Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 14678 - set of patches for djbdns
Summary: set of patches for djbdns
Status: RESOLVED NEEDINFO
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All All
: High enhancement (vote)
Assignee: Jared H. Hudson (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-01-28 09:51 UTC by sunscan
Modified: 2004-05-21 10:32 UTC (History)
6 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
set of patches that i find around... :) (smn-dns-0.0.2.tar.gz,11.00 KB, application/gzip)
2003-01-28 09:52 UTC, sunscan
Details
fixes a little bug for grsecurity-enabled kernels that don't allow fchrooting out of already established chroot. (djbdns-1.05-r3-grsec-patch.diff,357 bytes, patch)
2003-03-19 05:11 UTC, Stanislav Karchebny
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description sunscan 2003-01-28 09:51:11 UTC
I find around this set of patches for djbdns that can be usefull (NOT tested).
:)
Comment 1 sunscan 2003-01-28 09:52:54 UTC
Created attachment 7713 [details]
set of patches that i find around... :)
Comment 2 Stanislav Karchebny 2003-03-19 05:11:25 UTC
Created attachment 9590 [details, diff]
fixes a little bug for grsecurity-enabled kernels that don't allow fchrooting out of already established chroot.

I found this when trying to use djbdns on grsecurity-enabled 2.4.19 kernel.
The service failed constantly saying it couldn't get to some file. straceing it
showed that kernel doesn't allow some djb trick with fchroot, so i fixed it a
bit.
I DO NOT KNOW HOW EXACTLY THIS CAN AFFECT OVERALL DJBDNS SECURITY, AND
THEREFORE I AM NOT LIABLE FOR ANY CONSEQUENCES OF USING THIS PATCH. Iow: You're
on your own.
Comment 3 Martin Holzer (RETIRED) gentoo-dev 2003-04-21 17:07:16 UTC
also watch bug #19375 
Comment 4 Georgi Georgiev 2003-08-13 09:17:20 UTC
Most of the patches in the set of patches (attachment #1 [details]) have been discussed on the dns@list.cr.yp.to list, and pretty much everyone agrees they are not only not useful, but even contradict with the design of djbdns.
Comment 5 Danyel Lawson 2003-12-14 17:09:31 UTC
This is bad.  Who is in charge here?
Comment 6 Danyel Lawson 2003-12-15 01:18:50 UTC
Please ignore my previous post
Comment 7 Jared H. Hudson (RETIRED) gentoo-dev 2004-05-21 03:19:52 UTC
When you say grsecurity will complain, do you mean it will not work with djbdns at all or it produces just a cosmetic error? If the former, I will add this patch with a grsecurity use flag, if the latter I will not add this patch.
Comment 8 solar (RETIRED) gentoo-dev 2004-05-21 10:32:08 UTC
Jared,
I ask you to please NOT add a grsecurity USE flag for this one special 
case of dealing with optional fchroot behaviors. My guess is it's a
security risk and I don't want users to assocate grsecurity with the
need to relax security. Please either take the patch as is all together
or talk to djb and see if the proposed patch is ok.