|MoonBase|™ Project Main Channel. – Telegram
|MoonBase| Project Main Channel.
265 subscribers
1.34K photos
3 videos
157 files
612 links
"Unix-Like-Latino" - Videos On Youtube By JavaShin-X.
Download Telegram
###- "JavaShin-X CustoKernal" "Stable-Release" "4.9.224-jsX R1" -###
Custom Kernel Modified Based On Lineage Os Kernel For The Moto G7 Power Ocean Model : XT1955 = ocean.
Hi Cool People Let Me Introduce Some Of My Efforts I Made To This AndroidKernel.
To Improves Your Experience With This Awesome Phone.
Work Done Based On Experience Haxing Linux Kernel A long The Years , Mostly Patching , Fixing Adding , Modding.
Im Not A Developer Not A Programmer Not A Hacker.
Im Just A Unix/Linux System Administrator - Computer Technician. But We Don't Stop Learning.
Kernel Very Well Tested Never Been An Issue With Any Phone Trusted Code Available On Github.

- 2 Variants = Different Roms :

- GoldenFreezer = -perf_r1+
Roms Tested With This Kernel = LineageOS , SuperiorOS , Pixel Experience , CrDROID.

- MetalCooler = -sec_r1+
Roms Tested With This Kernel = MSM-Extended , AICP , HAVOC-OS , AEX AOSP Extended.

- More Untested Roms.

##-Features-##

* Upgrade Los Kernel Into Caf - MSM Kernel From 4.9.203 To 4.9.224.
* Pre-Tested Using Patches From Kernel.org Stable Queue And TestBuilds -Pre-jsX.
* Upstreamed to 4.9.224 Kernel.org Stable Release.
* Release build have significantly reduced debugging messages/routines for slight performance & battery enhancements.
* Optimize compiler flags with better CPU optimizations.
* Optimize for performance rather than size.
* Higher performance with lower battery usage.
* Various other improvements.
* Added Some Goodies From QuanticKernel Thank To Carlos-Quantic-Master.
* Plus extra Mod patches By JavaShin-X. "-jsX" Compiled With CLANG.
• Ultra low latency.
• SchedUtil Cpu Governor Set To Default.
• Addeded BFQ I/O SCHED. And Set To Default.
• Added 750Hz timer interrupt. And Set To Default.
• Zswap now uses BTREE instead of ZPOOL. And Set To Default.
• Zswap Now Default To Z3fold Lz4 Instead Of ZBUD. * Changed.
• Zmalloc by Default.
• VDSO32 Bits Enabled By Default
• WireGuard VPN.
• Boeffla generic wakelock blocker driver. 1.0.3
• AnyKernel v3 To Retain Magisk Root.
• Disabled GFS to Achieve Better UI Performance.
• BlueTooth Check Key-Sizes Only If Secure Simple Pairing.
• Simple Android Low Memory Killer.
• Enable ZRAM to 3GB and use lz4 as compressor. * Changed.
• Use optimized spinning loop for arm64, this makes about 20% performance improvement on the CPU multithread load.
• Compiled With Last clang-r383902 11.0.1 - May 2020
• Compiled With Last Gcc 9.2.1 ARM32Hf & AARCH64 - From developer.arm.com As CROSS-COMPILERS.
• Specific Aarch64 Arm64 Hexagon Sdm632 optimizations. "-march=armv8-a+fp+simd+crc+crypto"
• Plus ricer optimizations "-O3 -fno-stack-protector -pipe". 🧐
• Many More Changes.
• Fix some compilation issues JavaShin Cracking His HEAD.
• CROSS_COMPILE_ARM32 & CLANG_TRIPLE_ARM32
Changes From Version 4.9.223-jsX TO Current Release on -perf_r1+ and -sec_r1+ . =
- Introducing " _r# " suffix - to identify Builds Of Same Release.
- Enable KSM for page merging.
- ADD UKSM/KSM strategy Ultra-KSM for page merging.
- Zen I/O scheduler - Primarily based on Noop, deadline, and SIO IO schedulers. Thanks To electimon.
- Enable cleancache driver to cache clean pages if tmem is present.
- Enable frontswap to cache swap pages if tmem is present.
- Avoid 100% CPU Usage During Compaction .
- Updated Last WireGuard Backport v1.0.20200506. + Fixed Conflicts.
- Mod Increases number of tasks Sched-Core nr_migrate = 256.
- Mod Readahead Min-Max - address_space-level file pages sizes.
- Add Add JavaShin-X-Intereactive-Kernal-Mods CONFIG_JSX_INTERACTIVO.
- Ainur Eagle DTS software-processed driver for Android. Thanks To electimon.
- MDSS color control KCAL . Thanks To electimon.
- Devfreq - Use high priority workqueue. Thanks To electimon.
- Kgsl - Increase priority of RT thread. Thanks To electimon.
- Run kgsl-workqueue as a high prio wq. Thanks To electimon.
- Workqueue - change permissions to allow root control of wq_power_efficient toggle. Thanks To electimon.
- Zstd Compression Algo Backported.
- Updated Lzo From msm-4.14.
- LZO-RLE Compression Algo Backported.
- Zswap kernel feature that provides a compressed RAM cache for swap pages Using ZSTD Algo&Crypto.
- ZRAM Will See Greater Performance Thanks To Lzo-rle By Default.
- Backport kvmalloc and kvmalloc_node kv[mz]alloc helpers.
- Add - Streebog Crypto Support Developed By Russia's FSB.
* introduced as a cryptographic hash function developed in large part by the Russian government.
- Crypto/compress - add asynchronous compression support Api's.
- Crypto/acomp - add support for lzo via scomp.

