PATCH 0/5] Use per-CPU temporary mappings for patching,
Christopher M. Riedl
- [PATCH v5 0/3] drivers/acpi: Remove function callback casts,
Oscar Carter
- [PATCH v4 0/3] drivers/acpi: Remove function callback casts,
Oscar Carter
- [PATCH v3] firewire: Remove function callback casts,
Oscar Carter
- [PATCH v3 0/2] drivers/irqchip: Remove function callback casts,
Oscar Carter
- [PATCH v18 00/12] Landlock LSM,
Mickaël Salaün
- [PATCH v18 01/12] landlock: Add object management, Mickaël Salaün
- [PATCH v18 02/12] landlock: Add ruleset and domain management, Mickaël Salaün
- [PATCH v18 03/12] landlock: Set up the security framework and manage credentials, Mickaël Salaün
- [PATCH v18 04/12] landlock: Add ptrace restrictions, Mickaël Salaün
- [PATCH v18 05/12] LSM: Infrastructure management of the superblock, Mickaël Salaün
- [PATCH v18 06/12] fs,security: Add sb_delete hook, Mickaël Salaün
- [PATCH v18 07/12] landlock: Support filesystem access-control, Mickaël Salaün
- [PATCH v18 08/12] landlock: Add syscall implementation, Mickaël Salaün
- [PATCH v18 09/12] arch: Wire up landlock() syscall, Mickaël Salaün
- [PATCH v18 10/12] selftests/landlock: Add initial tests, Mickaël Salaün
- [PATCH v18 11/12] samples/landlock: Add a sandbox manager example, Mickaël Salaün
- [PATCH v18 12/12] landlock: Add user and kernel documentation, Mickaël Salaün
- [PATCH v2] drivers/irqchip: Remove function callback casts,
Oscar Carter
- [PATCH v2] firewire-core: remove cast of function callback,
Takashi Sakamoto
- [PATCH] staging/rtl8192e: Remove function callback casts, Oscar Carter
- [PATCH] drivers/irqchip: Remove function callback casts,
Oscar Carter
- [PATCH v2 0/9] Function Granular KASLR,
Kristen Carlson Accardi
- [PATCH v2 1/9] objtool: Do not assume order of parent/child functions, Kristen Carlson Accardi
- [PATCH v2 2/9] x86: tools/relocs: Support >64K section headers, Kristen Carlson Accardi
- [PATCH v2 3/9] x86/boot: Allow a "silent" kaslr random byte fetch, Kristen Carlson Accardi
- [PATCH v2 4/9] x86: Makefile: Add build and config option for CONFIG_FG_KASLR, Kristen Carlson Accardi
- [PATCH v2 5/9] x86: Make sure _etext includes function sections, Kristen Carlson Accardi
- [PATCH v2 6/9] x86/tools: Add relative relocs for randomized functions, Kristen Carlson Accardi
- [PATCH v2 7/9] x86: Add support for function granular KASLR, Kristen Carlson Accardi
- [PATCH v2 8/9] kallsyms: Hide layout, Kristen Carlson Accardi
- [PATCH v2 9/9] module: Reorder functions, Kristen Carlson Accardi
- Re: [PATCH v2 0/9] Function Granular KASLR, Kees Cook
- Re: [PATCH v2 0/9] Function Granular KASLR, Thomas Gleixner
- [PATCH 0/2] firewire: obsolete cast of function callback toward CFI,
Takashi Sakamoto
- [PATCH v2] firewire: Remove function callback casts,
Oscar Carter
- [PATCH] firewire: Remove function callback casts,
Oscar Carter
- [PATCH AUTOSEL 4.9 02/27] gcc-common.h: Update for GCC 10, Sasha Levin
- [PATCH AUTOSEL 4.14 02/39] gcc-common.h: Update for GCC 10, Sasha Levin
- [PATCH AUTOSEL 4.19 02/31] gcc-common.h: Update for GCC 10, Sasha Levin
