<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>A smaller kernel, not a thicker agent on Root Lock by HeartSuite</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/</link><description>Recent content in A smaller kernel, not a thicker agent on Root Lock by HeartSuite</description><generator>Hugo</generator><language>en</language><atom:link href="https://heartsecsuite.com/rootlock/kernel-hardening/index.xml" rel="self" type="application/rss+xml"/><item><title>Kernel hardening in one comparison table</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/procurement-brief/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://heartsecsuite.com/rootlock/kernel-hardening/procurement-brief/</guid><description>&lt;p&gt;&lt;strong&gt;Overview&lt;/strong&gt;: Side-by-side comparison of Root Lock by HeartSuite kernel configuration choices against community hardened kernels and the KSPP benchmark.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Fielded &lt;strong&gt;6.18.9-hs&lt;/strong&gt; (packaging &lt;code&gt;6.18.9-HeartSuite-3&lt;/code&gt;, build &lt;strong&gt;#37&lt;/strong&gt;). &lt;strong&gt;5.19.6&lt;/strong&gt; is the legacy measured stream.&lt;br&gt;
&lt;strong&gt;Evidence:&lt;/strong&gt; &lt;a href="../evidence-pack-6.18.9.txt"&gt;&lt;code&gt;evidence-pack-6.18.9.txt&lt;/code&gt;&lt;/a&gt; (2026-08-18, checker &lt;code&gt;e870d01&lt;/code&gt;). Legacy: &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/kernel-comparison-matrix-5.19.6/"&gt;5.19.6 matrix&lt;/a&gt;, &lt;a href="../evidence-pack-5.19.6.txt"&gt;&lt;code&gt;evidence-pack-5.19.6.txt&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For deployment, Secure Boot, fleet, and “no custom kernel” alternatives see the &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/enterprise-adoption-guide/"&gt;Enterprise Adoption Guide&lt;/a&gt;. Support and scanner notes: &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/kernel-support-policy/"&gt;Kernel Support Policy&lt;/a&gt;, &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/distro-compatibility-matrix/"&gt;Distro Compatibility Matrix&lt;/a&gt;, &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/cve-hygiene-for-scanners/"&gt;CVE Hygiene for Scanners&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="what-this-document-covers"&gt;What this document covers&lt;a class="td-heading-self-link" href="#what-this-document-covers" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;All numbers below are outputs of &lt;code&gt;kernel-hardening-checker&lt;/code&gt; commit &lt;code&gt;e870d0141259f875d3d1b54fef49dec7074e4cac&lt;/code&gt; applied to the &lt;strong&gt;#37 pin config&lt;/strong&gt; (SHA-256 &lt;code&gt;3cd1824742b9a15e9467c774c5f62081f9547f730ad7cd9bce464a7d286a7db9&lt;/code&gt;) and to configs bundled with that checker.&lt;/p&gt;</description></item><item><title>A custom kernel in a regulated fleet</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/enterprise-adoption-guide/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://heartsecsuite.com/rootlock/kernel-hardening/enterprise-adoption-guide/</guid><description>&lt;p&gt;&lt;strong&gt;Overview&lt;/strong&gt;: Practical guidance for CISOs and procurement teams adopting the Root Lock kernel in regulated fleets — why the custom kernel exists, how vendor risk is owned, deployment and recovery patterns, and honest limitations including alternatives when a custom kernel is not acceptable.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Audience&lt;/strong&gt;: Fortune 500 CISOs, procurement, risk, and compliance teams evaluating Root Lock by HeartSuite for production and regulated workloads.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related reading&lt;/strong&gt;: Start with the &lt;a href="../procurement-brief/"&gt;Procurement Brief&lt;/a&gt; (comparison table and decision guide) and &lt;a href="../auditor-brief/"&gt;Threat model&lt;/a&gt; (threat model and residual risks). Cross-references throughout this guide point to the full set of kernel-hardening, security, operational, and comparison pages.