Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 156746 - Kernel eclasses and ebuilds need H_SECURITY_SUPPORTED
Summary: Kernel eclasses and ebuilds need H_SECURITY_SUPPORTED
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Eclasses (show other bugs)
Hardware: All Linux
: High major
Assignee: Gentoo Kernel Bug Wranglers and Kernel Maintainers
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-11-30 18:37 UTC by Harlan Lieberman-Berg (RETIRED)
Modified: 2007-01-01 17:52 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Harlan Lieberman-Berg (RETIRED) gentoo-dev 2006-11-30 18:37:33 UTC
As per new Kernel Security Guidelines, unsupported kernel sources should have an ewarn triggered upon emerge warning users that they are installing a kernel not supported by Gentoo Security. My idea about what the language should be is below:

The kernel source XXX you are installing is not supported by the Gentoo Security Team.
The maintainer YYYY of this kernel source is responsible for security updates and patches.
Use at your own risk.
Comment 1 Harlan Lieberman-Berg (RETIRED) gentoo-dev 2006-12-01 08:10:13 UTC
H_SECURITY_SUPPORTED should be set to true for the following -sources:
ck-sources
gentoo-sources
hardened-sources
hppa-sources
mips-sources
openvz-sources
rsbac-sources
sparc-sources
suspend2-sources
systrace-sources
usermode-sources
vserver-sources
xen-sources

The following are unsupported due to hardmask:
cell-sources
openblocks-sources
openmosix-sources

The following are unsupported due to maintainer decision or direct copies from upstream:
freebsd-sources
git-sources
mm-sources
xbox-sources
vanilla-sources
Comment 2 Daniel Drake (RETIRED) gentoo-dev 2006-12-01 20:05:16 UTC
I can't decide which message to use, I can't think of any which fit all of the kernels listed there. I'd much prefer we document this on the website first, then we can just add a URL, which would list reasons for not supporting each of those kernels.
Comment 3 Daniel Drake (RETIRED) gentoo-dev 2006-12-26 19:47:11 UTC
http://www.gentoo.org/proj/en/security/kernel.xml
I'll get to this soon.
Comment 4 Daniel Drake (RETIRED) gentoo-dev 2007-01-01 17:52:49 UTC
created K_SECURITY_UNSUPPORTED flag and set it on:

git-sources 	
kurobox-sources
mm-sources
openblocks-sources
openmosix-sources
sh-sources
xbox-sources
vanilla-sources