- [PATCH AUTOSEL 5.4 04/49] gcc-common.h: Update for GCC 10, Sasha Levin
- [PATCH AUTOSEL 5.6 04/62] gcc-common.h: Update for GCC 10, Sasha Levin
- [PATCH v17 00/10] Landlock LSM,
Mickaël Salaün
- [PATCH v17 01/10] landlock: Add object management, Mickaël Salaün
- [PATCH v17 02/10] landlock: Add ruleset and domain management, Mickaël Salaün
- [PATCH v17 03/10] landlock: Set up the security framework and manage credentials, Mickaël Salaün
- [PATCH v17 04/10] landlock: Add ptrace restrictions, Mickaël Salaün
- [PATCH v17 05/10] fs,landlock: Support filesystem access-control, Mickaël Salaün
- [PATCH v17 06/10] landlock: Add syscall implementation, Mickaël Salaün
- [PATCH v17 07/10] arch: Wire up landlock() syscall, Mickaël Salaün
- [PATCH v17 08/10] selftests/landlock: Add initial tests, Mickaël Salaün
- [PATCH v17 09/10] samples/landlock: Add a sandbox manager example, Mickaël Salaün
- [PATCH v17 10/10] landlock: Add user and kernel documentation, Mickaël Salaün
- Re: [PATCH v17 00/10] Landlock LSM, Mickaël Salaün
- Open source a new kernel harden project,
wzt wzt
- [PATCH] gcc-plugins: remove always false $(if ...) in Makefile,
Masahiro Yamada
- Get involved in the KSPP,
Oscar Carter
- FYI: NGI POINTER OSS Funding, Dmitry Vyukov
- [PATCH v5 0/6] Add support for O_MAYEXEC,
Mickaël Salaün
- [PATCH] security/keys: rewrite big_key crypto to use Zinc,
Jason A. Donenfeld
- [PATCH v4 0/5] Add support for O_MAYEXEC,
Mickaël Salaün
- [RFC PATCH v2 0/5] Use per-CPU temporary mappings for patching,
Christopher M. Riedl
- [PATCH v3 0/5] Add support for RESOLVE_MAYEXEC,
Mickaël Salaün
- Re: [PATCH] nsproxy: attach to namespaces via pidfds,
Jann Horn
- [PATCH v13 0/8] proc: modernize proc to support multiple private instances,
Alexey Gladkov
- Re: gcc extended format checking plugin, Masahiro Yamada
- [PATCH v12 0/7] proc: modernize proc to support multiple private instances,
Alexey Gladkov
- [PATCH] gcc-plugins: latent_entropy: remove unneeded semicolon, Jason Yan
- [PATCH] gcc-plugins: structleak: remove unneeded variable 'ret', Jason Yan
- [PATCH v16 00/10] Landlock LSM,
Mickaël Salaün
- [PATCH v16 01/10] landlock: Add object management, Mickaël Salaün
- [PATCH v16 02/10] landlock: Add ruleset and domain management, Mickaël Salaün
- [PATCH v16 03/10] landlock: Set up the security framework and manage credentials, Mickaël Salaün
- [PATCH v16 04/10] landlock: Add ptrace restrictions, Mickaël Salaün
- [PATCH v16 05/10] fs,landlock: Support filesystem access-control, Mickaël Salaün
- [PATCH v16 07/10] arch: Wire up landlock() syscall, Mickaël Salaün
- [PATCH v16 06/10] landlock: Add syscall implementation, Mickaël Salaün
- [PATCH v16 08/10] selftests/landlock: Add initial tests, Mickaël Salaün
- [PATCH v16 09/10] samples/landlock: Add a sandbox manager example, Mickaël Salaün
- [PATCH v16 10/10] landlock: Add user and kernel documentation, Mickaël Salaün
- [PATCH 0/9] Function Granular Kernel Address Space Layout Randomization,
Kristen Carlson Accardi
- [PATCH 1/9] objtool: do not assume order of parent/child functions, Kristen Carlson Accardi