&lt;/p&gt;</description></item><item><title>Which distros boot the Root Lock kernel</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/distro-compatibility-matrix/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://heartsecsuite.com/rootlock/kernel-hardening/distro-compatibility-matrix/</guid><description>&lt;p&gt;&lt;strong&gt;Overview&lt;/strong&gt;: Which Linux distributions Root Lock by HeartSuite currently tests, which kernel line each row uses, and what you still own before production Lockdown. This page follows the live-matrix catalog as of 2026-08-18. It replaces the April 2026 v1.6.4 “Validated” table (Fedora 41, Alpine 3.21 as validated, Ubuntu 22.04 omitted).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Audience&lt;/strong&gt;: Procurement, security architects, and platform engineers selecting a base OS.&lt;/p&gt;
&lt;p&gt;This matrix complements the workload notes in &lt;a href="../../introduction/system-requirements/"&gt;System Requirements&lt;/a&gt; and the buyer-facing deployment guidance in the &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/enterprise-adoption-guide/"&gt;Enterprise Adoption Guide&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>How long each Root Lock kernel is maintained</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/kernel-support-policy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://heartsecsuite.com/rootlock/kernel-hardening/kernel-support-policy/</guid><description>&lt;p&gt;&lt;strong&gt;Overview&lt;/strong&gt;: How HeartSuite maintains, patches, and delivers the Root Lock kernel under subscription — LTS strategy, coordinated update bundles, and how that differs from distribution-vendor errata programs such as RHEL.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Audience&lt;/strong&gt;: Procurement, risk, compliance, and platform teams evaluating Root Lock kernel maintenance alongside existing distribution patching programs.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related reading&lt;/strong&gt;: &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/enterprise-adoption-guide/"&gt;Enterprise Adoption Guide&lt;/a&gt;, &lt;a href="../../maintenance/updating-heartsuite/"&gt;Updating Root Lock&lt;/a&gt;, &lt;a href="../../security/"&gt;Kernel Security Transparency&lt;/a&gt;, &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/distro-compatibility-matrix/"&gt;Distro Compatibility Matrix&lt;/a&gt;, &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/cve-hygiene-for-scanners/"&gt;CVE Hygiene for Scanners&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="what-this-policy-covers"&gt;What this policy covers&lt;a class="td-heading-self-link" href="#what-this-policy-covers" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;This policy describes how HeartSuite supports the &lt;strong&gt;Root Lock kernel&lt;/strong&gt; — the custom-built Linux kernel that Root Lock by HeartSuite requires for Lockdown enforcement — under a commercial &lt;strong&gt;subscription&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title>Your scanner flags CVEs this kernel does not have</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/cve-hygiene-for-scanners/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://heartsecsuite.com/rootlock/kernel-hardening/cve-hygiene-for-scanners/</guid><description>&lt;p&gt;&lt;strong&gt;Overview&lt;/strong&gt;: How to verify kernel CVE status on Root Lock hosts without false positives from upstream version comparison — the workflow vulnerability scanners and auditors should follow instead of matching &lt;code&gt;uname -r&lt;/code&gt; to NVD fix versions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Audience&lt;/strong&gt;: Security operations, vulnerability management, GRC, and audit teams on &lt;strong&gt;enterprise Linux&lt;/strong&gt; (RHEL and Rocky, Ubuntu LTS, Debian, SUSE) who verify kernel CVEs with distribution errata rather than upstream version strings — and who are evaluating or operating Root Lock by HeartSuite in production.