From 7af4586067f8f0aa8b4be095d4d0e108265c17a9 Mon Sep 17 00:00:00 2001 From: Alexander Popov Date: Fri, 23 Aug 2019 19:09:36 +0300 Subject: [PATCH] Introduce the versioning At the Chaos Communication Camp 2019 @jelly told that it would be nice to add the kconfig-hardened-check to Arch Linux. So I add versioning to make it happen. Thanks @jelly, nice to meet you! --- README.md | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 8ffaeb1..d8a43a6 100644 --- a/README.md +++ b/README.md @@ -176,8 +176,18 @@ CONFIG_ARCH_MMAP_RND_BITS | 32 | clipos |userspace_prot [+] config check is finished: 'OK' - 50 / 'FAIL' - 70 ``` +## kconfig-hardened-check versioning -### Questions and answers +I usually update the kernel hardening recommendations after each Linux kernel release. + +So the version of `kconfig-hardened-check` is associated with the corresponding version of the kernel. + +The version format is: __[major_number].[kernel_version]__ + +The current version of `kconfig-hardened-check` is __0.5.2__, it's marked with the git tag. + + +## Questions and answers __Q:__ How disabling `CONFIG_USER_NS` cuts the attack surface? It's needed for containers! -- 2.31.1