* 4.9.224-jsX-sec_r1+ Only =
- Removed Ricer Optimizations Default To -O2 And Enable Stack-Protector Strong And Fortify Source.
- TI DRV2624 haptics support : kang taimen haptics driver And Fix Thanks To electimon & erfan .
- Enhanced Security Configuration. & AndroidHardening-LinuxKernel-Hardened Patches. =
Git Repository = https://github.com/AndroidHardeningArchive/linux-hardened
{#-
0001-enable-HARDENED_USERCOPY-by-default.patch
0002-enable-SECURITY_DMESG_RESTRICT-by-default.patch
0003-set-kptr_restrict-2-by-default.patch
0004-enable-DEBUG_LIST-by-default.patch
0005-enable-BUG_ON_DATA_CORRUPTION-by-default.patch
0006-enable-ARM64_SW_TTBR0_PAN-by-default.patch
0007-arm64-enable-RANDOMIZE_BASE-by-default.patch
0008-enable-SLAB_FREELIST_RANDOM-by-default.patch
0009-enable-SLAB_FREELIST_HARDENED-by-default.patch
0010-disable-SLAB_MERGE_DEFAULT-by-default.patch
0011-enable-REFCOUNT_FULL-by-default.patch
0012-enable-CC_STACKPROTECTOR_STRONG-by-default.patch
0013-enable-FORTIFY_SOURCE-by-default.patch
0014-enable-PANIC_ON_OOPS-by-default.patch
0015-stop-hiding-SLUB_DEBUG-behind-EXPERT.patch
0016-stop-hiding-X86_16BIT-behind-EXPERT.patch
0017-disable-X86_16BIT-by-default.patch
0018-stop-hiding-MODIFY_LDT_SYSCALL-behind-EXPERT.patch
0019-disable-MODIFY_LDT_SYSCALL-by-default.patch
0020-set-LEGACY_VSYSCALL_NONE-by-default.patch
0021-stop-hiding-AIO-behind-EXPERT.patch
0022-disable-AIO-by-default.patch
0023-remove-SYSVIPC-from-arm64-x86_64-defconfigs.patch
0024-disable-DEVPORT-by-default.patch
0025-disable-PROC_VMCORE-by-default.patch
0026-disable-NFS_DEBUG-by-default.patch
0027-enable-DEBUG_WX-by-default.patch
0028-disable-LEGACY_PTYS-by-default.patch
0029-disable-DEVMEM-by-default.patch
0030-enable-STRICT_DEVMEM-by-default-everywhere.patch
0031-enable-IO_STRICT_DEVMEM-by-default.patch
0032-disable-COMPAT_BRK-by-default.patch
0033-use-maximum-supported-mmap-rnd-entropy-by-default.patch
0034-enable-protected_-symlinks-hardlinks-by-default.patch
0035-enable-SECURITY-by-default.patch
0036-enable-SECURITY_YAMA-by-default.patch
0037-enable-SECURITY_NETWORK-by-default.patch
0038-enable-AUDIT-by-default.patch
0039-enable-SECURITY_SELINUX-by-default.patch
0040-enable-SYN_COOKIES-by-default.patch
0041-drivers-media-improve-the-return-type-of-a-bunch-of-.patch
0042-add-__read_only-for-non-init-related-usage.patch
0043-make-sysctl-constants-read-only.patch
0044-mark-kernel_set_to_readonly-as-__ro_after_init.patch
0045-mark-slub-runtime-configuration-as-__ro_after_init.patch
0046-add-__ro_after_init-to-slab_nomerge-and-slab_state.patch
0047-mark-size_index-as-__ro_after_init.patch
0048-mark-kmem_cache-as-__ro_after_init.patch
0049-mark-__supported_pte_mask-as-__ro_after_init.patch
0050-mark-kobj_ns_type_register-as-only-used-for-init.patch
