
أداة للتحقق من خيارات تعزيز الأمان في نواة لينكس
(سابقًا kconfig-hardened-check)
هناك العديد من خيارات تعزيز أمان نواة لينكس. الكثير منها غير مُفعّل من قبل التوزيعات الرئيسية. علينا تفعيل هذه الخيارات بأنفسنا لجعل أنظمتنا أكثر أمانًا.
لكن لا أحد يحب فحص الإعدادات يدويًا. لذا دع الحواسيب تقوم بعملها!
kernel-hardening-checker (سابقًا kconfig-hardened-check) هي أداة لفحص خيارات تعزيز أمان نواة لينكس.
الترخيص: GPL-3.0.
يدعم kernel-hardening-checker فحص:
البنيات المدعومة:
تستند توصيات تعزيز الأمان إلى:
كما أنشأت [Linux Kernel Defence Map][4]، وهو تمثيل رسومي للعلاقات بين ميزات تعزيز الأمان وفئات الثغرات أو تقنيات الاستغلال المقابلة.
يرجى الملاحظة أن تغيير معاملات أمان نواة لينكس قد يؤثر أيضًا على أداء النظام ووظائف برمجيات مساحة المستخدم. لذلك، عند تعيين هذه المعاملات، ضع في اعتبارك نموذج التهديد لنظام المعلومات المبني على لينكس الخاص بك واختبر حمولته النموذجية بدقة.
هناك عدة خيارات:
يمكنك تثبيت الحزمة من مستودع Git هذا باستخدام pip:
python3 -m pip install git+https://github.com/a13xp0p0v/kernel-hardening-checker
إذا واجهت خطأ بسبب بيئة مُدارة خارجيًا، قم بإنشاء بيئة افتراضية باستخدام python3 -m venv.
يمكنك تثبيت حزمة kernel-hardening-checker عبر مدير الحزم في بعض توزيعات GNU/Linux. انظر https://repology.org/project/kernel-hardening-checker/versions
بدلاً من ذلك، يمكنك ببساطة تشغيل ./bin/kernel-hardening-checker من المستودع المستنسخ دون تثبيت.
$ ./bin/kernel-hardening-checker -h usage: kernel-hardening-checker [-h] [--version] [-m {verbose,json,show_ok,show_fail}] [-a] [-c CONFIG] [-v KERNEL_VERSION] [-l CMDLINE] [-s SYSCTL] [-p {X86_64,X86_32,ARM64,ARM,RISCV}] [-g {X86_64,X86_32,ARM64,ARM,RISCV}]
A tool for checking the security hardening options of the Linux kernel
options: -h, --help show this help message and exit --version show program's version number and exit -m, --mode {verbose,json,show_ok,show_fail} select a special output mode instead of the default one -a, --autodetect autodetect and check the security hardening options of the running kernel -c, --config CONFIG check the security hardening options in a Kconfig file (also supports *.gz files) -v, --kernel-version KERNEL_VERSION extract the kernel version from a version file (such as /proc/version) instead of using a Kconfig file -l, --cmdline CMDLINE check the security hardening options in a kernel command line file (such as /proc/cmdline) -s, --sysctl SYSCTL check the security hardening options in a sysctl output file (the result of "sudo sysctl -a > file") -p, --print {X86_64,X86_32,ARM64,ARM,RISCV} print security hardening recommendations for the selected architecture -g, --generate {X86_64,X86_32,ARM64,ARM,RISCV} generate a Kconfig fragment containing the security hardening options for the selected architecture
## أنماط الإخراج
- لا وسيطة `-m` لوضع الإخراج الافتراضي (انظر المثال أدناه)
- `-m verbose` لطباعة معلومات إضافية:
- خيارات التهيئة دون فحص مقابل
- تفاصيل الفحوصات المعقدة باستخدام AND/OR، مثل هذا:
```
-------------------------------------------------------------------------------------------
<<< OR >>>
CONFIG_STRICT_DEVMEM |kconfig|cut_attack_surface|defconfig | y
CONFIG_DEVMEM |kconfig|cut_attack_surface| kspp | is not set
-------------------------------------------------------------------------------------------
```
- `-m json` لطباعة النتائج بتنسيق JSON (لدمج `kernel-hardening-checker` مع أدوات أخرى)
- `-m show_ok` لإظهار الفحوصات الناجحة فقط
- `-m show_fail` لإظهار الفحوصات الفاشلة فقط
## مثال الإخراج```
$ ./bin/kernel-hardening-checker -a
[+] Going to autodetect and check the security hardening options of the running kernel
[+] Detected version of the running kernel: (6, 11, 0)
[+] Detected kconfig file of the running kernel: /boot/config-6.11.0-1007-oem
[+] Detected cmdline parameters of the running kernel: /proc/cmdline
[+] Saved sysctls to a temporary file /tmp/sysctl-at_0n9si
[+] Detected architecture: X86_64
[+] Detected compiler: GCC 130200
[!] WARNING: sysctl options available for root are not found in /tmp/sysctl-at_0n9si, try checking the output of "sudo sysctl -a"
=========================================================================================================================
option_name | type | reason | decision |desired_val | check_result
=========================================================================================================================
CONFIG_BUG |kconfig| self_protection |defconfig | y | OK
CONFIG_SLUB_DEBUG |kconfig| self_protection |defconfig | y | OK
CONFIG_THREAD_INFO_IN_TASK |kconfig| self_protection |defconfig | y | OK
CONFIG_IOMMU_DEFAULT_PASSTHROUGH |kconfig| self_protection |defconfig | is not set | OK
CONFIG_IOMMU_SUPPORT |kconfig| self_protection |defconfig | y | OK
CONFIG_STACKPROTECTOR |kconfig| self_protection |defconfig | y | OK
CONFIG_STACKPROTECTOR_STRONG |kconfig| self_protection |defconfig | y | OK
CONFIG_STRICT_KERNEL_RWX |kconfig| self_protection |defconfig | y | OK
CONFIG_STRICT_MODULE_RWX |kconfig| self_protection |defconfig | y | OK
CONFIG_REFCOUNT_FULL |kconfig| self_protection |defconfig | y | OK: version >= (5, 4, 208)