&lt;/p&gt;</description></item><item><title>How to verify the kernel you downloaded</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/supply-chain-and-advisories/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://heartsecsuite.com/rootlock/kernel-hardening/supply-chain-and-advisories/</guid><description>&lt;p&gt;&lt;strong&gt;Overview&lt;/strong&gt;: What supply-chain artefacts HeartSuite publishes today (SHA-256 bundle integrity, CONFIG-gate SBOM, OSV, CycloneDX) and what remains on the roadmap (GPG/cosign signing, OVAL).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Audience&lt;/strong&gt;: Procurement, vendor risk, GRC, and platform security teams mapping HeartSuite deliverables to supply-chain questionnaires, SOC 2 / ISO evidence requests, and enterprise Linux vulnerability-management programs.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Related reading&lt;/strong&gt;: &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/kernel-support-policy/"&gt;Kernel Support Policy&lt;/a&gt;, &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/enterprise-adoption-guide/"&gt;Enterprise Adoption Guide&lt;/a&gt;, &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/cve-hygiene-for-scanners/"&gt;CVE Hygiene for Scanners&lt;/a&gt;, &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/evidence-status/"&gt;Evidence Status&lt;/a&gt;, &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/auditor-brief/"&gt;Threat model&lt;/a&gt;, &lt;a href="../../maintenance/updating-heartsuite/"&gt;Updating Root Lock&lt;/a&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="what-this-page-covers"&gt;What this page covers&lt;a class="td-heading-self-link" href="#what-this-page-covers" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;This page states &lt;strong&gt;what HeartSuite publishes today&lt;/strong&gt; for Root Lock kernel supply-chain verification and &lt;strong&gt;what is on the roadmap&lt;/strong&gt; — without overstating availability.&lt;/p&gt;</description></item><item><title>Which kernel evidence is published today</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/evidence-status/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://heartsecsuite.com/rootlock/kernel-hardening/evidence-status/</guid><description>&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Root Lock by HeartSuite kernel evidence&lt;br&gt;
&lt;strong&gt;Fielded 6.18 pin:&lt;/strong&gt; &lt;code&gt;6.18.9-hs&lt;/code&gt; / packaging &lt;code&gt;6.18.9-HeartSuite-3&lt;/code&gt; / build &lt;strong&gt;#37&lt;/strong&gt;&lt;br&gt;
&lt;strong&gt;Legacy stream:&lt;/strong&gt; kernel &lt;strong&gt;5.19.6&lt;/strong&gt; (maintenance-only; see &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/kernel-support-policy/#519-stream-deprecation"&gt;Kernel Support Policy&lt;/a&gt;)&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="summary"&gt;Summary&lt;a class="td-heading-self-link" href="#summary" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Stream&lt;/th&gt;
 &lt;th&gt;Role&lt;/th&gt;
 &lt;th&gt;Config SHA-256&lt;/th&gt;
 &lt;th&gt;Evidence pack&lt;/th&gt;
 &lt;th&gt;Comparison matrix&lt;/th&gt;
 &lt;th&gt;Checker run&lt;/th&gt;
 &lt;th&gt;Runtime verification&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;6.18.9-hs #37&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Fielded pin / new deployments&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;3cd18247…&lt;/code&gt; in &lt;a href="../evidence-pack-6.18.9.txt"&gt;pack&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;&lt;a href="../evidence-pack-6.18.9.txt"&gt;Published&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/kernel-comparison-matrix-6.18.9/"&gt;Published&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;2026-08-18 (&lt;code&gt;e870d01&lt;/code&gt;)&lt;/td&gt;