- [PATCH 2/9] x86: tools/relocs: Support >64K section headers, Kristen Carlson Accardi
- [PATCH 3/9] x86/boot: Allow a "silent" kaslr random byte fetch, Kristen Carlson Accardi
- [PATCH 4/9] x86: Makefile: Add build and config option for CONFIG_FG_KASLR, Kristen Carlson Accardi
- [PATCH 5/9] x86: make sure _etext includes function sections, Kristen Carlson Accardi
- [PATCH 6/9] x86/tools: Adding relative relocs for randomized functions, Kristen Carlson Accardi
- [PATCH 7/9] x86: Add support for function granular KASLR, Kristen Carlson Accardi
- [PATCH 8/9] kallsyms: hide layout, Kristen Carlson Accardi
- [PATCH 9/9] module: Reorder functions, Kristen Carlson Accardi
- Re: [PATCH 0/9] Function Granular Kernel Address Space Layout Randomization, Kees Cook
- [PATCH v3 0/5] hardening : prevent write to proces's read-only pages,
Lev Olshvang
- [PATCH v1 0/1] hardening : prevent write to proces's read-only pages, Lev Olshvang
- [PATCH v1] prevent write to proces's read-only pages, Lev Olshvang
- [PATCH RESEND v11 0/8] proc: modernize proc to support multiple private instances,
Alexey Gladkov
- [PATCH RESEND v11 1/8] proc: rename struct proc_fs_info to proc_fs_opts, Alexey Gladkov
- [PATCH RESEND v11 3/8] proc: move hide_pid, pid_gid from pid_namespace to proc_fs_info, Alexey Gladkov
- [PATCH RESEND v11 2/8] proc: allow to mount many instances of proc in one pid namespace, Alexey Gladkov
- [PATCH RESEND v11 4/8] proc: instantiate only pids that we can ptrace on 'hidepid=4' mount option, Alexey Gladkov
- [PATCH RESEND v11 5/8] proc: add option to mount only a pids subset, Alexey Gladkov
- [PATCH RESEND v11 6/8] docs: proc: add documentation for "hidepid=4" and "subset=pid" options and new mount behavior, Alexey Gladkov
- [PATCH RESEND v11 8/8] proc: use named enums for better readability, Alexey Gladkov
- [PATCH RESEND v11 7/8] proc: use human-readable values for hidepid, Alexey Gladkov
- Re: [PATCH RESEND v11 0/8] proc: modernize proc to support multiple private instances, Eric W. Biederman
- Re: [Cocci] Coccinelle rule for CVE-2019-18683,
Markus Elfring
- Coccinelle rule for CVE-2019-18683,
Alexander Popov
- [PATCH] gcc-common.h: 'params.h' has been dropped in GCC10,
Frédéric Pierret (fepitre)
- [PATCH v3 0/5] Optionally randomize kernel stack offset each syscall,
Kees Cook
- [RFC PATCH 0/5] Prevent write to read-only pages (text, PLT/GOT,
Lev Olshvang
- [PATCH v11 0/8] proc: modernize proc to support multiple private instances,
Alexey Gladkov
- kCFI sources,
joao@overdrivepizza.com
- [PATCH] gcc-plugins/stackleak: Avoid assignment for unused macro argument,
Kees Cook
- [PATCH v8 1/7] powerpc/mm: Implement set_memory() routines,
Russell Currey
- [PATCH v2 bpf] kbuild: fix dependencies for DEBUG_INFO_BTF,
Slava Bacherikov
- [PATCH v7 0/7] set_memory() routines and STRICT_MODULE_RWX,
Russell Currey
- CONFIG_DEBUG_INFO_BTF and CONFIG_GCC_PLUGIN_RANDSTRUCT,
Jann Horn
- [PATCH v5 0/6] implement KASLR for powerpc/fsl_booke/64,
Jason Yan
- [PATCH v5 1/6] powerpc/fsl_booke/kaslr: refactor kaslr_legal_offset() and kaslr_early_init(), Jason Yan
