Kernel-hardening archive mirror
 help / color / mirror / Atom feed
- recent:[subjects (threaded)|topics (new)|topics (active)]
2024-03-16  3:14 Re: [RFC PATCH v2 00/19] PKS write protected page tables 40+ messages
2024-02-05  7:45 [ANNOUNCE] CFP: Linux Security Summit Europe 2024
2023-11-29 21:19 [ANNOUNCE] CFP: Linux Security Summit North America 2024
2023-11-02 14:50 Re: Isolating abstract sockets 18+ messages
2023-10-11 15:49 sending commit notification to patch thread (was "Re: [PATCH v3 0/1] Restrict access to TIOCLINUX") 13+ messages
2023-09-16 16:18 Re: [PATCH] slub: Introduce CONFIG_SLUB_RCU_DEBUG 7+ messages
2023-08-28 16:42 Re: [PATCH v2 1/1] tty: Restrict access to TIOCLINUX' copy-and-paste subcommands 4+ messages
2023-08-25 21:22 Re: Kernel hardening project suggestion: Normalizing ->ctor slabs and TYPESAFE_BY_RCU slabs 9+ messages
2023-08-23 14:36 Re: [PATCH] Restrict access to TIOCLINUX 13+ messages
2023-08-22 14:39 Re: [PATCH v3 0/5] Landlock: IOCTL support - TTY restrictions RFC
2023-05-16 20:17 Re: [PATCH] sysctl: add config to make randomize_va_space RO 10+ messages
2023-04-17  8:35 [ANNOUNCE] [CFP] Linux Security Summit Europe (LSS-EU)
2023-04-10 21:25 Re: Per-process flag set via prctl() to deny module loading? 6+ messages
2023-04-03 12:06 Re: [PATCH RFC] Randomized slab caches for kmalloc()
2023-02-15 10:03 Re: [PATCH] mm/slab: always use cache from obj 4+ messages
2023-02-06 18:58 Re: Linux guest kernel threat model for Confidential Computing 39+ messages
2023-01-27 18:38 Re: [PATCH] fs: Use CHECK_DATA_CORRUPTION() when kernel bugs are detected 5+ messages
2023-01-20 22:24 [ANNOUNCE] Linux Security Summit North Americ (LSS-NA) CfP
2022-12-06  2:20 Re: Reducing runtime complexity 7+ messages
2022-11-09 16:19 Re: [PATCH] exit: Put an upper limit on how often we can oops 13+ messages
2022-10-11 19:52 Re: [Self-introduction] - Paulo Almeida 3+ messages
2022-07-27 17:47 Re: [PATCH] Introduce the pkill_on_warn boot parameter 33+ messages
2022-06-29  7:35 Re: [PATCH v2] stack: Declare {randomize_,}kstack_offset to fix Sparse warnings 2+ messages
2022-06-29  5:51 Re: [PATCH] stack: Declare {randomize_,}kstack_offset to fix Sparse warnings 3+ messages
2022-06-01 19:03 Re: Possibility of merge of disable icotl TIOCSTI patch 2+ messages
2022-05-18 15:50 [ANNOUNCE][CFP] Linux Security Summit Europe 2022
2022-05-09 20:58 Re: [PATCH] Decouple slub_debug= from no_hash_pointers again 2+ messages
2022-04-13  0:16 Re: Kernel Self Protection Project: slub_debug=ZF 2+ messages
2022-03-26 17:09 Re: OOB accesses in ax88179_rx_fixup() (in USB network card driver) - variants 2+ messages
2022-03-24 14:11 Re: Large post detailing recent Linux RNG improvements 4+ messages
2022-03-19 12:10 CVE Proofs of Concept
2022-03-18 22:31 Re: [ANNOUNCE][CFP] Linux Security Summit North America 2022 2+ messages
2022-03-09 19:35 Re: [PATCH] powerpc/32: Stop printing the virtual memory layout 34+ messages
2022-02-06 13:47 Re: [PATCH] Add ability to disallow idmapped mounts 7+ messages
2022-01-14 13:36 Re: [PATCH v3 1/3] x86: Implement arch_prctl(ARCH_VSYSCALL_CONTROL) to disable vsyscall 13+ messages
2022-01-04 15:50 [PATCH v18 4/4] selftest/interpreter: Add tests for trusted_for(2) policies 5+ messages
2021-12-27 17:40 Re: [PATCH v2] x86: Implement arch_prctl(ARCH_VSYSCALL_CONTROL) to disable vsyscall 3+ messages
2021-12-16 18:31 Re: [PATCH] x86: Implement arch_prctl(ARCH_VSYSCALL_LOCKOUT) to disable vsyscall 7+ messages
2021-12-07  0:40 Re: [PATCH] net: prestera: replace zero-length array with flexible-array member 4+ messages
2021-12-01 16:40 Re: [PATCH v17 0/3] Add trusted_for(2) (was O_MAYEXEC) 9+ messages
2021-11-22 16:21 Re: [PATCH v2 0/2] Introduce the pkill_on_warn parameter 32+ messages
2021-11-21  0:42 I'm Jordan; New Kernel Developer Here!
