Skip to content

Commit 1472d41

Browse files
authored
Add KSPP partial compliance notice for proc_mem.force_override=ptrace
1 parent 97640a9 commit 1472d41

2 files changed

Lines changed: 14 additions & 4 deletions

File tree

‎README.md‎

Lines changed: 12 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -321,23 +321,32 @@ there are a few cases of partial or non-compliance due to technical limitations.
321321
More than 30 kernel boot parameters and over 30 sysctl settings are fully aligned with
322322
the KSPP's recommendations.
323323

324+
**Partial compliance:**
325+
326+
1. Kernel boot parameter `proc_mem.force_override=never`
327+
328+
Restrict processes from modifying their own memory mappings by completely disables use of
329+
`/proc/PID/mem` to write to protected pages. Can be enabled easily if required.
330+
331+
* [security-misc pull request #332](https://github.com/Kicksecure/security-misc/pull/332)
332+
324333
**Non-compliance:**
325334

326-
1. `sysctl user.max_user_namespaces=0`
335+
2. `sysctl user.max_user_namespaces=0`
327336

328337
Disables user namespaces entirely. Not recommended due to the potential for widespread breakages.
329338

330339
* [security-misc pull request #263](https://github.com/Kicksecure/security-misc/pull/263)
331340

332-
2. `sysctl fs.binfmt_misc.status=0`
341+
3. `sysctl fs.binfmt_misc.status=0`
333342

334343
Disables the registration of interpreters for miscellaneous binary formats. Currently not
335344
feasible due to compatibility issues with Firefox.
336345

337346
* [security-misc pull request #249](https://github.com/Kicksecure/security-misc/pull/249)
338347
* [security-misc issue #267](https://github.com/Kicksecure/security-misc/issues/267)
339348

340-
3. Kernel boot parameter `hash_pointers=always`
349+
4. Kernel boot parameter `hash_pointers=always`
341350

342351
Force all exposed pointers to be hashed and must be used in combination with the already enabled
343352
`slab_debug=FZ` kernel boot parameter. Currently is not possible as requires Linux kernel >= 6.17.

‎etc/default/grub.d/40_kernel_hardening.cfg#security-misc-shared‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -326,7 +326,8 @@ GRUB_CMDLINE_LINUX="$GRUB_CMDLINE_LINUX bdev_allow_write_mounted=0"
326326
## https://github.com/a13xp0p0v/kernel-hardening-checker/pull/201
327327
## https://github.com/Kicksecure/security-misc/issues/330
328328
##
329-
## Using "proc_mem.force_override=never" provides superior protection by never allowing overrides.
329+
## KSPP=partial
330+
## KSPP sets the stricter kernel parameter proc_mem.force_override=never.
330331
##
331332
GRUB_CMDLINE_LINUX="$GRUB_CMDLINE_LINUX proc_mem.force_override=ptrace"
332333

0 commit comments

Comments
 (0)