kernel recompilation for better hardening

Added CI support in git master.

But Travis CI is Ubuntu based. Not sure it is worth the effort making the CI build compatible with Ubuntu. Did run into some issues due to version differences (Linux 4.15 vs 4.19) but now fixed. I don’t know if there is a Debian buster based CI. Inquired just now:

[question] Can this project be used by upstreams? · Issue #62 · lamby/travis.debian.net · GitHub

Otherwise I’d be happy to use any other CI service.

https://travis-ci.com/Whonix/hardened-vm-kernel

The current build hangs.

https://travis-ci.com/Whonix/hardened-vm-kernel/builds/141763417

But this is not a “perfect proof” since running on Ubuntu with older kernel version.

1 Like