CONFIG_INIT_STACK_ALL_ZERO |kconfig| self_protection |defconfig | y | OK
CONFIG_CPU_MITIGATIONS |kconfig| self_protection |defconfig | y | OK
CONFIG_RANDOMIZE_BASE |kconfig| self_protection |defconfig | y | OK
CONFIG_VMAP_STACK |kconfig| self_protection |defconfig | y | OK
CONFIG_LSM_MMAP_MIN_ADDR |kconfig| self_protection |defconfig | 65536 | FAIL: "0"
CONFIG_DEBUG_WX |kconfig| self_protection |defconfig | y | OK
CONFIG_WERROR |kconfig| self_protection |defconfig | y | FAIL: "is not set"
CONFIG_X86_MCE |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_SPECTRE_V1 |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_SPECTRE_V2 |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_SSB |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MICROCODE |kconfig| self_protection |defconfig | y | OK
CONFIG_MICROCODE_INTEL |kconfig| self_protection |defconfig | y | OK: CONFIG_MICROCODE is "y"
CONFIG_MICROCODE_AMD |kconfig| self_protection |defconfig | y | OK: CONFIG_MICROCODE is "y"
CONFIG_X86_SMAP |kconfig| self_protection |defconfig | y | OK: version >= (5, 19, 0)
CONFIG_X86_UMIP |kconfig| self_protection |defconfig | y | OK
CONFIG_X86_MCE_INTEL |kconfig| self_protection |defconfig | y | OK
CONFIG_X86_MCE_AMD |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_RETPOLINE |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_GDS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_RFDS |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_SPECTRE_BHI |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_MDS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_TAA |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_MMIO_STALE_DATA |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_L1TF |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_RETBLEED |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_SRBDS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_TSA |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_VMSCAPE |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_RANDOMIZE_MEMORY |kconfig| self_protection |defconfig | y | OK
CONFIG_X86_KERNEL_IBT |kconfig| self_protection |defconfig | y | FAIL: "is not set"
CONFIG_MITIGATION_RETHUNK |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_PAGE_TABLE_ISOLATION|kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_UNRET_ENTRY |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_CALL_DEPTH_TRACKING |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_IBPB_ENTRY |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_IBRS_ENTRY |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_SRSO |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_ITS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_INTEL_IOMMU |kconfig| self_protection |defconfig | y | OK
CONFIG_AMD_IOMMU |kconfig| self_protection |defconfig | y | OK
CONFIG_RANDOM_KMALLOC_CACHES |kconfig| self_protection | kspp | y | OK
CONFIG_SLAB_MERGE_DEFAULT |kconfig| self_protection | kspp | is not set | FAIL: "y"
CONFIG_BUG_ON_DATA_CORRUPTION |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_SLAB_FREELIST_HARDENED |kconfig| self_protection | kspp | y | OK
CONFIG_SLAB_FREELIST_RANDOM |kconfig| self_protection | kspp | y | OK
CONFIG_SHUFFLE_PAGE_ALLOCATOR |kconfig| self_protection | kspp | y | OK
CONFIG_FORTIFY_SOURCE |kconfig| self_protection | kspp | y | OK
CONFIG_DEBUG_VIRTUAL |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_INIT_ON_ALLOC_DEFAULT_ON |kconfig| self_protection | kspp | y | OK
CONFIG_STATIC_USERMODEHELPER |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_SECURITY_LOCKDOWN_LSM |kconfig| self_protection | kspp | y | OK
CONFIG_LSM |kconfig| self_protection | kspp | *lockdown* | OK: in "landlock,lockdown,yama,integrity,apparmor"
CONFIG_SECURITY_LOCKDOWN_LSM_EARLY |kconfig| self_protection | kspp | y | OK
CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY|kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_DEBUG_SG |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_ZERO_CALL_USED_REGS |kconfig| self_protection | kspp | y | OK
CONFIG_DEBUG_CREDENTIALS |kconfig| self_protection | kspp | y | OK: version >= (6, 6, 8)
CONFIG_DEBUG_NOTIFIERS |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_KFENCE |kconfig| self_protection | kspp | y | OK
CONFIG_KFENCE_SAMPLE_INTERVAL |kconfig| self_protection | kspp | 100 | FAIL: "0"
CONFIG_RANDSTRUCT_FULL |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_HARDENED_USERCOPY |kconfig| self_protection | kspp | y | OK
CONFIG_HARDENED_USERCOPY_DEFAULT_ON |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_HARDENED_USERCOPY_FALLBACK |kconfig| self_protection | kspp | is not set | OK: is not found
CONFIG_HARDENED_USERCOPY_PAGESPAN |kconfig| self_protection | kspp | is not set | OK: is not found
CONFIG_GCC_PLUGIN_LATENT_ENTROPY |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_MODULE_SIG |kconfig| self_protection | kspp | y | OK
CONFIG_MODULE_SIG_ALL |kconfig| self_protection | kspp | y | OK
CONFIG_MODULE_SIG_SHA512 |kconfig| self_protection | kspp | y | OK