2021-11-14 15:45 Re: [PATCH v16 1/3] fs: Add trusted_for(2) syscall implementation and related sysctl 10+ messages
2021-11-12 12:25 Re: [fs] a0918006f9: netperf.Throughput_tps -11.6% regression 10+ messages
2021-10-21 16:07 An analysis of current and potential security mitigations based on a TIOCSPGRP exploit 2+ messages
2021-10-11 21:07 Re: [PATCH v14 0/3] Add trusted_for(2) (was O_MAYEXEC) 12+ messages
2021-10-08 22:44 Re: [PATCH v13 3/3] selftest/interpreter: Add tests for trusted_for(2) policies 10+ messages
2021-10-07 19:00 Re: [PATCH v12 0/3] Add trusted_for(2) (was O_MAYEXEC) 10+ messages
2021-09-19 20:44 Self introduction
2021-09-14  2:44 Re: [ANNOUNCE][CFP] Linux Security Summit 2021 4+ messages
2021-09-02 16:13 Re: Landlock news #1
2021-08-24  3:24 Re: [PATCH] ucounts: Fix regression preventing increasing of rlimits in init_user_ns 9+ messages
2021-08-03  6:00 Re: Leveraging pidfs for process creation without fork 14+ messages
2021-07-05 12:52 Re: [PATCH v8 3/8] security/brute: Detect a brute force attack 6+ messages
2021-06-26  3:21 [PATCH 2/2] seq_buf: Make trace_seq_putmem_hex() support data longer than 8 2+ messages
2021-06-26  0:57 回复: [PATCH 1/2] seq_buf: fix overflow when length is bigger than 8 4+ messages
2021-06-25 13:27 Re: [PATCH] seq_buf: let seq_buf_putmem_hex support len larger than 8 7+ messages
2021-06-17 10:09 Re: [PATCH v5] bpf: core: fix shift-out-of-bounds in ___bpf_prog_run 18+ messages
2021-06-11 15:41 Re: [PATCH v8 0/8] Fork brute force attack mitigation 13+ messages
2021-06-08  8:53 Re: KASAN: use-after-free Read in hci_chan_del 7+ messages
2021-06-02 20:37 Re: [PATCH v11 0/9] Count rlimits in each user namespace 15+ messages
2021-05-23 15:47 Re: [PATCH v7 0/7] Fork brute force attack mitigation 12+ messages
2021-05-10 19:38 Re: [PATCH RFC 3/9] x86/mm/cpa: Add grouped page allocations 32+ messages
2021-05-07 16:15 New mailing list for Landlock LSM user space discussions
2021-05-07  7:14 Re: 08ed4efad6: stress-ng.sigsegv.ops_per_sec -41.9% regression 21+ messages
2021-04-23 15:22 Re: [PATCH v34 00/13] Landlock LSM 17+ messages
2021-04-11  8:46 Re: Notify special task kill using wait* functions 8+ messages
2021-04-09 16:04 Re: [PATCH v33 00/12] Landlock LSM 16+ messages
2021-04-07 21:37 Re: [PATCH v10 3/6] stack: Optionally randomize kernel stack offset each syscall 9+ messages
2021-04-07 16:56 Re: [PATCH v9 4/8] Reimplement RLIMIT_NPROC on top of ucounts 15+ messages
2021-04-01 22:42 Re: [PATCH v8 3/6] stack: Optionally randomize kernel stack offset each syscall 19+ messages
2021-04-01 20:59 Re: [PATCH v8 0/6] Optionally randomize kernel stack offset each syscall 2+ messages
2021-04-01 20:52 [PATCH v32 12/12] landlock: Add user and kernel documentation 13+ messages
2021-04-01 17:12 Re: [PATCH v31 07/12] landlock: Support filesystem access-control 20+ messages
2021-04-01 13:33 Re: [PATCH v9 0/6] Optionally randomize kernel stack offset each syscall 9+ messages
