Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 234571

Summary: PATCH sys-kernel/hardened-sources-2.6.25-r3 working patch for fbcondecor-0.9.4
Product: Gentoo Linux Reporter: Magnus Granberg <zorry>
Component: HardenedAssignee: The Gentoo Linux Hardened Team <hardened>
Status: RESOLVED WONTFIX    
Severity: normal CC: martin
Priority: High    
Version: 2008.0   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---
Attachments: working fbcondecor-0.9.4 patch
diff 4200_fbcondecor-0.9.4 and 4460_fbcondecor-0.9.4

Description Magnus Granberg gentoo-dev 2008-08-12 20:38:15 UTC
* Applying 4200_fbcondecor-0.9.4.patch (-p0+) ...                                                                                 [ ok ]
 * Applying 4300_squashfs-3.3.patch (-p0+) ...                                                                                     [ ok ]
 * Applying 4400_speakup-support.patch (-p0+) ...                                                                                  [ ok ]
 * Applying 4405_alpha-sysctl-uac.patch (-p0+) ...                                                                                 [ ok ]
 * Applying 4420_grsec-2.1.12-2.6.25.12-200807261355.patch (-p0+) ...                                                              [ !! ]
 * Please attach /var/tmp/portage/sys-kernel/hardened-sources-2.6.25-r3/temp/4420_grsec-2.1.12-2.6.25.12-200807261355.err to any bug you may post.
Comment 1 Magnus Granberg gentoo-dev 2008-08-12 20:41:09 UTC
Created attachment 162774 [details, diff]
working fbcondecor-0.9.4 patch

Need to be after 4450_selinux-avc_audit-log-curr_ip.patch
Comment 2 Magnus Granberg gentoo-dev 2008-08-12 20:43:19 UTC
Created attachment 162776 [details, diff]
diff 4200_fbcondecor-0.9.4 and 4460_fbcondecor-0.9.4
Comment 3 Magnus Granberg gentoo-dev 2008-08-12 20:46:53 UTC
 * Applying 4445_grsec-2.1.11-mute-warnings.patch (-p0+) ...                                                                       [ ok ]
 * Applying 4450_selinux-avc_audit-log-curr_ip.patch (-p0+) ...                                                                    [ ok ]
 * Applying 4460_fbcondecor-0.9.4.patch (-p0+) ...                                                                                 [ ok ]
>>> Source unpacked.
Working on vanilla toolchain with hardened-sources-2.6.25-r3 and no PAX or GRSEC enable.
Comment 4 Gordon Malm (RETIRED) gentoo-dev 2008-08-13 02:15:38 UTC
I'm not carrying fbcondecor patches in hardened-extras.  If you submit an fbcondecor patch to kernel@g.o that fixes the conflicts with the grsecurity patch (appears that it should be a trivial task) I'll consider removing fbcondecor from UNIPATCH_EXCLUDE in hardened-sources.  Nice work though and thanks for your inquiry.
Comment 5 Magnus Granberg gentoo-dev 2008-08-13 21:28:02 UTC
Thats okey with me.
Comment 6 Martin Väth 2009-06-01 07:00:49 UTC
When I tried last time (with kernel 2.6.29), there was no obvious conflict
between grsecurity and fbcondecor. And at least applying the patch works with
hardened-sources-2.6.29.

However, fbcondecor is still in UNIPATCH_EXCLUDE; actually, meanwhile it is
the only item there. Is there a particular reason for this?

If not, I would suggest to remove it from that list. It is certainly not a "must"
but a "nice to have", even on hardened systems...