0051-mark-open_softirq-as-only-used-for-init.patch
0052-remove-unused-softirq_action-callback-parameter.patch
0053-mark-softirq_vec-as-__ro_after_init.patch
0054-add-a-SLAB_HARDENED-configuration-option.patch
0055-add-missing-cache_from_obj-PageSlab-check.patch
0056-real-slab_equal_or_root-check-for-MEMCG_KMEM.patch
0057-bug-on-kmem_cache_free-with-the-wrong-cache.patch
0058-always-perform-cache_from_obj-consistency-checks.patch
0059-bug-on-PageSlab-PageCompound-in-ksize.patch
0060-add-simpler-page-sanitization.patch
0061-add-support-for-verifying-page-sanitization.patch
0062-slub-add-basic-full-slab-sanitization.patch
0063-slub-add-support-for-verifying-slab-sanitization.patch
0064-slub-add-multi-purpose-random-canaries.patch
0065-security-perf-Allow-further-restriction-of-perf_even.patch
0066-enable-SECURITY_PERF_EVENTS_RESTRICT-by-default.patch
0067-add-sysctl-to-disallow-unprivileged-CLONE_NEWUSER-by.patch
0068-add-kmalloc-krealloc-alloc_size-attributes.patch
0069-add-vmalloc-alloc_size-attributes.patch
0070-add-kvmalloc-alloc_size-attribute.patch
0071-add-percpu-alloc_size-attributes.patch
0072-add-alloc_pages_exact-alloc_size-attributes.patch
0073-Add-the-extra_latent_entropy-kernel-parameter.patch
0074-ata-avoid-null-pointer-dereference-on-bug.patch
0075-sanity-check-for-negative-length-in-nla_memcpy.patch
0076-add-page-destructor-sanity-check.patch
0077-PaX-shadow-cr4-sanity-check-essentially-a-revert.patch
0078-add-writable-function-pointer-detection.patch
0079-support-overriding-early-audit-kernel-cmdline.patch
0080-FORTIFY_SOURCE-intra-object-overflow-checking.patch
0081-Revert-mm-revert-x86_64-and-arm64-ELF_ET_DYN_BASE-ba.patch
0082-x86_64-move-vdso-to-mmap-region-from-stack-region.patch
0083-x86-determine-stack-entropy-based-on-mmap-entropy.patch
0084-arm64-determine-stack-entropy-based-on-mmap-entropy.patch
0085-randomize-lower-bits-of-the-argument-block.patch
0086-x86_64-match-arm64-brk-randomization-entropy.patch
0087-support-randomizing-the-lower-bits-of-brk.patch
0088-arm64-randomize-lower-bits-of-brk.patch
0089-x86-randomize-lower-bits-of-brk.patch
0090-arm64-guarantee-brk-gap-is-at-least-one-page.patch
0091-x86-guarantee-brk-gap-is-at-least-one-page.patch
0092-x86_64-bound-mmap-between-legacy-modern-bases.patch
0093-security-tty-Add-owner-user-namespace-to-tty_struct.patch
0094-security-tty-make-TIOCSTI-ioctl-require-CAP_SYS_ADMI.patch
0095-enable-SECURITY_TIOCSTI_RESTRICT-by-default.patch
0096-restrict-device-timing-side-channels.patch
0097-add-toggle-for-disabling-newly-added-USB-devices.patch
0098-wire-up-fsanitize-local-init.patch
0099-hard-wire-legacy-checkreqprot-option-to-0.patch
0100-regulatory-add-NUL-to-request-alpha2.patch
0101-disable-unprivileged-eBPF-access-by-default.patch
0102-enable-BPF-JIT-hardening-by-default-if-available.patch
#-}