 &lt;td&gt;2026-08-18 (Debian 12 guest)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;5.19.6&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;Legacy / existing fleets&lt;/td&gt;
 &lt;td&gt;&lt;a href="../evidence-pack-5.19.6.txt"&gt;Published&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;&lt;a href="../evidence-pack-5.19.6.txt"&gt;Published&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/kernel-comparison-matrix-5.19.6/"&gt;Published&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;2026-05-19 (&lt;code&gt;b9b83a0&lt;/code&gt;)&lt;/td&gt;
 &lt;td&gt;2026-05-19 (Debian 12 VM)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;The two lines do &lt;strong&gt;not&lt;/strong&gt; share the same kernel config. 5.19.6 compiled out BPF/FUSE/OVERLAY/USER_NS/AppArmor/TOMOYO. Fielded 6.18.9-hs #37 compiles those in. Treat 5.19.6 scores as &lt;strong&gt;legacy&lt;/strong&gt;, not as a substitute for 6.18.9-hs.&lt;/p&gt;</description></item><item><title>Hardening matrix for kernel 6.18.9</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/kernel-comparison-matrix-6.18.9/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://heartsecsuite.com/rootlock/kernel-hardening/kernel-comparison-matrix-6.18.9/</guid><description>&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Root Lock by HeartSuite, fielded &lt;strong&gt;6.18.9-hs&lt;/strong&gt; (packaging &lt;code&gt;6.18.9-HeartSuite-3&lt;/code&gt;, build &lt;strong&gt;#37&lt;/strong&gt;)&lt;br&gt;
&lt;strong&gt;uname -r:&lt;/strong&gt; &lt;code&gt;6.18.9-hs&lt;/code&gt;&lt;br&gt;
&lt;strong&gt;Config SHA-256 (pin payload):&lt;/strong&gt; &lt;code&gt;3cd1824742b9a15e9467c774c5f62081f9547f730ad7cd9bce464a7d286a7db9&lt;/code&gt;&lt;br&gt;
&lt;strong&gt;vmlinuz SHA-256:&lt;/strong&gt; &lt;code&gt;1b44fffb9b570497f19f4c68e170602b542bc84bfe9f49d936c123dc59f5db8a&lt;/code&gt;&lt;br&gt;
&lt;strong&gt;Tool:&lt;/strong&gt; &lt;a href="https://github.com/a13xp0p0v/kernel-hardening-checker"&gt;kernel-hardening-checker&lt;/a&gt; commit &lt;code&gt;e870d0141259f875d3d1b54fef49dec7074e4cac&lt;/code&gt;, run 2026-08-18&lt;br&gt;
&lt;strong&gt;Source file:&lt;/strong&gt; &lt;a href="../evidence-pack-6.18.9.txt"&gt;&lt;code&gt;evidence-pack-6.18.9.txt&lt;/code&gt;&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;Legacy (published):&lt;/strong&gt; &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/kernel-comparison-matrix-5.19.6/"&gt;Hardening scores: 5.19.6&lt;/a&gt;, &lt;a href="../evidence-pack-5.19.6.txt"&gt;&lt;code&gt;evidence-pack-5.19.6.txt&lt;/code&gt;&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This page measures the &lt;strong&gt;fielded #37 pin&lt;/strong&gt;. It is not a derived unpublished cut. &lt;code&gt;CONFIG_IO_URING&lt;/code&gt;, &lt;code&gt;CONFIG_KEXEC&lt;/code&gt;, and &lt;code&gt;CONFIG_KEXEC_FILE&lt;/code&gt; are &lt;strong&gt;=y&lt;/strong&gt;. Guest &lt;code&gt;/boot/config-6.18.9-hs&lt;/code&gt; is an 11-line RD stub — hash the pin payload config.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="part-1--measured-comparison"&gt;Part 1 — Measured comparison&lt;a class="td-heading-self-link" href="#part-1--measured-comparison" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Arch linux-hardened &lt;strong&gt;6.18.16-hardened1&lt;/strong&gt; and vanilla &lt;strong&gt;6.18.9&lt;/strong&gt; &lt;code&gt;defconfig&lt;/code&gt; are era-matched 6.18.x (no 6.18.9-hardened in the Arch archive).&lt;/p&gt;</description></item><item><title>Hardening scores: 5.19.6 against the field</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/kernel-comparison-matrix-5.19.6/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://heartsecsuite.com/rootlock/kernel-hardening/kernel-comparison-matrix-5.19.6/</guid><description>&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Root Lock by HeartSuite, kernel 5.19.6&lt;br&gt;
