Commit Graph

54 Commits

Author SHA1 Message Date
RoyalOughtness
261936654f chore: copy config from upstream and remove dep (#593) 2024-11-21 17:23:06 -08:00
RoyalOughtness
e86816d052 chore: switch to bluebuild's justfile module with validation (#556) 2024-11-11 16:11:37 -08:00
RoyalOughtness
a6025e2c4b breakfix: Revert "feat: audit-secureblue: check for filesystem=host:ro and device=all (#535)" (#550)
This reverts commit d376dd0180.
2024-11-11 11:20:56 -08:00
spaceoden
d376dd0180 feat: audit-secureblue: check for filesystem=host:ro and device=all (#535) 2024-11-11 09:04:12 -08:00
mintpilo
290d1ec895 fix: remove redundant pkexec line in kargs commands (#539)
Co-authored-by: RoyalOughtness <129108030+RoyalOughtness@users.noreply.github.com>
2024-11-10 17:28:25 -05:00
Bruno
29927c2db0 docs: fix dead links, add missing items (#544)
* docs: fix dead links, update descriptions

* docs: more emphasis on "unstable", less on "additional"

* docs: return an original word

* docs: grammar and brevity

* docs: verbosity
2024-11-10 17:23:45 -05:00
RoyalOughtness
d9774b993b fix: audit script breaks without flatpaks present (#520)
* fix: audit script breaks without flatpaks present

* Update 70-secureblue.just
2024-11-03 18:21:30 -08:00
RoyalOughtness
c22504449f fix: misspelling 2024-10-30 23:05:33 -07:00
RoyalOughtness
ea9620f017 fix: typo in just 2024-10-30 23:04:42 -07:00
Root
396afbd7a2 feat: add karg option to disable SMT on any CPU (#502)
* feat: add option to disable SMT in kargs

* fix: improvements

* fix: context

* fix: wording

* fix: wording

* fix: wording

* fix: var name

---------

Co-authored-by: RoyalOughtness <129108030+RoyalOughtness@users.noreply.github.com>
2024-10-30 21:03:16 -07:00
spaceoden
60a5bb4a99 feat: Update 70-secureblue.just to include signed image test in audit script (#498)
Co-authored-by: RoyalOughtness <129108030+RoyalOughtness@users.noreply.github.com>
2024-10-30 21:01:59 -07:00
spaceoden
74867bdc40 feat: Update 70-secureblue.just to include ipc perm check in audit script (#495)
Co-authored-by: RoyalOughtness <129108030+RoyalOughtness@users.noreply.github.com>
2024-10-30 21:01:05 -07:00
RoyalOughtness
750d7bdd70 chore: remove all quotes from kargs for consistency 2024-10-30 20:58:19 -07:00
qoijjj
16ef609a71 fix: quotation clashes in just script 2024-10-26 19:39:04 -07:00
Rubiginosa
2688625ead fix: Add check for sysctl runtime state (#469)
* Add check for sysctl runtime state

* improve variable naming
2024-10-23 14:19:21 -07:00
Rubiginosa
3f240dd334 feat: add check for container policy (#471)
Co-authored-by: qoijjj <129108030+qoijjj@users.noreply.github.com>
2024-10-23 13:55:29 -07:00
mintpilo
58e1c3b07f fix: typo that would cause additional kargs to not be applied, and make read lines look nicer (#473)
So sorry...
2024-10-18 22:15:08 -07:00
mintpilo
0caa1fb436 feat: consolidate kargs scripts, and docs polishing (#457) 2024-10-18 20:00:13 -07:00
qoijjj
7e5a9d49e2 feat: add new karg to audit script 2024-10-17 18:44:35 -07:00
qoijjj
4a73e0ccce fix: missing backslash in ujust command 2024-10-17 18:43:04 -07:00
qoijjj
f0bab7f5b2 feat: nvidia-open images, major streamlining, bugfixes, and polish (#461) 2024-10-17 18:20:58 -07:00
Rubiginosa
f2bd5e84f6 feat: Add blacklist check for currently loaded modules (#440)
* Add blacklist check for currently loaded modules

* Remove redundant bluetooth check

* Correct misuse of SYSCTL test string

* return check for flatpak bluetooth

* fix variable name

* fix array size check
2024-10-09 11:45:07 -07:00
Rubiginosa
59f7b10415 fix: misuse of SYSCTL_TEST_STRING (#442) 2024-10-07 13:18:41 -07:00
Rubiginosa
7ae972e095 feat: Add audit-secureblue checks for flatpak bluetooth and ptrace access (#438)
* Add check for bluetooth and ptrace