##- Please give feedback. A lot of work has been done to get here. -##

* Disclaimer ===
"Not Responsible For Any Kind Of Damage To Any Device"
"Use At Your Own Risk , No Warranty Included , If Brick Well It Bricks In The Name Of Science Don't Blame ME"
"If You Got Here Is For A Reason , Meaning You Already Know What Are You Doing With Your Phone"
"Meaning That You Already Void OEM Warranty"
" And There Is No Turning Back Starting When You Typed = fastboot oem unlock + key "


* Instructions :
Always retain a backup of your current kernel and system image. Before Flashing.
After Set Everything Up - Working System Custom Rom With Recovery & Magisk Root.
Then Just Need To Reboot To Recovery Via Advanced Reboot Power Menu Or "adb reboot recovery"
Or Starting Phone In Bootloader Mode Selecting Recovery From Menu Using Vol - And Power.

LIneageOS BASED = Sources Tree Branch "-jsX-Mod"
https://github.com/javashin/android_...e-17.1-jsX-mod

Tested On :
LineageOS & SuperiorOS & Bootleggers & PixelEX & MSM-Ex & CrDROID ROMS. 4 OCEAN.

Thanks To : Moto G7 Power Community .
electimon , Barry Allen , TailanCunha , Dan Ford , David Rondeau , steve , gabi , Deivid , Francisco.
Testers : Wolfseth , Rey Castagnoli , D Silva.

Credits :
erfanoabdi for Provide the lineageos-17.1 kernel source tree 4 moto g7 power ocean.
Carlos Ayrton For His Quantic Mods.

@everyone Who Has Tried My Kernal.

Flasheable Kernal Zip On Attachments.

##- Enjoy - Cheers ! -##

Carlos Jimenez = NickName =
JavaShin-X WrongDevice =
Ozmage JavaShin-X Fork.
Dominican Republic - Wed May 20 2020.
OCEAN_LOS_4_9_224_jsX_perf_r1+_AKA_GoldenFreezer_20_MAY_2020_LineageOS.zip
13.8 MB
-Perf+ AKA GoldenFreezer Performance Kernel Mode 4.9.224-jsX-perf_r1+ 🥶
OCEAN_LOS_4_9_224_jsX_sec_r1+_AKA_MetalCooler_ANDROIDHARDEN_20_MAY.zip
13.5 MB
-Sec+ AKA MetalCoolerAndroidHardened Kernel 4.9.224-jsX-sec_r1+ 🥶
JavaShin-X Custo Kernal Mods For Kernel Stable Release 5.6.14.

linux-5.6.14-ck-jsX_r1-Performance-Turbo-Mode

##-@{
Hello I Like To Share My Release Of My Custom Kernel Mods Patches.
For Linux Distros Running On Laptops And Desktops With Intel CPU's.
This Kernel Mod Is One Of The Best I Made So Far Kernel Uses My
Experimental But Stable As HEll Branch Based on linux-lucjan Sources Mods Patches.
}@-##