CONFIG_MODULE_SIG_FORCE |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_INIT_ON_FREE_DEFAULT_ON |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_EFI_DISABLE_PCI_DMA |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_RESET_ATTACK_MITIGATION |kconfig| self_protection | kspp | y | OK
CONFIG_UBSAN_BOUNDS |kconfig| self_protection | kspp | y | OK
CONFIG_UBSAN_LOCAL_BOUNDS |kconfig| self_protection | kspp | y | OK: CONFIG_UBSAN_BOUNDS is "y"
CONFIG_UBSAN_TRAP |kconfig| self_protection | kspp | y | FAIL: CONFIG_UBSAN_ENUM is not "is not set"
CONFIG_UBSAN_SANITIZE_ALL |kconfig| self_protection | kspp | y | OK: CONFIG_UBSAN_BOUNDS is "y"
CONFIG_SCHED_STACK_END_CHECK |kconfig| self_protection | kspp | y | OK
CONFIG_KSTACK_ERASE |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_KSTACK_ERASE_METRICS |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_KSTACK_ERASE is not "y"
CONFIG_KSTACK_ERASE_RUNTIME_DISABLE |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_KSTACK_ERASE is not "y"
CONFIG_SCHED_CORE |kconfig| self_protection | kspp | y | OK
CONFIG_LIST_HARDENED |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT|kconfig| self_protection | kspp | y | OK
CONFIG_PAGE_TABLE_CHECK |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_PAGE_TABLE_CHECK_ENFORCED |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_DEFAULT_MMAP_MIN_ADDR |kconfig| self_protection | kspp | 65536 | OK
CONFIG_HW_RANDOM_TPM |kconfig| self_protection | kspp | y | OK
CONFIG_CFI_CLANG |kconfig| self_protection | kspp | y | FAIL: CONFIG_CC_IS_CLANG is not "y"
CONFIG_CFI_PERMISSIVE |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_CC_IS_CLANG is not "y"
CONFIG_IOMMU_DEFAULT_DMA_STRICT |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_INTEL_IOMMU_DEFAULT_ON |kconfig| self_protection | kspp | y | OK
CONFIG_CFI_AUTO_DEFAULT |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_CFI_AUTO_DEFAULT is not present
CONFIG_MITIGATION_SLS |kconfig| self_protection | kspp | y | OK
CONFIG_INTEL_IOMMU_SVM |kconfig| self_protection | kspp | y | OK
CONFIG_AMD_IOMMU_V2 |kconfig| self_protection | kspp | y | OK: version >= (6, 7, 0)
CONFIG_SECURITY |kconfig| security_policy |defconfig | y | OK
CONFIG_SECURITY_YAMA |kconfig| security_policy | kspp | y | OK
CONFIG_LSM |kconfig| security_policy | kspp | *yama* | OK: in "landlock,lockdown,yama,integrity,apparmor"
CONFIG_SECURITY_LANDLOCK |kconfig| security_policy | kspp | y | OK
CONFIG_LSM |kconfig| security_policy | kspp | *landlock* | OK: in "landlock,lockdown,yama,integrity,apparmor"
CONFIG_SECURITY_SELINUX_DISABLE |kconfig| security_policy | kspp | is not set | OK: is not found
CONFIG_SECURITY_SELINUX_BOOTPARAM |kconfig| security_policy | kspp | is not set | FAIL: "y"
CONFIG_SECURITY_SELINUX_DEVELOP |kconfig| security_policy | kspp | is not set | FAIL: "y"
CONFIG_SECURITY_WRITABLE_HOOKS |kconfig| security_policy | kspp | is not set | OK: is not found
CONFIG_SECURITY_SELINUX_DEBUG |kconfig| security_policy | kspp | is not set | OK
CONFIG_SECURITY_SELINUX |kconfig| security_policy |a13xp0p0v | y | OK
CONFIG_LSM |kconfig| security_policy |a13xp0p0v | *selinux* | OK: "apparmor" is in CONFIG_LSM
CONFIG_SECCOMP |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_SECCOMP_FILTER |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_BPF_UNPRIV_DEFAULT_OFF |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_STRICT_DEVMEM |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_X86_INTEL_TSX_MODE_OFF |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_SECURITY_DMESG_RESTRICT |kconfig|cut_attack_surface| kspp | y | OK
CONFIG_ACPI_CUSTOM_METHOD |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_COMPAT_BRK |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_DEVKMEM |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_BINFMT_MISC |kconfig|cut_attack_surface| kspp | is not set | FAIL: "m"
CONFIG_INET_DIAG |kconfig|cut_attack_surface| kspp | is not set | FAIL: "m"
CONFIG_KEXEC |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_PROC_KCORE |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_LEGACY_PTYS |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_HIBERNATION |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_COMPAT |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_IA32_EMULATION |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_X86_X32 |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_X86_X32_ABI |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_MODIFY_LDT_SYSCALL |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_OABI_COMPAT |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_X86_MSR |kconfig|cut_attack_surface| kspp | is not set | FAIL: "m"
CONFIG_LEGACY_TIOCSTI |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_MODULE_FORCE_LOAD |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_M486 |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_MODULES |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_DEVMEM |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_IO_STRICT_DEVMEM |kconfig|cut_attack_surface| kspp | y | FAIL: "is not set"
