Repository navigation
Conversation
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
Signed-off-by: Levente Polyak <levente@leventepolyak.net>
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
It can make sense to disable this to reduce attack surface / complexity.
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
Signed-off-by: Daniel Micay <danielmicay@gmail.com>
With 46c7dd5 ("modpost: always show verbose warning for section mismatch"), sec_mismatch_verbose was removed which would have printed errors for all writable function pointers during compilation if it hadn't been "#if 0"ed out for quite some time now. Let's introduce a new DEBUG_WRITABLE_FUNCTION_POINTERS_VERBOSE Kconfig option to cleanly control this linux-hardened functionality. Signed-off-by: Thibaut Sautereau <thibaut.sautereau@ssi.gouv.fr> Signed-off-by: Levente Polyak <levente@leventepolyak.net>
Commit a9cd410 ("mm/page_alloc.c: memory hotplug: free pages as higher order") changed `static void __init __free_pages_boot_core()` into `void __free_pages_core()`, causing the following section mismatch warning at compile time: WARNING: vmlinux.o(.text+0x180fe4): Section mismatch in reference from the function __free_pages_core() to the variable .meminit.data:extra_latent_entropy The function __free_pages_core() references the variable __meminitdata extra_latent_entropy. This is often because __free_pages_core lacks a __meminitdata annotation or the annotation of extra_latent_entropy is wrong. This commit is an attempt at fixing this issue. I'm not sure it's OK as we are accessing pages that are still managed by the memblock allocator. The prefetching part is not an issue as it only affects struct pages. Signed-off-by: Thibaut Sautereau <thibaut.sautereau@ssi.gouv.fr> [levente@leventepolyak.net: most of core MM initialization moved to mm/mm_init.c] Signed-off-by: Levente Polyak <levente@leventepolyak.net> [nicolas.bouchinet@ssi.gouv.fr: MAX_ORDER has been renamed to MAX_PAGE_ORDER (see 5e0a760)] Signed-off-by: Nicolas Bouchinet <nicolas.bouchinet@ssi.gouv.fr>
This has required some rework during the port to 5.13, due to da844b7 ("kasan, mm: integrate slab init_on_alloc with HW_TAGS"), and the patch is actually quite simpler now since we do not need to unpoison objects anymore. Signed-off-by: Levente Polyak <levente@leventepolyak.net> Signed-off-by: Thibaut Sautereau <thibaut.sautereau@ssi.gouv.fr> [nicolas.bouchinet@ssi.gouv.fr: pre/post-alloc hooks moved from mm/slab.h to mm/slub.c (see 6011be5)] Signed-off-by: Nicolas Bouchinet <nicolas.bouchinet@ssi.gouv.fr>
This is modified from Brad Spengler/PaX Team's code in the last public patch of grsecurity/PaX based on my understanding of the code. Changes or omissions from the original code are mine and don't reflect the original grsecurity/PaX code. TCP simultaneous connect adds a weakness in Linux's implementation of TCP that allows two clients to connect to each other without either entering a listening state. The weakness allows an attacker to easily prevent a client from connecting to a known server provided the source port for the connection is guessed correctly. As the weakness could be used to prevent an antivirus or IPS from fetching updates, or prevent an SSL gateway from fetching a CRL, it should be eliminated. This creates a net.ipv4.tcp_simult_connect sysctl that when disabled, disables TCP simultaneous connect. Reviewed-by: Thibaut Sautereau <thibaut.sautereau@ssi.gouv.fr> Reviewed-by: Levente Polyak <levente@leventepolyak.net> Signed-off-by: Levente Polyak <levente@leventepolyak.net>
When disabled, unprivileged users will not be able to create new overlayfs mounts. This cuts the attack surface if no unprivileged user namespace mounts are required like for running rootless containers. Signed-off-by: Levente Polyak <levente@leventepolyak.net>
Trigger BUG when kfence encounters data corruption of kfence managed objects. This allows a finer-grained control instead of globally enabling panic_on_warn. Signed-off-by: Levente Polyak <levente@leventepolyak.net>
Before commit d0fe47c ("slub: add back check for free nonslab objects"), freeing a non-slab object used to trigger a BUG if CONFIG_DEBUG_VM was enabled. Now it only warns, which I think is not enough for such a memory corruption. Let's restore the previous behaviour, but tie it to CONFIG_BUG_ON_DATA_CORRUPTION as suggested by Levente. After page folios were introduced in v5.17, this patch was adapted to trigger a bug when the order of the folio is zero instead of when the page is not a compound page, which is not equivalent but respects the semantics of the conversion to page folios and follows the change made to the WARN_ON_ONCE beneath. Suggested-by: Levente Polyak <levente@leventepolyak.net> Signed-off-by: Thibaut Sautereau <thibaut.sautereau@ssi.gouv.fr> [nicolas.bouchinet@ssi.gouv.fr: kfree moved from mm/slab_common.c to mm/slub.c (see b774d3e)] Signed-off-by: Nicolas Bouchinet <nicolas.bouchinet@ssi.gouv.fr>
This forces processes to have `CAP_SYS_ADMIN` in order to use io_uring or to be in the io_uring_group. The patch alter the sysctl value range in order that once set to "2" it can't be lowered again. The io_uring_group sysctl option is set to -1 by default, user should define a proper group and set the sysctl properly if they want it configured. Signed-off-by: Nicolas Bouchinet <nicolas.bouchinet@ssi.gouv.fr>
Note: To upstream Signed-off-by: Nicolas Bouchinet <nicolas.bouchinet@ssi.gouv.fr>
Signed-off-by: Levente Polyak <levente@leventepolyak.net>
|
Only one PR for this feature please. |
anthraxx
force-pushed
the
6.12
branch
5 times, most recently
from
August 8, 2026 09:48
2061efe to
190bddb
Compare
anthraxx
force-pushed
the
6.12
branch
5 times, most recently
from
September 8, 2026 21:52
ca72940 to
21c65ce
Compare
anthraxx
force-pushed
the
6.12
branch
2 times, most recently
from
September 23, 2026 23:40
d9ec3d0 to
98dd31d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This small patch allows processes with specific effective or supplementary gid (beside those with CAP_SYS_ADMIN) to create user namespaces. It is analogous behaviour to /proc/ visibility when /proc is mounted with
gid' andhidepid' options. Gid can be set via kernel.unprivileged_userns_clone knob so as not to introduce unnecessary additional sysctls. The meaning of currently accepted values 0 and 1 doesn't change. Any higher value specifies a gid of privileged user's group.