2021-04-01  8:34 Re: [PATCH v7 5/6] arm64: entry: Enable random_kstack_offset support 14+ messages
2021-03-31  6:33 Re: [PATCH v5 1/1] fs: Allow no_new_privs tasks to call chroot(2) 11+ messages
2021-03-30 21:18 Re: two potential randstruct improvements 3+ messages
2021-03-27 18:56 Re: [PATCH v5 1/1] fs: Allow no_new_privs tasks to call chroot(2) 2+ messages
2021-03-26 15:41 Re: [PATCH v6 7/8] Documentation: Add documentation for the Brute LSM 31+ messages
2021-03-25  9:29 Re: [PATCH v30 02/12] landlock: Add ruleset and domain management 49+ messages
2021-03-19 22:51 Re: Fine-grained Forward CFI on top of Intel CET / IBT 4+ messages
2021-03-18 12:46 Re: [PATCH v6 2/6] init_on_alloc: Optimize static branches 9+ messages
2021-03-16 20:06 Re: [PATCH v4 1/1] fs: Allow no_new_privs tasks to call chroot(2) 9+ messages
2021-03-16 19:32 Re: [PATCH v8 3/8] Use atomic_t for ucounts reference counting 15+ messages
2021-03-16  8:17 Re: [PATCH v3 1/1] fs: Allow no_new_privs tasks to call chroot(2) 4+ messages
2021-03-15 17:28 Re: [PATCH v5 1/7] mm: Restore init_on_* static branch defaults 12+ messages
2021-03-12 17:54 Re: [PATCH v5 7/8] Documentation: Add documentation for the Brute LSM 27+ messages
2021-03-11 10:42 Re: [PATCH v1 0/1] Unprivileged chroot 8+ messages
2021-03-11 10:37 Re: [PATCH v2 1/1] fs: Allow no_new_privs tasks to call chroot(2) 6+ messages
2021-03-05 17:56 Re: d28296d248:  stress-ng.sigsegv.ops_per_sec -82.7% regression 17+ messages
2021-03-04 10:08 Re: [PATCH 02/20] crypto: Manual replacement of the deprecated strlcpy() with return values 46+ messages
2021-02-27 18:46 Re: [PATCH v4 0/8] Fork brute force attack mitigation 2+ messages
2021-02-25 19:06 [PATCH v29 12/12] landlock: Add user and kernel documentation 13+ messages
2021-02-25 11:40 Re: [PATCH v1 1/1] Kernel Config to make randomize_va_space read-only. 2+ messages
2021-02-24 22:42 Re: [PATCH v9 01/16] tracing: move function tracer options to Kconfig (causing parisc build failures) 40+ messages
2021-02-24 14:11 Re: [PATCH v1 1/1] Kernel Config to make randomize_va_space read-only. 2+ messages
2021-02-23  5:30 Re: [PATCH v6 0/7] Count rlimits in each user namespace 18+ messages
2021-02-19 15:34 Re: [PATCH v28 07/12] landlock: Support filesystem access-control 28+ messages
2021-02-06 10:45 Re: [PATCH v3 2/2] arm64/acpi: disallow writeable AML opregion mapping for EFI code regions 16+ messages
2021-02-05 17:31 Joining the general Linux kernel hardening mailing list
2021-02-05  2:55 c632dadc10: BUG:KASAN:null-ptr-deref_in_is_ucounts_overlimit 10+ messages
2021-01-27 19:57 Re: [PATCH v27 07/12] landlock: Support filesystem access-control 17+ messages
2021-01-25 17:21 Re: [PATCH v4 00/10] Function Granular KASLR 46+ messages
2021-01-22 19:33 Re: [PATCH kspp-next] kbuild: prevent CC_FLAGS_LTO self-bloating on recursive rebuilds 2+ messages
2021-01-22 13:00 [PATCH v4 7/7] kselftests: Add test to check for rlimit changes in different user namespaces 8+ messages
