Gentoo Archives: gentoo-commits

From: "Anthony G. Basile" <blueness@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] dev/blueness:master commit in: sys-kernel/hardened-sources/
Date: Mon, 12 Dec 2011 22:23:04
Message-Id: 7099db0768a67b9ae7f894205484cb1f8bbc6181.blueness@gentoo
1 commit: 7099db0768a67b9ae7f894205484cb1f8bbc6181
2 Author: Anthony G. Basile <blueness <AT> gentoo <DOT> org>
3 AuthorDate: Mon Dec 12 22:22:46 2011 +0000
4 Commit: Anthony G. Basile <blueness <AT> gentoo <DOT> org>
5 CommitDate: Mon Dec 12 22:22:46 2011 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=dev/blueness.git;a=commit;h=7099db07
7
8 sys-kernel/hardened-sources: testing patchset 20111210
9
10 (Portage version: 2.1.10.11/git/Linux x86_64, signed Manifest commit with key 0xD0455535)
11
12 ---
13 sys-kernel/hardened-sources/ChangeLog | 7 +++
14 sys-kernel/hardened-sources/Manifest | 22 +++++++--
15 .../hardened-sources-2.6.32-r81.ebuild | 49 ++++++++++++++++++++
16 .../hardened-sources/hardened-sources-3.1.5.ebuild | 49 ++++++++++++++++++++
17 4 files changed, 123 insertions(+), 4 deletions(-)
18
19 diff --git a/sys-kernel/hardened-sources/ChangeLog b/sys-kernel/hardened-sources/ChangeLog
20 index ad934d9..898249d 100644
21 --- a/sys-kernel/hardened-sources/ChangeLog
22 +++ b/sys-kernel/hardened-sources/ChangeLog
23 @@ -1,5 +1,12 @@
24
25
26 +*hardened-sources-3.1.5 (12 Dec 2011)
27 +*hardened-sources-2.6.32-r81 (12 Dec 2011)
28 +
29 + 12 Dec 2011; Anthony G. Basile <blueness@g.o>
30 + +hardened-sources-2.6.32-r81.ebuild, +hardened-sources-3.1.5.ebuild:
31 + testing patchset 20111210
32 +
33 10 Dec 2011; Anthony G. Basile <blueness@g.o>
34 -hardened-sources-2.6.32-r80.ebuild, -hardened-sources-3.1.4-r1.ebuild:
35 moved to tree
36
37 diff --git a/sys-kernel/hardened-sources/Manifest b/sys-kernel/hardened-sources/Manifest
38 index 1001927..0b2f795 100644
39 --- a/sys-kernel/hardened-sources/Manifest
40 +++ b/sys-kernel/hardened-sources/Manifest
41 @@ -1,12 +1,26 @@
42 -----BEGIN PGP SIGNED MESSAGE-----
43 Hash: SHA256
44
45 -MISC ChangeLog 10492 RMD160 58b1cdf9a4d630d7a138e23a35714c3cea64e359 SHA1 44ff727c61edba2033a7bf1d9356cded58ee7727 SHA256 ec8fed12c942770f5e817d25622cd0b9e508244b1f7b8552c732fddd47a5acb7
46 +DIST deblob-2.6.32 84094 RMD160 394f46ec5b869638a7bc2e87beb118167c9bd6cb SHA1 1a2a1efb72126609d9e3b9be99ae5be2751efd06 SHA256 de625f0bd221c9c38d4453f1b709622f222d86a0ae9350d2b7b0e17795e6de6d
47 +DIST deblob-3.1 103909 RMD160 723d36ef2574419417bbf30eda6a83aaa91922d7 SHA1 39d2c6e69f4e3b84e112b6e3e9389c983976fe4b SHA256 9dcf6f981cb3681f8afab0a4f814aebd6c2f46f8e635d2f35657d8344ef6b30e
48 +DIST deblob-check-2.6.32 247608 RMD160 840bf8a229ea79810519eee6241edb85b78a6562 SHA1 d45a24eb16e5ac956c0fcddbc1ac4d67e326c7b8 SHA256 da1aecdf3ab7f1207b90642d303e52262ccc2ed9e49739b729512b88950d17f3
