All of lore.kernel.org
 help / color / mirror / Atom feed
* [kernel-hardening] Introduction
@ 2015-12-17 23:34 Leibowitz, Michael
  2015-12-18  0:36 ` Kees Cook
  0 siblings, 1 reply; 29+ messages in thread
From: Leibowitz, Michael @ 2015-12-17 23:34 UTC (permalink / raw)
  To: kernel-hardening

Hi,

I work in Intel's Open Source Technology center, along with my
colleague, Elena Reshetova.  I'm reasonably new real-life kernel
development, having previously just mucked about.  Otherwise, I'm a
long-time open source/security trouble maker.

I'm Interested in working on struct randomization ala RANDSTRUCT.
Does this seem like a suitable task?

Also, what is the envisioned working model?  Is there a hardening tree
to use?  Should we start with sending patches to this list?  Is there
a hardening maintainer?

Cheers

-- 
Michael Leibowitz

^ permalink raw reply	[flat|nested] 29+ messages in thread
* [kernel-hardening] Introduction
@ 2017-01-12 15:06 park jinbum
  2017-01-12 16:06 ` Mark Rutland
  0 siblings, 1 reply; 29+ messages in thread
From: park jinbum @ 2017-01-12 15:06 UTC (permalink / raw)
  To: kernel-hardening

Hello All,

I'd like to contribute to kernel self protection project.
I've experienced ARM kernel, security solution on production.
(kernel memory protection, contents protection, ...)

I'm interested in following topics.
- Move kernel stack to vmap area (done on x86, other archs still need it)
- KASLR for ARM
- protect ARM vector table as fixed-location kernel target
- expand use of __ro_after_init, especially in arch/arm64

I'm still a kernel newbie,  so they can be too much for me.
If there is something easier and smaller to do, that is good for me.

^ permalink raw reply	[flat|nested] 29+ messages in thread
* [kernel-hardening] Introduction
@ 2017-01-24  0:06 Jessica Frazelle
  2017-01-25 19:37 ` Kees Cook
  0 siblings, 1 reply; 29+ messages in thread
From: Jessica Frazelle @ 2017-01-24  0:06 UTC (permalink / raw)
  To: kernel-hardening

I've been lurking on this mailing list for over a year now, so I think
I understand the gist of how it works. I am looking for some ways to
help out in my free time.

The subsystems I know the most about are cgroups and namespaces. I
previously was a maintainer of Docker (I added the seccomp integration
and maintained the AppArmor bits) and now I work on kubernetes.

Let me know if you think there is a good place to start!

Thanks,
Jess

^ permalink raw reply	[flat|nested] 29+ messages in thread

end of thread, other threads:[~2017-01-30 20:02 UTC | newest]

Thread overview: 29+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-12-17 23:34 [kernel-hardening] Introduction Leibowitz, Michael
2015-12-18  0:36 ` Kees Cook
2015-12-18  0:48   ` Daniel Micay
2015-12-18 16:54     ` Schaufler, Casey
2015-12-18 21:11       ` Kees Cook
2015-12-18  1:00   ` Solar Designer
2015-12-18  2:42   ` David Windsor
  -- strict thread matches above, loose matches on Subject: below --
2017-01-12 15:06 park jinbum
2017-01-12 16:06 ` Mark Rutland
2017-01-13  8:23   ` AKASHI, Takahiro
2017-01-13 17:54     ` Kees Cook
2017-01-13 18:51       ` PaX Team
2017-01-13 19:06         ` Kees Cook
2017-01-13 19:26           ` Kees Cook
2017-01-13 20:38             ` Kees Cook
2017-01-13 23:09             ` PaX Team
2017-01-13 23:15               ` Kees Cook
2017-01-14 10:10                 ` PaX Team
2017-01-17 17:32                   ` Kees Cook
2017-01-17 18:43                     ` PaX Team
2017-01-13 20:35           ` PaX Team
2017-01-13 21:57           ` Daniel Micay
2017-01-13 22:04             ` Kees Cook
2017-01-24  0:06 Jessica Frazelle
2017-01-25 19:37 ` Kees Cook
2017-01-26  4:12   ` Jessica Frazelle
2017-01-26 21:42     ` Kees Cook
2017-01-27 19:14       ` Jessica Frazelle
2017-01-30 20:02         ` Kees Cook

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.