CONFIG_LDISC_AUTOLOAD |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_X86_VSYSCALL_EMULATION |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_COMPAT_VDSO |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_DRM_LEGACY |kconfig|cut_attack_surface|maintainer| is not set | OK: is not found
CONFIG_FB |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "y"
CONFIG_VT |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "y"
CONFIG_BLK_DEV_FD |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "m"
CONFIG_BLK_DEV_FD_RAWCMD |kconfig|cut_attack_surface|maintainer| is not set | OK
CONFIG_NOUVEAU_LEGACY_CTX_SUPPORT |kconfig|cut_attack_surface|maintainer| is not set | OK: is not found
CONFIG_N_GSM |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "m"
CONFIG_ZSMALLOC_STAT |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_DEBUG_KMEMLEAK |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_BINFMT_AOUT |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_KPROBE_EVENTS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_UPROBE_EVENTS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_GENERIC_TRACER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_FUNCTION_TRACER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_STACK_TRACER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_HIST_TRIGGERS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_BLK_DEV_IO_TRACE |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PROC_VMCORE |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PROC_PAGE_MONITOR |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_USELIB |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_CHECKPOINT_RESTORE |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_USERFAULTFD |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_HWPOISON_INJECT |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_MEM_SOFT_DIRTY |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_DEVPORT |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_DEBUG_FS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_NOTIFIER_ERROR_INJECTION |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_FAIL_FUTEX |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_PUNIT_ATOM_DEBUG |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_ACPI_CONFIGFS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_EDAC_DEBUG |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_DRM_I915_DEBUG |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_DVB_C8SECTPFE |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_MTD_SLRAM |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_MTD_PHRAM |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_IO_URING |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_KCMP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_RSEQ |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_LATENCYTOP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_KCOV |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_PROVIDE_OHCI1394_DMA_INIT |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_SUNRPC_DEBUG |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_X86_16BIT |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_BLK_DEV_UBLK |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_SMB_SERVER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_XFS_ONLINE_SCRUB_STATS |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_CACHESTAT_SYSCALL |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PREEMPTIRQ_TRACEPOINTS |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_ENABLE_DEFAULT_TRACERS |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_PROVE_LOCKING |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_TEST_DEBUG_VIRTUAL |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_MPTCP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_TLS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_TIPC |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_IP_SCTP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_KGDB |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PTDUMP_DEBUGFS |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_X86_PTDUMP |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_DEBUG_CLOSURES |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_BCACHE_CLOSURES_DEBUG |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_STAGING |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_KSM |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_KALLSYMS |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_KEXEC_FILE |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_CRASH_DUMP |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_USER_NS |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_X86_CPUID |kconfig|cut_attack_surface| clipos | is not set | FAIL: "m"