2021-01-21 16:07 Re: [RFC PATCH v3 1/8] Use refcount_t for ucounts reference counting 22+ messages
2021-01-16 17:16 Re: [PATCH v26 07/12] landlock: Support filesystem access-control 25+ messages
2021-01-13 18:01 Re: [RFC PATCH v2 1/8] Use atomic type for ucounts reference counting 15+ messages
2021-01-10 20:41 linux-hardening list archive
2021-01-07  8:39 Re: [PATCH v6 2/3] io_uring: add IOURING_REGISTER_RESTRICTIONS opcode 11+ messages
2021-01-04 23:07 Re: [PATCH v2] bug: further enhance use of CHECK_DATA_CORRUPTION 11+ messages
2020-12-28  7:24 Re: [PATCH 04/13] x86/extable: Introduce _ASM_EXTABLE_UA for uaccess fixups 2+ messages
2020-12-15  6:09 Re: Kernel complexity 5+ messages
2020-12-11 17:46 Re: [PATCH v2 0/6] aarch64: avoid mprotect(PROT_BTI|PROT_EXEC) [BZ #26831] 20+ messages
2020-12-09 19:24 Re: [PATCH v8 00/16] Add support for Clang LTO 51+ messages
2020-12-04 15:40 Re: [PRE-REVIEW PATCH 0/2] Remove all strlcpy in favor of strscpy 4+ messages
2020-12-04 11:54 Re: [PATCH RFC v2 2/6] mm/slab: Perform init_on_free earlier 24+ messages
2020-12-03 18:47 Re: [PATCH v6 14/25] kbuild: lto: remove duplicate dependencies from .mod files 73+ messages
2020-12-02 18:54 Re: [PATCH v7 00/17] Add support for Clang LTO 50+ messages
2020-12-01 19:23 [PATCH v25 12/12] landlock: Add user and kernel documentation 13+ messages
2020-11-24  2:38 Re: [PATCH v24 12/12] landlock: Add user and kernel documentation 27+ messages
2020-11-19  9:16 Re: [PATCH v4] mm: Optional full ASLR for mmap() and mremap() 2+ messages
2020-11-16 21:36 Re: [PATCH v22 01/12] landlock: Add object management 37+ messages
2020-11-15 15:00 Re: [PATCH v2 0/8] Fork brute force attack mitigation 15+ messages
2020-11-10  8:16 Re: [PATCH v23 00/12] Landlock LSM 15+ messages
2020-11-05 19:37 Re: [PATCH] mm, hugetlb: Avoid double clearing for hugetlb pages 17+ messages
2020-11-05 11:31 Re: [PATCH 0/4] aarch64: avoid mprotect(PROT_BTI|PROT_EXEC) [BZ #26831] 28+ messages
2020-11-04 16:21 Re: [RFC PATCH v1 4/4] Allow to change the user namespace in which user rlimits are counted 12+ messages
2020-10-27 17:19 Re: [RESEND PATCH v11 0/3] Add trusted_for(2) (was O_MAYEXEC) 6+ messages
2020-10-26 16:51 Re: BTI interaction between seccomp filters in systemd and glibc mprotect calls, causing service failures 12+ messages
2020-10-15 12:31 Re: [PATCH v21 12/12] landlock: Add user and kernel documentation 18+ messages
2020-10-13 18:32 Re: Remove all strlcpy() uses in favor of strscpy() (#89) 3+ messages
2020-10-12 21:02 Re: [PATCH v5 25/29] arm64: allow LTO_CLANG and THINLTO to be selected 40+ messages
2020-10-07 15:16 Re: Linux-specific kernel hardening 13+ messages
2020-10-06  5:57 Re: [PATCH] random32: Restore __latent_entropy attribute on net_rand_state 5+ messages
2020-10-06  0:00 [PATCH v2] MAINTAINERS: Change hardening mailing list
2020-10-05 23:58 Re: [PATCH] MAINTAINERS: Change hardening mailing list 3+ messages
2020-10-05  7:10 Re: [PATCH v4 04/29] objtool: Add a pass for generating __mcount_loc 42+ messages