&lt;strong&gt;Config SHA-256:&lt;/strong&gt; &lt;code&gt;d67caa637263c33ce939b7eef867f0695d60d11d285d6694a7f5567e73ba6fbc&lt;/code&gt;&lt;br&gt;
&lt;strong&gt;Tool:&lt;/strong&gt; &lt;a href="https://github.com/a13xp0p0v/kernel-hardening-checker"&gt;kernel-hardening-checker&lt;/a&gt; commit &lt;code&gt;b9b83a0&lt;/code&gt;, run 2026-05-19&lt;br&gt;
&lt;strong&gt;Source file:&lt;/strong&gt; &lt;code&gt;evidence-pack-5.19.6.txt&lt;/code&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="part-1--measured-comparison-same-kernel-era"&gt;Part 1 — Measured comparison (same kernel era)&lt;a class="td-heading-self-link" href="#part-1--measured-comparison-same-kernel-era" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;All three configs below are built from the 5.19.x kernel tree. Checker scores are directly comparable — same Kconfig namespace, same option universe.&lt;/p&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Config&lt;/th&gt;
 &lt;th&gt;Source&lt;/th&gt;
 &lt;th&gt;Kernel&lt;/th&gt;
 &lt;th&gt;Overall&lt;/th&gt;
 &lt;th&gt;Attack-surface&lt;/th&gt;
 &lt;th&gt;Exploit-resistance&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;strong&gt;HS 5.19.6&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;HS canonical config (SHA256: &lt;code&gt;d67caa6…&lt;/code&gt;)&lt;/td&gt;
 &lt;td&gt;5.19.6&lt;/td&gt;
 &lt;td&gt;&lt;strong&gt;129/258 (50.0%)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;&lt;strong&gt;91/132 (68.9%)&lt;/strong&gt;&lt;/td&gt;
 &lt;td&gt;31/109 (28.4%)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Arch linux-hardened&lt;/td&gt;
 &lt;td&gt;gitlab.archlinux.org/archlinux/packaging/packages/linux-hardened @ tag &lt;code&gt;5.19.11.hardened1-1&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;5.19.11&lt;/td&gt;
 &lt;td&gt;158/258 (61.2%)&lt;/td&gt;
 &lt;td&gt;77/132 (58.3%)&lt;/td&gt;
 &lt;td&gt;&lt;strong&gt;69/109 (63.3%)&lt;/strong&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Vanilla x86_64 defconfig&lt;/td&gt;
 &lt;td&gt;Bundled in kernel-hardening-checker&lt;/td&gt;
 &lt;td&gt;5.17.1&lt;/td&gt;
 &lt;td&gt;126/258 (48.8%)&lt;/td&gt;
 &lt;td&gt;90/132 (68.2%)&lt;/td&gt;
 &lt;td&gt;29/109 (26.6%)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="reading-the-table"&gt;Reading the table&lt;a class="td-heading-self-link" href="#reading-the-table" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Attack-surface&lt;/strong&gt; measures how many dangerous kernel features are disabled. Higher = more things turned off.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Exploit-resistance&lt;/strong&gt; measures how many defensive mitigations against memory bugs are enabled. Higher = harder to exploit.&lt;/li&gt;
&lt;li&gt;These two axes are &lt;strong&gt;largely independent&lt;/strong&gt; and optimized for different threat models.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="what-this-shows"&gt;What this shows&lt;a class="td-heading-self-link" href="#what-this-shows" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;HS leads on attack-surface (91 vs 77 vs 90): it disables &lt;code&gt;BPF_SYSCALL&lt;/code&gt;, &lt;code&gt;FUSE_FS&lt;/code&gt;, &lt;code&gt;OVERLAY_FS&lt;/code&gt;, &lt;code&gt;SECURITY_APPARMOR&lt;/code&gt;, &lt;code&gt;SECURITY_TOMOYO&lt;/code&gt;, and &lt;code&gt;USER_NS&lt;/code&gt; — all of which Arch linux-hardened keeps enabled for its general-purpose user base.&lt;/p&gt;</description></item><item><title>What a red team should test on this kernel</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/auditor-brief/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://heartsecsuite.com/rootlock/kernel-hardening/auditor-brief/</guid><description>&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Root Lock by HeartSuite — fielded &lt;strong&gt;6.18.9-hs&lt;/strong&gt; (packaging &lt;code&gt;6.18.9-HeartSuite-3&lt;/code&gt;, build &lt;strong&gt;#37&lt;/strong&gt;); &lt;strong&gt;5.19.6&lt;/strong&gt; legacy&lt;br&gt;
