Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 315371 - no hardened auto-build stages on numerous mirrors
Summary: no hardened auto-build stages on numerous mirrors
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Release Media
Classification: Unclassified
Component: Stages (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Release Team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-04-15 02:38 UTC by zim zum
Modified: 2010-10-14 05:36 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description zim zum 2010-04-15 02:38:23 UTC
[19:05:58][ zimzum] strange
[19:06:05][ zimzum] the april autobuilds dont have hardened/
[19:08:21][+blueness] zimzum: http://gentoo.osuosl.org/releases/amd64/autobuilds/20100401/
[19:08:59][+blueness] or or are you looking for i686?
[19:09:42][ zimzum] yes
[19:09:45][ zimzum] of course!
[19:10:37][ zimzum] why is it not on any of the other mirrors now?
[19:10:59][ zimzum] is there any news/announcement or anything about this?
[19:11:42][ zimzum] I am not a fan of distro-born surprise buttsex :(
[19:14:33][+blueness] zimzum: its not that big a deal, you can use a previous stage3 and update
[19:15:06][+blueness] i could build one if you like, but not put it on the mirror
[19:15:12][ zimzum] there are numerous work-arounds
[19:15:24][ zimzum] but why was it just removed?
[19:15:37][+blueness] i don't know if it was removed or just not built
[19:15:55][ zimzum] for end-user purposes, whats the difference?
[19:16:05][ zimzum] either way I basically have to do stage1 now for 99% of new installs
[19:16:08][+blueness] gengor or Zorry: ^^^ no recent stage3 hardened i686 ^^^
[19:16:22][+blueness] nah, grab the older stage3 and update
[19:17:10][ zimzum] is it on any other mirrors besides osuosl.org?
[19:17:49][ zimzum] how long will it be necessary to perform new installs with outdated stage?
[19:18:13][+blueness] zimzum: i'm sure it'll get cleared
[19:18:23][+blueness] again, if you like, i'll build you one
[19:18:52][ zimzum] I can work around this...but it presents a lot of time-consuming issues in the interim
[19:18:59][ zimzum] also, can you define 'cleared' ?
[19:19:24][+blueness] cleared up
[19:19:38][ zimzum] does that mean it will get built with autobuilds again?
[19:19:48][ zimzum] re-propagated to the other mirrors again?
[19:20:23][+blueness] zimzum: i'll look into finding who's responsible and asking that it get autobuilt
[19:20:24][+blueness] else
[19:20:29][+blueness] you can file a bug about it
[19:20:33][ zimzum] are you basing this on on-going information or historical data?
[19:20:37][ zimzum] ok
[19:22:23][+blueness] gn8
[19:30:32]--> Topic for #gentoo-hardened: http://www.gentoo.org/proj/en/hardened/primer.xml | get: http://gentoo.osuosl.org/releases/${ARCH}/autobuilds/${builddate}/hardened/ | Use hardened/linux/${arch}/10.0 profiles
[19:30:32]--> Topic set by solar [] [Tue Dec 22 20:10:53 2009]


Reproducible: Always

Steps to Reproduce:
1. go to a gentoo mirror
2. browse to releases/${ARCH}/autobuilds/${builddate}/hardened
3. get 404




There are ways two relatively documented work-arounds for this:

1) dig through the only mirror that seems to have hardened stage3 auto-builds and update:

http://gentoo.osuosl.org/releases/

2)perform a stage 1 install using the hardened profile

Either case results in extra steps and time consumption deploying hardened systems.
Comment 1 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2010-04-15 02:48:16 UTC
Hi, just to inform you some more. There is no reason why files would be on one mirror and not the other. In this case, I just found the files here too:
http://mirrors.kernel.org/gentoo/releases/amd64/autobuilds/20100401/hardened/

What you are (probably) seeing is that the hardened stages failed and as such, there was not any pushed to the mirrors for the latest build date. This is a fact of the automated process, if it fails one week it won't necessarily get looked at and assumed that the next week will work.
Comment 2 Faustus 2010-04-17 00:06:49 UTC
The bug is somewhat misleading. There is no mirror inconsistency. There are no hardened autobuilds for x86 on all mirrors for April:
http://gentoo.osuosl.org/releases/x86/autobuilds/20100406/
http://gentoo.osuosl.org/releases/x86/autobuilds/20100413/
Comment 3 Faustus 2010-04-17 00:15:47 UTC
What is the proper way to convert a regular autobuild to a hardened one?

Is it something like:

eselect profile set hardened/linux/x86/10.0
emerge -1 binutils gcc libc
emerge -e system
emerge -1 hardened-sources

Thanks.
Comment 4 Raúl Porcel (RETIRED) gentoo-dev 2010-04-17 11:34:25 UTC
Let's see...

amd64:

Latest hardened autobuild was on 20100415

x86:

Latest hardened autobuild was on 20100216

Why? Because they have failed to build. I've fixed it and next week the x86 hardened autobuild should be available. Will keep this bug open until they appear on the mirror.

@ Faustus: the proper way to get a hardened autobuild is using directly the latest available, so 20100216 in the case of x86.
Comment 5 Faustus 2010-04-17 11:42:51 UTC
Sorry for spamming...

Raul, I am just interested to know what are the exact differences between regular and hardened builds. Will the commands I wrote get the equivalent of a hardened build, or is there something else I missed?
Comment 6 Raúl Porcel (RETIRED) gentoo-dev 2010-04-17 12:00:42 UTC
(In reply to comment #5)
> Sorry for spamming...
> 
> Raul, I am just interested to know what are the exact differences between
> regular and hardened builds. Will the commands I wrote get the equivalent of a
> hardened build, or is there something else I missed?
> 

You'll need to ask the hardened team, i have no clue.
Comment 7 Faustus 2010-04-22 15:03:33 UTC
Seems it's ok now (200100420).
Comment 8 Raúl Porcel (RETIRED) gentoo-dev 2010-04-24 16:22:02 UTC
Both x86 and amd64 stages are on the mirrors now.
Comment 9 Faustus 2010-10-14 05:36:29 UTC
There are no hardened autobuilds again for 20101012.