CONFIG_X86_IOPL_IOPERM |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_ACPI_TABLE_UPGRADE |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_EFI_CUSTOM_SSDT_OVERLAYS |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_AIO |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_MAGIC_SYSRQ |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_MAGIC_SYSRQ_SERIAL |kconfig|cut_attack_surface|grapheneos| is not set | FAIL: "y"
CONFIG_EFI_TEST |kconfig|cut_attack_surface| lockdown | is not set | FAIL: "m"
CONFIG_MMIOTRACE_TEST |kconfig|cut_attack_surface| lockdown | is not set | OK
CONFIG_KPROBES |kconfig|cut_attack_surface| lockdown | is not set | FAIL: "y"
CONFIG_BPF_SYSCALL |kconfig|cut_attack_surface| lockdown | is not set | FAIL: "y"
CONFIG_MMIOTRACE |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_LIVEPATCH |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_IP_DCCP |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "m"
CONFIG_FTRACE |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_VIDEO_VIVID |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "m"
CONFIG_INPUT_EVBUG |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "m"
CONFIG_CORESIGHT |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_XFS_SUPPORT_V4 |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_BLK_DEV_WRITE_MOUNTED |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_FAULT_INJECTION |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK
CONFIG_ARM_PTDUMP_DEBUGFS |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_ARM_PTDUMP |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_SECCOMP_CACHE_DEBUG |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK
CONFIG_CRASH_DM_CRYPT |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_LKDTM |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK
CONFIG_TRIM_UNUSED_KSYMS |kconfig|cut_attack_surface|a13xp0p0v | y | FAIL: "is not set"
CONFIG_SYN_COOKIES |kconfig| network_security |defconfig | y | OK
CONFIG_COREDUMP |kconfig| harden_userspace | clipos | is not set | FAIL: "y"
CONFIG_PROC_MEM_NO_FORCE |kconfig| harden_userspace |a13xp0p0v | y | FAIL: is not found
CONFIG_ARCH_MMAP_RND_BITS |kconfig| harden_userspace |a13xp0p0v | 32 | OK
CONFIG_ARCH_MMAP_RND_COMPAT_BITS |kconfig| harden_userspace |a13xp0p0v | 16 | OK
CONFIG_X86_USER_SHADOW_STACK |kconfig| harden_userspace | kspp | y | OK
nokaslr |cmdline| self_protection |defconfig | is not set | OK: is not found
no_hash_pointers |cmdline| self_protection |defconfig | is not set | OK: is not found
nosmep |cmdline| self_protection |defconfig | is not set | OK: is not found
nosmap |cmdline| self_protection |defconfig | is not set | OK: is not found
dis_ucode_ldr |cmdline| self_protection |defconfig | is not set | OK: is not found
setcpuid |cmdline| self_protection |defconfig | is not set | OK: is not found
clearcpuid |cmdline| self_protection |defconfig | is not set | OK: is not found
nopti |cmdline| self_protection |defconfig | is not set | OK: is not found
nospec_store_bypass_disable |cmdline| self_protection |defconfig | is not set | OK: is not found
nospectre_v1 |cmdline| self_protection |defconfig | is not set | OK: is not found
nospectre_v2 |cmdline| self_protection |defconfig | is not set | OK: is not found
nospectre_bhb |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nobti |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nopauth |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nomte |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nogcs |cmdline| self_protection |defconfig | is not set | OK: is not found
iommu.passthrough |cmdline| self_protection |defconfig | 0 | OK: CONFIG_IOMMU_DEFAULT_PASSTHROUGH is "is not set"
rodata |cmdline| self_protection |defconfig | on | OK: rodata is not found
spectre_v2 |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spectre_v2_user |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spectre_bhi |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spec_store_bypass_disable |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
l1tf |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
mds |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
tsx_async_abort |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
srbds |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
mmio_stale_data |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
retbleed |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spec_rstack_overflow |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
gather_data_sampling |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
reg_file_data_sampling |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
tsa |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
indirect_target_selection |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
vmscape |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
slab_merge |cmdline| self_protection | kspp | is not set | OK: is not found
slub_merge |cmdline| self_protection | kspp | is not set | OK: is not found
page_alloc.shuffle |cmdline| self_protection | kspp | 1 | FAIL: is not found
hash_pointers |cmdline| self_protection | kspp | always | FAIL: is not found
slab_nomerge |cmdline| self_protection | kspp | is present | FAIL: is not present