&lt;strong&gt;Evidence status:&lt;/strong&gt; Measured config SHA-256, checker output, and runtime verification for &lt;strong&gt;6.18.9-hs #37&lt;/strong&gt; are in &lt;a href="../evidence-pack-6.18.9.txt"&gt;&lt;code&gt;evidence-pack-6.18.9.txt&lt;/code&gt;&lt;/a&gt; (2026-08-18). The &lt;strong&gt;5.19.6&lt;/strong&gt; pack remains the legacy measured stream.&lt;br&gt;
&lt;strong&gt;Primary stream:&lt;/strong&gt; &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/kernel-comparison-matrix-6.18.9/"&gt;Hardening matrix for kernel 6.18.9&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;Legacy stream:&lt;/strong&gt; Config SHA-256 &lt;code&gt;d67caa637263c33ce939b7eef867f0695d60d11d285d6694a7f5567e73ba6fbc&lt;/code&gt; — measured 2026-05-19, checker &lt;code&gt;b9b83a0&lt;/code&gt; — &lt;a href="https://heartsecsuite.com/rootlock/kernel-hardening/kernel-comparison-matrix-5.19.6/"&gt;comparison matrix&lt;/a&gt;, &lt;a href="../evidence-pack-5.19.6.txt"&gt;&lt;code&gt;evidence-pack-5.19.6.txt&lt;/code&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This page describes the &lt;strong&gt;fielded #37 pin&lt;/strong&gt;. It does not describe a derived unpublished cut that turns &lt;code&gt;IO_URING&lt;/code&gt; / &lt;code&gt;KEXEC&lt;/code&gt; off. Those options are &lt;strong&gt;=y&lt;/strong&gt; on the binary that boots.&lt;/p&gt;</description></item><item><title>SELinux, AppArmor, TOMOYO — a different job</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/lsm-comparison/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://heartsecsuite.com/rootlock/kernel-hardening/lsm-comparison/</guid><description>&lt;p&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Root Lock by HeartSuite, kernel 5.19.6&lt;br&gt;
&lt;strong&gt;Audience:&lt;/strong&gt; Security engineers familiar with SELinux, AppArmor, or TOMOYO evaluating HeartSuite for containment or appliance deployments.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="the-core-distinction"&gt;The core distinction&lt;a class="td-heading-self-link" href="#the-core-distinction" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;SELinux, AppArmor, and TOMOYO all answer the same question: &lt;em&gt;given that a kernel feature is present, what should a process be allowed to do with it?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;HeartSuite answers a different question: &lt;em&gt;which kernel features should exist on this system at all?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;This is not a claim that one approach is universally superior.&lt;/p&gt;</description></item><item><title>Kernel hardening in plain language</title><link>https://heartsecsuite.com/rootlock/kernel-hardening/analyst-summary/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://heartsecsuite.com/rootlock/kernel-hardening/analyst-summary/</guid><description>&lt;p&gt;&lt;em&gt;Kernel: Root Lock by HeartSuite 5.19.6. Config hash: &lt;code&gt;d67caa637263c33ce939b7eef867f0695d60d11d285d6694a7f5567e73ba6fbc&lt;/code&gt;. Measured: 2026-05-19.&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;Root Lock ships a Linux kernel with 9 loadable modules. A standard Debian Linux system typically ships 3,500 to 4,000.&lt;/p&gt;
&lt;p&gt;That count is not a capability cut. The kernel is built for one job. Nothing else is included.&lt;/p&gt;
&lt;p&gt;Root Lock also disables the kernel features most often used to bypass security controls: BPF (a programmable kernel interface), FUSE (user-space filesystems), overlay filesystems, and competing security policy engines including AppArmor and SELinux. Each of these has been used in documented real-world attacks to escape software sandboxes or override security policies.&lt;/p&gt;</description></item></channel></rss>