Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 26684 - grsecurity-sources / grsec-sources in portage
Summary: grsecurity-sources / grsec-sources in portage
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: solar (RETIRED)
Depends on:
Reported: 2003-08-15 10:52 UTC by solar (RETIRED)
Modified: 2003-10-05 22:46 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---

ibook config, desktop config (configs.txt,6.08 KB, text/plain)
2003-08-18 17:22 UTC, Nicolas Kaiser

Note You need to log in before you can comment on or make changes to this bug.
Description solar (RETIRED) gentoo-dev 2003-08-15 10:52:30 UTC
Gentoo Linux includes support for grsecurity in nearly every kernel that
we have. Unfortunately the patch level is not always as up2date as Brad's
code due to the many other patches that are included, however what I'm
wondering here is do the Gentoo users want the option of merging a
vanilla-kernel with just "one" patch applied. It would be called
grsecurity-sources. I would like to use the grsec2 series for this so we
can help Brad debug and get it to a stable level.

That was a poll that ran on gentoo-dev, gentoo-hardened, grsec mailing lists
that got good feedback.

Added to portage as grsec-sources- and
~sparc ~alpha ~ppc)
This ebuild was written to work for both 1.9.x and 2.x and should play along
with SLOT's
Comment 1 solar (RETIRED) gentoo-dev 2003-08-15 10:53:34 UTC
Anybody interested in testing grsec-sources and reporting some feedback?
Comment 2 Nicolas Kaiser 2003-08-18 17:22:30 UTC
Created attachment 16294 [details]
ibook config, desktop config
Comment 3 Nicolas Kaiser 2003-08-18 17:24:05 UTC
I'm running on a dual x86 desktop, and also tried running it on my iBook (ppc).
But I found that the latter needs a couple of hardware specific patches (notably AGP support and framebuffer), so I patched over the latest benh2 kernel.
Patching worked well except for CONFIG_GRKERNSEC_PAX_RANDMMAP, and I rather disabled it than merge it manually.

As these are X machines, I excluded some options, and found that I needed to disable as well CONFIG_GRKERNSEC_KMEM for DRM acceleration.
Apart from that, everything working nicely.
Find attached configurations. Hope you like my feedback :)
Comment 4 solar (RETIRED) gentoo-dev 2003-10-05 22:46:40 UTC
changing resolution to TEST-REQUEST (more or less leaving this bug open so
others may find the ibook config)