* Add check for flatpak bluetooth and ptrace access
2024-10-04 10:18:14 -07:00
Rubiginosa
5deb22e35b feat: Add audit-secureblue check for system bluetooth and ptrace 2024-10-04 10:12:22 -07:00
Rubiginosa
c1ec422eab feat: add check for D-Bus access (#432) 2024-09-28 20:29:13 -07:00
qoijjj
c68039132a fix: add brew justfile due to upstream move 2024-09-20 23:41:28 -07:00
Bruno
66d8b731e6 fix: check for gnome-shell instead of gsettings in one test (#424) 2024-09-11 09:56:52 -07:00
Rubiginosa
8333bcf2f5 feat: add check for hardened_malloc flatpak preload (#412)
* updated has_permission to use regex matching

* added flatpak check for hardened_malloc

* changed hasPermission to maintain old behavior for strings
2024-09-10 10:33:14 -07:00
Rubiginosa
b5f5d2afa0 feat: refactor flatpak audit for readability and extensibility (#414)
* refactored flatpak audit to be more extensible

* fixed old typo

* added warning string array for flatpak audit
2024-08-30 15:28:56 -07:00
Bruno
79471e2141 fix: audit script improvements (GHNS test, order of tests) (#415)
* only test GHNS if kdeglobals exist

* place faster tests before the slower flatpak audit
2024-08-30 13:45:15 -07:00
Bruno
e143c48e26 chore: several audit script improvements 2024-08-29 21:01:40 -07:00
Ivo Damjanović
fefc64baba feat: stop overwriting 60-custom.just for better compatibility with upstream bluebuild and downstream user builds (#409)
* feat: create addjustconfig.sh to include custom commands at buildtime

* fix: 60-custom.just.readme.md to 61-custom.just.readme.md

* fix: Rename 60-custom.just to 61-custom.just

* feat: add just config script to enabled scripts

* fix: rename to 70-secureblue.just

* fix: Rename 61-custom.just.readme.md to 70-secureblue.just.readme.md

* fix: rename to 70-secureblue.just
2024-08-29 11:53:56 -07:00
qoijjj
a329524441 fix: justfile typo 2024-08-26 10:44:49 -07:00
qoijjj
e41d963841 feat: multiple securecore improvements 2024-08-26 09:45:20 -07:00
qoijjj
1b5e539ec2 fix: audit script cleanup 2024-08-22 12:03:22 -07:00
Rubiginosa
51ad84b1ad feat: Add flatpak auditing to audit-secureblue (#377)
* increase spacing on print_status

* Merged audit-flatpak into audit-secureblue

* print flatpak remote success

---------

Co-authored-by: qoijjj <129108030+qoijjj@users.noreply.github.com>
2024-08-21 13:22:11 -07:00
qoijjj
7ff130f248 fix: typo in audit script 2024-08-20 18:43:21 -07:00
qoijjj
38cbf7715a feat: add audit-secureblue just command (#382) 2024-08-20 15:08:18 -07:00
qoijjj
06c2883bb1 fix: improve usbguard just command 2024-08-19 18:21:50 -07:00
qoijjj
3b927dc8ed fix: check only the first string token when searching lsattr 2024-08-10 03:56:35 -07:00
qoijjj
872cb784ef feat: add ujust command to lock bash environment files to mitigate LD… (#365) 2024-08-09 16:14:44 -07:00
fiftydinar
e1a130f6f9 feat: Disable user Gnome extensions & user-installation of them (#361) 2024-08-06 17:14:30 -07:00
qoijjj
f75215cfdf fix: set permissions for xwayland file in ujust command 2024-08-03 12:19:43 -07:00
spaceoden
c21a697252 Update 60-custom.just.readme.md to put new kargs in the correct section (#357)
the new kargs were added to set-kargs-hardening, not set-kargs-hardening-unstable
2024-08-02 13:01:52 -07:00
qoijjj
9f56f2ff06 feat: set additional kargs to override suboptimal defaults 2024-08-01 22:43:23 -07:00
qoijjj
084fe1a40c fix: remove usbguard-dbus due to insufficient systemd sandboxing (#352) 2024-07-31 14:20:49 -07:00
qoijjj
eea350af56 fix: remove comments from harden-flatpak ujust command to fix just parsing 2024-07-30 16:26:34 -07:00
spaceoden
7c0976da7e feat: add to harden-flatpak logic that applies the highest supported hwcap (#346) 2024-07-30 15:31:43 -07:00
qoijjj
298bbda019 fix: ujust command typos 2024-07-30 00:03:25 -07:00