init_on_alloc |cmdline| self_protection | kspp | 1 | OK: CONFIG_INIT_ON_ALLOC_DEFAULT_ON is "y"
init_on_free |cmdline| self_protection | kspp | 1 | FAIL: is not found
hardened_usercopy |cmdline| self_protection | kspp | 1 | FAIL: is not found
slab_common.usercopy_fallback |cmdline| self_protection | kspp | is not set | OK: is not found
kfence.sample_interval |cmdline| self_protection | kspp | 100 | FAIL: is not found
lockdown |cmdline| self_protection | kspp |confidentiality| FAIL: is not found
module.sig_enforce |cmdline| self_protection | kspp | 1 | FAIL: is not found
efi |cmdline| self_protection | kspp |*disable_early_pci_dma*| FAIL: is not found
randomize_kstack_offset |cmdline| self_protection | kspp | 1 | OK: CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT is "y"
mitigations |cmdline| self_protection | kspp | auto,nosmt | FAIL: is not found
intel_iommu |cmdline| self_protection | kspp | on | OK: CONFIG_INTEL_IOMMU_DEFAULT_ON is "y"
iommu.strict |cmdline| self_protection | kspp | 1 | FAIL: is not found
pti |cmdline| self_protection | kspp | on | FAIL: is not found
cfi |cmdline| self_protection | kspp | kcfi | FAIL: is not found
iommu |cmdline| self_protection | clipos | force | FAIL: is not found
tsx |cmdline|cut_attack_surface|defconfig | off | OK: CONFIG_X86_INTEL_TSX_MODE_OFF is "y"
nosmt |cmdline|cut_attack_surface| kspp | is present | FAIL: is not present
vsyscall |cmdline|cut_attack_surface| kspp | none | FAIL: is not found
vdso32 |cmdline|cut_attack_surface| kspp | 0 | OK: CONFIG_COMPAT_VDSO is "is not set"
ia32_emulation |cmdline|cut_attack_surface| kspp | 0 | FAIL: is not found
debugfs |cmdline|cut_attack_surface| grsec | off | FAIL: is not found
sysrq_always_enabled |cmdline|cut_attack_surface|grapheneos| is not set | OK: is not found
bdev_allow_write_mounted |cmdline|cut_attack_surface|a13xp0p0v | 0 | FAIL: is not found
norandmaps |cmdline| harden_userspace |defconfig | is not set | OK: is not found
proc_mem.force_override |cmdline| harden_userspace |a13xp0p0v | never | FAIL: is not found
net.core.bpf_jit_harden |sysctl | self_protection | kspp | 2 | FAIL: is not found
vm.mmap_min_addr |sysctl | self_protection | kspp | 65536 | OK
kernel.oops_limit |sysctl | self_protection |a13xp0p0v | 100 | FAIL: "10000"
kernel.warn_limit |sysctl | self_protection |a13xp0p0v | 100 | FAIL: "0"
kernel.dmesg_restrict |sysctl |cut_attack_surface| kspp | 1 | OK
kernel.perf_event_paranoid |sysctl |cut_attack_surface| kspp | 3 | FAIL: "4"
dev.tty.ldisc_autoload |sysctl |cut_attack_surface| kspp | 0 | FAIL: "1"
kernel.kptr_restrict |sysctl |cut_attack_surface| kspp | 2 | FAIL: "1"
dev.tty.legacy_tiocsti |sysctl |cut_attack_surface| kspp | 0 | OK
user.max_user_namespaces |sysctl |cut_attack_surface| kspp | 0 | FAIL: "63417"
kernel.kexec_load_disabled |sysctl |cut_attack_surface| kspp | 1 | FAIL: "0"
kernel.unprivileged_bpf_disabled |sysctl |cut_attack_surface| kspp | 1 | FAIL: "2"
vm.unprivileged_userfaultfd |sysctl |cut_attack_surface| kspp | 0 | OK
kernel.modules_disabled |sysctl |cut_attack_surface| kspp | 1 | FAIL: "0"
kernel.io_uring_disabled |sysctl |cut_attack_surface| grsec | 2 | FAIL: "0"
kernel.sysrq |sysctl |cut_attack_surface|a13xp0p0v | 0 | FAIL: "176"
net.ipv4.icmp_ignore_bogus_error_responses|sysctl | network_security | cis | 1 | OK
net.ipv4.icmp_echo_ignore_broadcasts |sysctl | network_security | cis | 1 | OK
net.ipv4.conf.all.accept_redirects |sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv4.conf.default.accept_redirects|sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.all.accept_redirects |sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.default.accept_redirects|sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv4.conf.all.accept_source_route |sysctl | network_security | cis | 0 | OK
net.ipv4.conf.default.accept_source_route|sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.all.accept_source_route |sysctl | network_security | cis | 0 | OK
net.ipv6.conf.default.accept_source_route|sysctl | network_security | cis | 0 | OK
net.ipv4.tcp_syncookies |sysctl | network_security | cis | 1 | OK
net.ipv6.conf.all.accept_ra |sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.default.accept_ra |sysctl | network_security | cis | 0 | FAIL: "1"
fs.protected_symlinks |sysctl | harden_userspace | kspp | 1 | OK
fs.protected_hardlinks |sysctl | harden_userspace | kspp | 1 | OK
fs.protected_fifos |sysctl | harden_userspace | kspp | 2 | FAIL: "1"
fs.protected_regular |sysctl | harden_userspace | kspp | 2 | OK
fs.suid_dumpable |sysctl | harden_userspace | kspp | 0 | FAIL: "2"
kernel.randomize_va_space |sysctl | harden_userspace | kspp | 2 | OK
kernel.yama.ptrace_scope |sysctl | harden_userspace | kspp | 3 | FAIL: "1"
vm.mmap_rnd_bits |sysctl | harden_userspace |a13xp0p0v | 32 | FAIL: is not found
vm.mmap_rnd_compat_bits |sysctl | harden_userspace |a13xp0p0v | 16 | FAIL: is not found
[+] Config check is finished: 'OK' - 168 / 'FAIL' - 184
باستخدام الوسيطة -g، تقوم الأداة بإنشاء جزء Kconfig مع خيارات تعزيز الأمان للهندسة المعمارية المحددة.
