Which kernel evidence is published today
Subject: Root Lock by HeartSuite kernel evidence
Fielded 6.18 pin: 6.18.9-hs / packaging 6.18.9-HeartSuite-3 / build #37
Legacy stream: kernel 5.19.6 (maintenance-only; see Kernel Support Policy)
Summary
| Stream | Role | Config SHA-256 | Evidence pack | Comparison matrix | Checker run | Runtime verification |
|---|---|---|---|---|---|---|
| 6.18.9-hs #37 | Fielded pin / new deployments | 3cd18247… in pack | Published | Published | 2026-08-18 (e870d01) | 2026-08-18 (Debian 12 guest) |
| 5.19.6 | Legacy / existing fleets | Published | Published | Published | 2026-05-19 (b9b83a0) | 2026-05-19 (Debian 12 VM) |
The two lines do not share the same kernel config. 5.19.6 compiled out BPF/FUSE/OVERLAY/USER_NS/AppArmor/TOMOYO. Fielded 6.18.9-hs #37 compiles those in. Treat 5.19.6 scores as legacy, not as a substitute for 6.18.9-hs.
What is published today (6.18.9-hs #37)
- Identity — uname
6.18.9-hs,file#37, vmlinuz SHA-2561b44fffb…, pin config SHA-2563cd18247…inevidence-pack-6.18.9.txt - Automated scores — checker
e870d01: overall 148/259 (57.1%), attack-surface 57/131 (43.5%), exploit-resistance 78/110 (70.9%) - Runtime — Debian 12 guest: 74 modules loaded, 4190
.ko.xz, LSMlockdown,capability,landlock,yama,apparmor,tomoyo,bpf,ipe,ima,evm, Root Lock activate at t+4s - Buyer and auditor summaries — Procurement Brief and Threat model now follow this pack
Known limits of this publication
- Era-matched Arch linux-hardened 6.18.16-hardened1 and vanilla 6.18.9
defconfigare in the pack. - Guest
/boot/config-6.18.9-hsis an 11-line RD stub.CONFIG_IKCONFIGis off. Analysis uses the pin payload config whose SHA matchesVERSION_MAP. - This is the fielded pin, including
IO_URING=y,KEXEC=y,KEXEC_FILE=y. It is not a derived unpublished hardening cut.
What remains from 5.19.6
The 5.19.6 pack is unchanged and still reproducible (checker b9b83a0, SHA d67caa6… / fa227f1d…). Do not add 5.19.6 percentages to a 6.18.9-hs deployment report.
Evidence parity roadmap
| Milestone | Status |
|---|---|
| 6.18.9-hs #37 pin SHA + checker + runtime pack | Done (2026-08-18) |
| Auditor / procurement / 6.18 matrix refresh from that pack | Done (2026-08-18) |
| Era-matched Arch linux-hardened 6.18.16 row | Done (2026-08-18) |
Era-matched vanilla 6.18.9 defconfig | Done (2026-08-18) |
/boot/config-* matching the pin (stop shipping the RD stub as config-6.18.9-hs) | Open — installer/product |
| Derived cut with IO_URING/KEXEC/BPF compiled out | Not this pin — do not advertise as shipped |
For procurement and audit teams
Evaluating a 6.18.9-hs deployment today
- Use
evidence-pack-6.18.9.txtand Threat model. - Confirm
uname -ris6.18.9-hsandfileon vmlinuz contains#37. Absence of the wordHeartSuitedoes not mean the maintenance kernel. - Do not close BPF/FUSE/io_uring scanner findings as compiled-out on this pin.
Evaluating a 5.19.6 legacy fleet
- Use
evidence-pack-5.19.6.txt. Plan migration per the support policy.
Related pages
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.