First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 216612
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: The Gentoo Linux Hardened Team <hardened@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Kerin Millar <kerframil@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 216612 depends on: Show dependency tree
Bug 216612 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-04-06 20:26 0000
I am pleased to present the following patchset with a view to its being
committed as the initial hardened-sources-2.6.24 release.

http://confucius.dh.bytemark.co.uk/~kerin.millar/

The sha256sum for the hardened-patches-2.6.24-1.tar.bz2 archive is as follows:

686d535fd118e95d9ce85f8cc67d560df83c9a8422c26fa5330c7cfafad84286

Many thanks are due to Gordon Malm for his outstanding contributions.

These are the changes, relative to 2.6.23-r9:

* Re-based upon 2.6.24 + genpatches-2.6.24-5
* Incoporates unmodified grsec-2.1.11-2.6.24.4-200803262003 patch
* Introduces bespoke server and workstation oriented security levels
* Allows PaX to be enabled without grsecurity
* VDSO_COMPAT cannot be enabled during runtime if PaX is enabled

------- Comment #1 From Wolfram Schlich 2008-04-06 20:42:45 0000 -------
Thanks. I tried vanilla 2.6.24.4 + grsec-2.1.11-2.6.24.4-200803262003.patch
and it made my machine freeze *hard* without any oops/panic at all.
The only thing I changed in the .config from my tries with 2.6.23-hardened-r9
were that I disabled CONFIG_PAX_MEMORY_SANITIZE and CONFIG_PAX_MEMORY_UDEREF.

------- Comment #2 From Gordon Malm 2008-04-06 21:40:11 0000 -------
> * Allows PaX to be enabled without grsecurity

Thank you much Kerin.  Just a reminder, this not an actual change relative to
2.6.23-r9, we just split it out of the unrelated patch it has been contained in
for many releases.  With all the discussions, work and basically complete audit
we have done, I can certainly understand the mixup.

------- Comment #3 From Christian Heim (RETIRED) 2008-04-07 13:08:28 0000 -------
OK, I added the ebuild with a slight modification to the tree. Thanks a lot for
your effort Kerin and Gordon.

First Last Prev Next    No search results available      Search page      Enter new bug