يمكن دمج جزء Kconfig هذا مع إعدادات نواة لينكس الحالية:``` $ ./bin/kernel-hardening-checker -g X86_64 > /tmp/fragment $ cd ~/linux-src/ $ ./scripts/kconfig/merge_config.sh .config /tmp/fragment Using .config as base Merging /tmp/fragment Value of CONFIG_BUG_ON_DATA_CORRUPTION is redefined by fragment /tmp/fragment: Previous value: # CONFIG_BUG_ON_DATA_CORRUPTION is not set New value: CONFIG_BUG_ON_DATA_CORRUPTION=y ...
## شكر وتقدير
شكرًا للمساهمين[26] والمستخدمين لهذا المشروع!
## أسئلة وأجوبة
__س:__ كيف تؤثر جميع معاملات النواة هذه على أمان نواة لينكس؟
__ج:__ للإجابة على هذا السؤال، يمكنك استخدام `kernel-hardening-checker` [مصادر التوصيات][24]
و [خريطة دفاع نواة لينكس][4] مع مراجعها.
<br />
__س:__ كيف يؤدي تعطيل `CONFIG_USER_NS` إلى تقليل سطح الهجوم؟ إنه مطلوب للحاويات!
__ج:__ نعم، يوفر خيار `CONFIG_USER_NS` بعض العزل بين برامج مساحة المستخدم،
لكن الأداة توصي بتعطيله لتقليل سطح الهجوم __لنواة__ النظام.
المنطق:
- مقالة LWN حول مناقشة LKML المقابلة: https://lwn.net/Articles/673597/
- سلسلة تغريدات حول `CONFIG_USER_NS` والأمان: https://twitter.com/robertswiecki/status/1095447678949953541
- نظرة عامة جيدة على المقايضة بين تمكين مساحات أسماء المستخدمين، وتعطيلها، وجعلها متاحة فقط للجذر: https://github.com/NixOS/nixpkgs/pull/84522#issuecomment-614640601
<br />
__س:__ يوصي كل من KSPP و CLIP OS بـ `CONFIG_PANIC_ON_OOPS=y`. لماذا لا تفعل هذه الأداة الشيء نفسه؟
__ج:__ لا يمكنني دعم هذه التوصية للأسباب التالية:
- إنها تقلل من متانة النظام (لا يزال oops النواة حالة غير نادرة حتى على أنظمة الإنتاج)
- إنها تسمح بهجمات حجب الخدمة (DoS) أسهل للنظام بأكمله
يجب عليك تمكين `CONFIG_PANIC_ON_OOPS` إذا:
- لا تواجه نواتك حالات oops أثناء سير العمل النموذجي
- إعادة التشغيل العرضية ليست مشكلة في حالة الاستخدام الخاصة بك
أرى حلاً وسطًا جيدًا، وهو ما توصي به `kernel-hardening-checker`:
- تمكين خيار التهيئة `CONFIG_BUG`. إذا حدث oops في سياق عملية، فسيتم إنهاء العملية المخالفة/المهاجمة. في حالات أخرى، تتعطل النواة، وهو مشابه لـ `CONFIG_PANIC_ON_OOPS=y`.
- ضبط خيارات sysctl `kernel.oops_limit` و `kernel.warn_limit` إلى `100` على سبيل المثال. من ناحية، هذه القيمة لا تسمح بسهولة بـ DoS. من ناحية أخرى، ليست كبيرة جدًا بحيث تفوت محاولات استغلال الثغرات التي تولد الكثير من تحذيرات النواة أو حالات oops.