- [PATCH v5 3/6] powerpc/fsl_booke/64: implement KASLR for fsl_booke64, Jason Yan
- [PATCH v5 2/6] powerpc/fsl_booke/64: introduce reloc_kernel_entry() helper, Jason Yan
- [PATCH v5 4/6] powerpc/fsl_booke/64: do not clear the BSS for the second pass, Jason Yan
- [PATCH v5 5/6] powerpc/fsl_booke/64: clear the original kernel if randomized, Jason Yan
- [PATCH v5 6/6] powerpc/fsl_booke/kaslr: rename kaslr-booke32.rst to kaslr-booke.rst and add 64bit part, Jason Yan
- Re: [PATCH v5 0/6] implement KASLR for powerpc/fsl_booke/64, Jason Yan
- Re: [PATCH v5 0/6] implement KASLR for powerpc/fsl_booke/64, Scott Wood
- Re: [PATCH v5 0/6] implement KASLR for powerpc/fsl_booke/64, Jason Yan
- Re: [PATCH v5 0/6] implement KASLR for powerpc/fsl_booke/64, Daniel Axtens
- [RFC PATCH] arm64: remove CONFIG_DEBUG_ALIGN_RODATA feature,
Ard Biesheuvel
- [PATCH] gcc-plugins: drop support for GCC <= 4.7,
Masahiro Yamada
- [PATCH v10 0/9] proc: modernize proc to support multiple private instances,
Alexey Gladkov
- [PATCH v10 1/9] proc: rename struct proc_fs_info to proc_fs_opts, Alexey Gladkov
- [PATCH v10 2/9] proc: allow to mount many instances of proc in one pid namespace, Alexey Gladkov
- [PATCH v10 3/9] proc: move hide_pid, pid_gid from pid_namespace to proc_fs_info, Alexey Gladkov
- [PATCH v10 4/9] proc: instantiate only pids that we can ptrace on 'hidepid=4' mount option, Alexey Gladkov
- [PATCH v10 6/9] docs: proc: add documentation for "hidepid=4" and "subset=pid" options and new mount behavior, Alexey Gladkov
- [PATCH v10 5/9] proc: add option to mount only a pids subset, Alexey Gladkov
- [PATCH v10 7/9] proc: move hidepid values to uapi as they are user interface to mount, Alexey Gladkov
- [PATCH v10 8/9] proc: use human-readable values for hidehid, Alexey Gladkov
- [PATCH v10 9/9] proc: use named enums for better readability, Alexey Gladkov
- Re: [PATCH v10 0/9] proc: modernize proc to support multiple private instances, Eric W. Biederman
- [PATCH v5 0/6] binfmt_elf: Update READ_IMPLIES_EXEC logic for modern CPUs,
Kees Cook
- [PATCH v15 00/10] Landlock LSM,
Mickaël Salaün
- [PATCH v15 01/10] landlock: Add object management, Mickaël Salaün
- [PATCH v15 02/10] landlock: Add ruleset and domain management, Mickaël Salaün
- [PATCH v15 03/10] landlock: Set up the security framework and manage credentials, Mickaël Salaün
- [PATCH v15 04/10] landlock: Add ptrace restrictions, Mickaël Salaün
- [PATCH v15 05/10] fs,landlock: Support filesystem access-control, Mickaël Salaün
- [PATCH v15 06/10] landlock: Add syscall implementation, Mickaël Salaün
- [PATCH v15 07/10] arch: Wire up landlock() syscall, Mickaël Salaün
- [PATCH v15 08/10] selftests/landlock: Add initial tests, Mickaël Salaün
- [PATCH v15 09/10] samples/landlock: Add a sandbox manager example, Mickaël Salaün
- [PATCH v15 10/10] landlock: Add user and kernel documentation, Mickaël Salaün
- [PATCH 1/2] kconfig: remove unused variable in qconf.cc,
Masahiro Yamada
[Index of Archives]
[Linux Samsung SoC]
[Linux Actions SoC]
[Linux Rockchip SoC]
[Linux for Synopsys ARC Processors]
[Linux USB Devel]
[Video for Linux]
[Linux SCSI]
[Yosemite Forum]