49 +DIST deblob-check-3.1 405438 RMD160 da7efe959bc7c0017214daa764fcb486ff4434f2 SHA1 397157d3f6bf225f8cc4f48b6c05bc56482c2934 SHA256 77d125ae5466049fb3f1fe39ddb9320b66239de782a348c66133de591049db43
50 +DIST genpatches-2.6.32-46.base.tar.bz2 1028139 RMD160 36453ee2475c260ea02d14bb68a82c7eba4ba035 SHA1 9bb9884c6d55278542f1af473ca0d97cbbb87455 SHA256 32362617077de30ca78afb9dc363b4507b4069f9a26cf7196bc73727fee10eee
51 +DIST genpatches-2.6.32-46.extras.tar.bz2 24939 RMD160 055706793fb532caeb3d364c5e1bd0ad46aff4b2 SHA1 2a966a4d5f9a718a0d43c25df563d0377154996f SHA256 ee714d14310fd5242ce2e28a8f8e5fda63ba18957960814876506f8754b9d2a0
52 +DIST genpatches-3.1-8.base.tar.bz2 164116 RMD160 619061ed81cee8ca391937f4b15c2805948e168e SHA1 abc55d0cad5b98461441c3790a7356d869ec90cf SHA256 c35165f1931f93ccfe477f11d5e842c2510097f017293a55aaa34dce903a2da9
53 +DIST genpatches-3.1-8.extras.tar.bz2 17200 RMD160 fa8aa6ba8bc1e554758017d371769536d025bdc1 SHA1 47240cdc21d69d2af05d0b2bd7dcbb1615508f86 SHA256 b108dbf3b5ddad1701cacd2f1c936a63b60d1a4cd86fd7f9311230e3bacac56b
54 +DIST hardened-patches-2.6.32-83.extras.tar.bz2 538575 RMD160 541c5122ab122ca7466deaf2431fcafb3135b2c2 SHA1 24173b7178a077a7b8c0c979d3742efb07d2bc9a SHA256 8640f3aaed869c3a88928f12ccadb6314e240f61f29e68de74b572735f2e313d
55 +DIST hardened-patches-3.1.5-1.extras.tar.bz2 514517 RMD160 f4e68b456311300765c07217a1dd0ae79f7b505a SHA1 918bca15180498c10f026f6878502ce3a32067f8 SHA256 96232a098ee8797349fbb5c79b0d3f437424fd2f10ef53ab6a87add9f9055b33
56 +DIST linux-2.6.32.tar.bz2 64424138 RMD160 b93742cbaf8174f2200d2dbef0d47a26c618039c SHA1 410b4fc818023bfef60064e973ff0ab46d3bfb19 SHA256 5099786d80b8407d98a619df00209c2353517f22d804fdd9533b362adcb4504e
57 +DIST linux-3.1.tar.bz2 77190238 RMD160 f9a3ce57b9f20a1402ef340792d3c223140ce1d2 SHA1 ac792701561b1cd4279302b8bb8f474731762ad1 SHA256 2573d2378c754b0c602b57586e9311e5b38c5d1e6c137f02873833633a4b9359
58 +EBUILD hardened-sources-2.6.32-r81.ebuild 1840 RMD160 51810e14ef1289ecbb299abdbd9ef80fa98b166c SHA1 75c7d20fe14d4d5cbf0469e33d64cb800033b473 SHA256 31fb844b0b091c5d9118c9eaeaf06b0cdb54515a1c411b9c55ba5c7e3ff51414
59 +EBUILD hardened-sources-3.1.5.ebuild 1783 RMD160 90d3afe99ddb777af8f5a44dd74125afa3c22294 SHA1 2df17cc733e2296d98386a2cae1495aa2d651f10 SHA256 13bac6d7704dbcb90fc122ca95638ffadd60b080ee2d1aa46137c0578e502e33
60 +MISC ChangeLog 10729 RMD160 7049a6a447ea511d28637ef0025e571de2736fbe SHA1 8dc8c85c0569c8bfbc5c41f722da6346e7c3367e SHA256 c061dd75a5f7d66aa22d242a4eef62f0407c0f3320aab7caf900c9fdbd72779f
61 MISC metadata.xml 578 RMD160 7ea189a37d0f863ae9c52170bb85df27d21686fb SHA1 4765c25d7770a69f7b9dda2b1accc8ff27b74ad0 SHA256 64140e091b51002a5355d8fcfd351f2f39ed63da68af3a5751fc2058d0d03813