<br />
__س:__ لماذا يؤدي تمكين `CONFIG_STATIC_USERMODEHELPER` إلى تعطيل أشياء مختلفة في نظامي GNU/Linux؟
هل أحتاج حقًا إلى هذه الميزة؟
__ج:__ يمكن استخدام مساعدي وضع المستخدم في نواة لينكس لتصعيد الامتيازات في استغلالات النواة
([مثال 1][9], [مثال 2][10]). يمنع `CONFIG_STATIC_USERMODEHELPER` هذه الطريقة. لكنه
يتطلب الدعم المقابل في مساحة المستخدم: انظر [مثال التنفيذ][11] بواسطة
Tycho Andersen [@tych0][12].
<br />
__س:__ ماذا عن تأثير الأداء لميزات تقوية الأمان هذه؟
__ج:__ هذا سؤال ليس سهلاً، لأن تأثير الأداء يعتمد على عبء عمل النظام.
تقييم مفصل لتأثير الأداء لميزات تقوية أمان لينكس موجود
في TODO (القضية [#66][21]). هناك بعض الأعمال المثيرة للاهتمام في هذا المجال:
- أجرى Ike Devolder [@BlackIkeEagle][7] بعض اختبارات الأداء ووصف النتائج في [هذه المقالة][8].
- نشر Fabian Rauscher و Benedict Herzog و Timo Hönig و Daniel Gruss مقالاً
["تحليل منهجي لأداء أمان النواة وتكاليف الطاقة"][28] يصف
الحمل الزائد للطاقة ووقت التشغيل لتخفيفات ثغرات العتاد (CONFIG_CPU_MITIGATIONS).
<br />
__س:__ هل تحتوي نواتي على جميع تلك التخفيفات لثغرات التنفيذ العابرة في عتادي؟
__ج:__ فحص تهيئة النواة لا يكفي للإجابة على هذا السؤال.
أوصي بشدة باستخدام أداة [spectre-meltdown-checker][13] التي يحافظ عليها Stéphane Lesimple [@speed47][14].
<br />
__س:__ هل يمكنني بسهولة التحقق من إصدارات النواة التي تدعم خيار Kconfig معين؟
__ج:__ نعم. انظر مشروع [LKDDb][18] (قاعدة بيانات برامج تشغيل نواة لينكس) بواسطة Giacomo Catenazzi [@cateee][19].
يمكنك استخدامه لشجرة `mainline` أو `stable` من [kernel.org][20] أو لمصادر نواتك المخصصة.
<br />
__س:__ لماذا يتم تعطيل خيار `CONFIG_GCC_PLUGINS` تلقائيًا أثناء تجميع النواة؟
__ج:__ هذا يعني أن gcc لديك لا يدعم الإضافات. على سبيل المثال، إذا كان لديك `gcc-14` على Ubuntu،
حاول تثبيت حزمة `gcc-14-plugin-dev`، يجب أن يساعد ذلك.
[1]: https://kspp.github.io/Recommended_Settings
[2]: https://docs.clip-os.org/clipos/kernel.html#configuration
[3]: https://grsecurity.net/
[4]: https://github.com/a13xp0p0v/linux-kernel-defence-map
[5]: https://lwn.net/Articles/791863/
[6]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/38
[7]: https://github.com/BlackIkeEagle
[8]: https://blog.herecura.eu/blog/2020-05-30-kconfig-hardening-tests/
[9]: https://googleprojectzero.blogspot.com/2018/09/a-cache-invalidation-bug-in-linux.html
[10]: https://a13xp0p0v.github.io/2020/02/15/CVE-2019-18683.html
[11]: https://github.com/tych0/huldufolk
[12]: https://github.com/tych0
[13]: https://github.com/speed47/spectre-meltdown-checker
[14]: https://github.com/speed47
[15]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/53
[16]: https://github.com/a13xp0p0v/kernel-hardening-checker/pull/54
[17]: https://github.com/a13xp0p0v/kernel-hardening-checker/pull/62
[18]: https://cateee.net/lkddb/web-lkddb/
[19]: https://github.com/cateee/lkddb
[20]: https://kernel.org/
[21]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/66
[22]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/56
[23]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues?q=label:kernel_maintainer_feedback
[24]: https://github.com/a13xp0p0v/kernel-hardening-checker#motivation
[25]: https://grapheneos.org/features
[26]: https://github.com/a13xp0p0v/kernel-hardening-checker/graphs/contributors
[27]: https://learn.cisecurity.org/benchmarks
[28]: https://dl.acm.org/doi/epdf/10.1145/3708821.3736197