Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 216612 - Proposed hardened-sources-2.6.24 ebuild
Summary: Proposed hardened-sources-2.6.24 ebuild
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Hardened (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: The Gentoo Linux Hardened Team
Keywords: Inclusion
Depends on:
Reported: 2008-04-06 20:26 UTC by Kerin Millar
Modified: 2008-04-07 13:08 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Kerin Millar 2008-04-06 20:26:00 UTC
I am pleased to present the following patchset with a view to its being committed as the initial hardened-sources-2.6.24 release.

The sha256sum for the hardened-patches-2.6.24-1.tar.bz2 archive is as follows:


Many thanks are due to Gordon Malm for his outstanding contributions.

These are the changes, relative to 2.6.23-r9:

* Re-based upon 2.6.24 + genpatches-2.6.24-5
* Incoporates unmodified grsec-2.1.11- patch
* Introduces bespoke server and workstation oriented security levels
* Allows PaX to be enabled without grsecurity
* VDSO_COMPAT cannot be enabled during runtime if PaX is enabled
Comment 1 Wolfram Schlich (RETIRED) gentoo-dev 2008-04-06 20:42:45 UTC
Thanks. I tried vanilla + grsec-2.1.11-
and it made my machine freeze *hard* without any oops/panic at all.
The only thing I changed in the .config from my tries with 2.6.23-hardened-r9
Comment 2 Gordon Malm (RETIRED) gentoo-dev 2008-04-06 21:40:11 UTC
> * Allows PaX to be enabled without grsecurity

Thank you much Kerin.  Just a reminder, this not an actual change relative to 2.6.23-r9, we just split it out of the unrelated patch it has been contained in for many releases.  With all the discussions, work and basically complete audit we have done, I can certainly understand the mixup.
Comment 3 Christian Heim (RETIRED) gentoo-dev 2008-04-07 13:08:28 UTC
OK, I added the ebuild with a slight modification to the tree. Thanks a lot for your effort Kerin and Gordon.