* Here Is The URL OF The Base Patches. = >
https://github.com/sirlucjan/linux-lucjan

* Which Include This List Of Good Stuff. :: >>

- bfq improvements - latest fixes authored by Paolo Valente and BFQ Team.
- bfq-dev - latest fixes authored by Paolo Valente and BFQ Team.
- bfq-lucjan-dev - latest fixes authored by Paolo Valente and BFQ Team and forked by Piotr Gorski.
- graysky's GCC patch - version for gcc 9.1 - 10.1
- random fixes from zen-kernel - specific patches authored by Jan Alexander Steffens and ZEN Kernel Team.
- random fixes from pfkernel / random fixes from pfkernel - for example patches from Arch Linux or specific patches authored by Oleksandr Natalenko.
- fixes from ClearLinux - specific patches authored by ClearLinux Team.
- AUFS / AUFS - advanced multi-layered unification filesystem.
- UKSM (sources) / UKSM (info) - resync from dolohow’s github.
- LL-patches / LL-patches - specific patches authored by Piotr Gorski.
- LL-branding / LL-branding - specific patches authored by Piotr Gorski.

* This Kernel Patches Also Include This List Of Great Stuff. :: >>
- Zstd Algorithm Compression For -Kernel- -Intrd/Initramfs- -Modules-.
- Note: Modules Compressed With Zstd Needs Patched Kmod On UserSpace.
- New FSGSBASE Intel v12.
- Turbosched-v5. For Acpi-Freq And SchedUtil Cpu Governor.
- zswap ZPOOL Replaced With BTREE.
- FPU ZFS Friendly Fix.
- OPENZFS (ZfsOnLinux) Built-in Injected In Kernel To Be Able To Compile as Module Or Inside Kernel Modless.
- More Intel Dev's Optimizations.
- Oracle KTask for in-kernel multi-threading for CPU intensive tasks.
- Linux Efi Stub Boot Fast Thanks To Zstd And PADATA Patches.
- O3 Level Optimizations For Gcc & Clang Compilers. Gcc 10.1 Recommended To Use Compile Script Bundle In Patch.
- Gentoo Linux Specific Patches.
- OpenZFS 3x Throughput Boost For ZVOL Sync Write Performance.
- Revert BMQ CPU SCHED. Default to MuQSS Now.
- linux-5.6-ck2, MuQSS version 0.2 for linux-5.6.
- PCI/ASPM: Allow ASPM on links to PCIe-to-PCI/PCI-X Bridges.
* Detailed Info = https://www.phoronix.com/scan.php?page=news_item&px=Linux-5.8-ASPM-PCIe-PCI-PCI-X
- fuse: optimize writepages search.
* Detailed Info = https://www.phoronix.com/scan.php?page=news_item&px=Linux-5.8-Faster-FUSE-Writes
- Intel P-state driver initializing Passive mode enabled Uses Schedutil By Default.
- JavaShin-X Fixes Conflicts And Merges Cherry-Pickings ETC.

JavaShin-X . Thursday, May-21-2020

* 0001-JavaShin-X-Mods-Perf-On-Top-Of-Kernel-5.6.14-Vanilla.patch.zst
- md5sum = b8a9bf9012950ea30fe5af080f398aec
- sha256sum = f34d5081e256a2ca0ceb4522d035e086704f093af81619d7d7dde596305f3f78
* 0001-JavaShin-X-Mods-Perf-On-Top-Of-Kernel-5.6.14-Vanilla.patch.zst
* Links :: = >
- MEGA = https://mega.nz/file/dktDARJK#s7cPNNFEU0_2Gidx4v-BVwJKuRWbnFs9xvyEloskKpg
- Gdrive = https://drive.google.com/file/d/1dIrdp9r3JedxgQXwomBv4noHX3FwbmBb/view?usp=sharing