2020-10-03  9:52 Re: [RFC PATCH 3/6] security/fbfam: Use the api to manage statistics 45+ messages
2020-10-03  9:43 Re: [PATCH v2 0/4] [RFC] Implement Trampoline File Descriptor 52+ messages
2020-10-01 20:23 Re: [PATCH v11 2/3] arch: Wire up trusted_for(2) 6+ messages
2020-09-29 18:58 Re: [PATCH v5 00/10] Function Granular KASLR 15+ messages
2020-09-24 15:32 [PATCH v10 3/3] selftest/interpreter: Add tests for trusted_for(2) policies 4+ messages
2020-09-21 18:58 Re: [PATCH v3 13/30] kbuild: lto: postpone objtool 38+ messages
2020-09-16 13:42 Re: [PATCH v20 05/12] LSM: Infrastructure management of the superblock 18+ messages
2020-09-15 13:32 Re: [RFC PATCH v9 2/3] arch: Wire up introspect_access(2) 17+ messages
2020-09-12  0:16 Re: [RFC PATCH v8 0/3] Add support for AT_INTERPRETED (was O_MAYEXEC) 24+ messages
2020-09-11 16:22 Re: [PATCH] sched.h: drop in_ubsan field when UBSAN is in trap mode 5+ messages
2020-09-10 18:29 Re: [PATCH v2 05/28] objtool: Add a pass for generating __mcount_loc 213+ messages
2020-09-07 18:07 Re: [RFC PATCH 0/9] Fork brute force attack mitigation (fbfam) 4+ messages
2020-09-07  0:15 Re: [PATCH v3 4/6] powerpc: Introduce temporary mm 11+ messages
2020-09-06 13:52 Re: [RFC PATCH 0/9] Fork brute force attack mitigation (fbfam) 2+ messages
2020-09-02 12:16 Re: [PATCH] scripts: Add intended executable mode and SPDX license 13+ messages
2020-09-01 15:42 Re: [PATCH v1 0/4] [RFC] Implement Trampoline File Descriptor 67+ messages
2020-08-27 15:04 Re: [PATCH v4 3/3] io_uring: allow disabling rings during the creation 19+ messages
2020-08-27 14:44 Re: [PATCH v5 0/3] io_uring: add restrictions to support untrusted applications and guests 11+ messages
2020-08-20  0:35 Re: init_on_alloc/init_on_free boot options 3+ messages
2020-08-18 20:50 Re: [PATCH RFC 1/2] mm: Extract SLAB_QUARANTINE from KASAN 19+ messages
2020-08-18 20:30 Re: usercopy arch_within_stack_frames() is a no-op in almost all modern kernel configurations 2+ messages
2020-08-18  6:27 Re: [PATCH v2] overflow: Add __must_check attribute to check_*() helpers 5+ messages
2020-08-17  5:16 Re: [PATCH v2 1/5] powerpc/mm: Introduce temporary mm 14+ messages
2020-08-15 17:11 Re: [PATCH] overflow: Add __must_check attribute to check_*() helpers 5+ messages
2020-08-13 15:31 Re: [PATCH v7 3/7] exec: Move path_noexec() check earlier 44+ messages
2020-08-12 12:31 Re: [PATCH 0/3] Modernize tasklet callback API 27+ messages
2020-08-06  7:49 Re: [PATCH v3 0/3] io_uring: add restrictions to support untrusted applications and guests 5+ messages
2020-08-05 23:22 Re: [RFC] saturate check_*_overflow() output? 7+ messages
2020-07-31 14:41 Re: [PATCH v2 2/2] kernel/trace: Remove function callback casts 18+ messages
2020-07-31  4:16 Re: [PATCH 1/2] kbuild: move shared library build rules to scripts/gcc-plugins/Makefile 3+ messages
2020-07-30 17:14 Re: Alternative CET ABI 5+ messages
2020-07-28  8:17 Re: [PATCH 12/26] netfilter: switch nf_setsockopt to sockptr_t 4+ messages
2020-07-22 19:40 Re: [PATCH v6 5/7] fs,doc: Enable to enforce noexec mounts or file exec through O_MAYEXEC 25+ messages
2020-07-22 14:29 Re: [PATCH RFC v2 2/3] io_uring: add IOURING_REGISTER_RESTRICTIONS opcode 17+ messages
2020-07-18 12:34 Re: Clarification about the series to modernize the tasklet api 18+ messages
2020-07-15 19:58 Re: [PATCH 2/4] KVM: x86: Introduce paravirt feature CR0/CR4 pinning 30+ messages
2020-07-13 16:32 Re: [PATCH] gcc-plugins: Replace HTTP links with HTTPS ones 2+ messages
2020-07-13  9:24 Re: [PATCH RFC 0/3] io_uring: add restrictions to support untrusted applications and guests 9+ messages
2020-07-10 15:20 Re: [PATCH v3] firewire: Remove function callback casts 4+ messages
2020-07-10 12:57 Re: [PATCH v19 08/12] landlock: Add syscall implementation 27+ messages
2020-07-08 16:47 Re: [PATCH v3 09/10] kallsyms: Hide layout 24+ messages
2020-07-04 15:50 [PATCH v2] parisc/kernel/ftrace: Remove function callback casts
2020-07-04 12:25 Re: [PATCH] drivers/s390/char/tty3270: Remove function callback casts 4+ messages
2020-07-04 12:12 Re: [PATCH] parisc/kernel/ftrace: Remove function callback casts 3+ messages
2020-07-03 18:29 Re: [RFC PATCH v2] arm64/acpi: disallow AML memory opregions to access kernel memory 6+ messages
2020-06-28  5:59 Re: [PATCH] gcc-plugins: fix gcc-plugins directory path in documentation 3+ messages
2020-06-27 11:08 Re: [PATCH v5 0/3] drivers/acpi: Remove function callback casts 7+ messages
2020-06-24 15:49 Re: [PATCH] ACPI: Eliminate usage of uninitialized_var() macro 2+ messages
2020-06-24 14:53 Re: [PATCH v2 5/5] gcc-plugins/stackleak: Add 'verbose' plugin parameter 17+ messages
2020-06-23 13:42 RE: [PATCH v4 3/5] stack: Optionally randomize kernel stack offset each syscall 19+ messages
2020-06-23 10:16 Re: [PATCH 5/5] gcc-plugins/stackleak: Don't instrument vgettimeofday.c in arm64 VDSO 31+ messages
2020-06-23  9:14 Re: [RFC PATCH] arm64/acpi: disallow AML memory opregions to access kernel memory 6+ messages
2020-06-22 14:45 Re: [PATCH] acpi: disallow loading configfs acpi tables when locked down 10+ messages
2020-06-20 14:23 Re: [PATCH] kernel/trace: Remove function callback casts 5+ messages
2020-06-18 17:58 Re: [PATCH] tracing: Use linker magic instead of recasting ftrace_ops_list_func() 8+ messages
2020-06-18 14:06 [kvm-unit-tests PATCH v2] x86: Add control register pinning tests
2020-06-18 13:31 Re: [kvm-unit-tests PATCH] x86: Add control register pinning tests 6+ messages
2020-06-17 23:26 [kvm-unit-tests RESEND PATCH] x86: Add control register pinning tests
2020-06-16 16:07 Re: [RFC] io_uring: add restrictions to support untrusted applications and guests 10+ messages
2020-06-15 20:11 Re: [PATCH] f2fs: Eliminate usage of uninitialized_var() macro 3+ messages
2020-06-15  8:29 Re: [PATCH] erofs: Eliminate usage of uninitialized_var() macro 5+ messages

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).