Unpack.
"zstd -d 0001-JavaShin-X-Mods-Perf-On-Top-Of-Kernel-5.6.14-Vanilla.patch.zst"
0001-JavaShin-X-Mods-Perf-On-Top-Of-Kernel-5.6.14-Vanilla.patch.zst: 16901286 bytes
Apply On Top Kernel 5.6.14.
"patch -p1 -i *.patch"
Inside Kernel Dir.
0001_JavaShin_X_Mods_Perf_Sec_On_Top_Of_Kernel_5_6_14_Van_patch.zst
2.2 MB
For The Paranoid JavaShin-X Mod Kernel Perf+Sec Mix Kernel Extra Secure Linux-Hardened Patch.
0001-make-DEFAULT_MMAP_MIN_ADDR-match-LSM_MMAP_MIN_ADDR.patch
0002-enable-HARDENED_USERCOPY-by-default.patch
0003-disable-HARDENED_USERCOPY_FALLBACK-by-default.patch
0004-enable-SECURITY_DMESG_RESTRICT-by-default.patch
0005-set-kptr_restrict-2-by-default.patch
0006-enable-DEBUG_LIST-by-default.patch
0007-enable-BUG_ON_DATA_CORRUPTION-by-default.patch
0008-enable-ARM64_SW_TTBR0_PAN-by-default.patch
0009-arm64-enable-RANDOMIZE_BASE-by-default.patch
0010-enable-SLAB_FREELIST_RANDOM-by-default.patch
0011-enable-SLAB_FREELIST_HARDENED-by-default.patch
0012-disable-SLAB_MERGE_DEFAULT-by-default.patch
0013-enable-FORTIFY_SOURCE-by-default.patch
0014-enable-PANIC_ON_OOPS-by-default.patch
0015-stop-hiding-SLUB_DEBUG-behind-EXPERT.patch
0016-stop-hiding-X86_16BIT-behind-EXPERT.patch
0017-disable-X86_16BIT-by-default.patch
0018-stop-hiding-MODIFY_LDT_SYSCALL-behind-EXPERT.patch
0019-disable-MODIFY_LDT_SYSCALL-by-default.patch
0020-set-LEGACY_VSYSCALL_NONE-by-default.patch
0021-stop-hiding-AIO-behind-EXPERT.patch
0022-disable-AIO-by-default.patch
0023-remove-SYSVIPC-from-arm64-x86_64-defconfigs.patch
0024-disable-DEVPORT-by-default.patch
0025-disable-PROC_VMCORE-by-default.patch
0026-disable-NFS_DEBUG-by-default.patch
0027-enable-DEBUG_WX-by-default.patch
0028-disable-LEGACY_PTYS-by-default.patch
0029-disable-DEVMEM-by-default.patch
0030-enable-IO_STRICT_DEVMEM-by-default.patch
0031-disable-COMPAT_BRK-by-default.patch
0032-use-maximum-supported-mmap-rnd-entropy-by-default.patch
0033-enable-protected_-symlinks-hardlinks-by-default.patch
0034-enable-SECURITY-by-default.patch
0035-enable-SECURITY_YAMA-by-default.patch
0036-enable-SECURITY_NETWORK-by-default.patch
0037-enable-AUDIT-by-default.patch
0038-enable-SECURITY_SELINUX-by-default.patch
0039-enable-SYN_COOKIES-by-default.patch
0040-add-__read_only-for-non-init-related-usage.patch
0041-make-sysctl-constants-read-only.patch
0042-mark-kernel_set_to_readonly-as-__ro_after_init.patch
0043-mark-slub-runtime-configuration-as-__ro_after_init.patch
0044-add-__ro_after_init-to-slab_nomerge-and-slab_state.patch
0045-mark-kmem_cache-as-__ro_after_init.patch
0046-mark-__supported_pte_mask-as-__ro_after_init.patch
0047-mark-kobj_ns_type_register-as-only-used-for-init.patch
0048-mark-open_softirq-as-only-used-for-init.patch
0049-remove-unused-softirq_action-callback-parameter.patch
0050-mark-softirq_vec-as-__ro_after_init.patch
0051-mm-slab-trigger-BUG-if-requested-object-is-not-a-sla.patch
0052-bug-on-kmem_cache_free-with-the-wrong-cache.patch
0053-bug-on-PageSlab-PageCompound-in-ksize.patch
0054-mm-add-support-for-verifying-page-sanitization.patch
0055-slub-Extend-init_on_free-to-slab-caches-with-constru.patch
0056-slub-Add-support-for-verifying-slab-sanitization.patch
0057-slub-add-multi-purpose-random-canaries.patch
0058-security-perf-Allow-further-restriction-of-perf_even.patch
0059-enable-SECURITY_PERF_EVENTS_RESTRICT-by-default.patch
0060-add-sysctl-to-disallow-unprivileged-CLONE_NEWUSER-by.patch
0061-add-kmalloc-krealloc-alloc_size-attributes.patch
0062-add-vmalloc-alloc_size-attributes.patch
0063-add-kvmalloc-alloc_size-attribute.patch
0064-add-percpu-alloc_size-attributes.patch
0065-add-alloc_pages_exact-alloc_size-attributes.patch
0066-Add-the-extra_latent_entropy-kernel-parameter.patch
0067-ata-avoid-null-pointer-dereference-on-bug.patch
0068-sanity-check-for-negative-length-in-nla_memcpy.patch
0069-add-page-destructor-sanity-check.patch
0070-PaX-shadow-cr4-sanity-check-essentially-a-revert.patch
0071-add-writable-function-pointer-detection.patch
0072-support-overriding-early-audit-kernel-cmdline.patch
0073-FORTIFY_SOURCE-intra-object-overflow-checking.patch
0074-Revert-mm-revert-x86_64-and-arm64-ELF_ET_DYN_BASE-ba.patch
0075-x86_64-move-vdso-to-mmap-region-from-stack-region.patch
0076-x86-determine-stack-entropy-based-on-mmap-entropy.patch
0077-arm64-determine-stack-entropy-based-on-mmap-entropy.patch
0078-randomize-lower-bits-of-the-argument-block.patch
0079-x86_64-match-arm64-brk-randomization-entropy.patch
0080-support-randomizing-the-lower-bits-of-brk.patch
0081-mm-randomize-lower-bits-of-brk.patch
0082-x86-randomize-lower-bits-of-brk.patch
0083-mm-guarantee-brk-gap-is-at-least-one-page.patch
0084-x86-guarantee-brk-gap-is-at-least-one-page.patch
0085-x86_64-bound-mmap-between-legacy-modern-bases.patch
0086-restrict-device-timing-side-channels.patch
0087-add-toggle-for-disabling-newly-added-USB-devices.patch
0088-hard-wire-legacy-checkreqprot-option-to-0.patch
0089-security-tty-Add-owner-user-namespace-to-tty_struct.patch
0090-security-tty-make-TIOCSTI-ioctl-require-CAP_SYS_ADMI.patch
0091-enable-SECURITY_TIOCSTI_RESTRICT-by-default.patch
0092-disable-unprivileged-eBPF-access-by-default.patch
0093-enable-BPF-JIT-hardening-by-default-if-available.patch
0094-enable-protected_-fifos-regular-by-default.patch
0095-Revert-mark-kernel_set_to_readonly-as-__ro_after_ini.patch
0096-modpost-Add-CONFIG_DEBUG_WRITABLE_FUNCTION_POINTERS_.patch
0097-mm-Fix-extra_latent_entropy.patch
0098-add-CONFIG-for-unprivileged_userns_clone.patch
0099-enable-INIT_ON_ALLOC_DEFAULT_ON-by-default.patch
0100-enable-INIT_ON_FREE_DEFAULT_ON-by-default.patch
0101-add-CONFIG-for-unprivileged_userfaultfd.patch
0102-slub-Extend-init_on_alloc-to-slab-caches-with-constr.patch
0103-net-tcp-add-option-to-disable-TCP-simultaneous-conne.patch
Forwarded from Deleted Account
Forwarded from Deleted Account