62 -----BEGIN PGP SIGNATURE-----
63 Version: GnuPG v2.0.17 (GNU/Linux)
64
65 -iEYEAREIAAYFAk7jaAsACgkQl5yvQNBFVTVnDgCdH4CHTZnM94b0iPd4hY1nzYX8
66 -WnIAn3cFEy8dsKBzkDnij/A2GOBS7ScZ
67 -=ATYH
68 +iEYEAREIAAYFAk7mfrYACgkQl5yvQNBFVTWdlQCfQaFOuQ9o9dazrTr0y6m4ZAYe
69 +keEAnixAPEyLZ7P/MTq9G3+/gUGrWn0u
70 +=FCQH
71 -----END PGP SIGNATURE-----
72
73 diff --git a/sys-kernel/hardened-sources/hardened-sources-2.6.32-r81.ebuild b/sys-kernel/hardened-sources/hardened-sources-2.6.32-r81.ebuild
74 new file mode 100644
75 index 0000000..6d0feb4
76 --- /dev/null
77 +++ b/sys-kernel/hardened-sources/hardened-sources-2.6.32-r81.ebuild
78 @@ -0,0 +1,49 @@
79 +# Copyright 1999-2011 Gentoo Foundation
80 +# Distributed under the terms of the GNU General Public License v2
81 +# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-2.6.32-r80.ebuild,v 1.1 2011/12/10 14:03:42 blueness Exp $
82 +
83 +EAPI="4"
84 +
85 +ETYPE="sources"
86 +K_WANT_GENPATCHES="base extras"
87 +K_GENPATCHES_VER="46"
88 +K_DEBLOB_AVAILABLE="1"
89 +
90 +inherit kernel-2
91 +detect_version
92 +
93 +HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-83"
94 +HGPV_URI="http://dev.gentoo.org/~blueness/hardened-sources/hardened-patches/hardened-patches-${HGPV}.extras.tar.bz2"
95 +SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}"
96 +
97 +UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2"
98 +UNIPATCH_EXCLUDE="2901_kbuild-fix-passing-wno-options-to-gcc-4.4.patch 4200_fbcondecor-0.9.6.patch"
99 +
100 +DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})"
101 +HOMEPAGE="http://www.gentoo.org/proj/en/hardened/"
102 +IUSE="deblob"
103 +
104 +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86"
105 +
106 +pkg_postinst() {
107 + kernel-2_pkg_postinst
108 +
109 + local GRADM_COMPAT="sys-apps/gradm-2.2.2*"
110 +
111 + ewarn
112 + ewarn "Hardened Gentoo provides three different predefined grsecurity level:"
113 + ewarn "[server], [workstation], and [virtualization]."
114 + ewarn
115 + ewarn "Those who intend to use one of these predefined grsecurity levels"
116 + ewarn "should read the help associated with the level. Users importing a"
117 + ewarn "kernel configuration from a kernel prior to ${PN}-2.6.32,"
118 + ewarn "should review their selected grsecurity/PaX options carefully."
119 + ewarn
120 + ewarn "Users of grsecurity's RBAC system must ensure they are using"
121 + ewarn "${GRADM_COMPAT}, which is compatible with ${PF}."
122 + ewarn "It is strongly recommended that the following command is issued"
123 + ewarn "prior to booting a ${PF} kernel for the first time:"
124 + ewarn
125 + ewarn "emerge -na =${GRADM_COMPAT}"
126 + ewarn
127 +}
128
129 diff --git a/sys-kernel/hardened-sources/hardened-sources-3.1.5.ebuild b/sys-kernel/hardened-sources/hardened-sources-3.1.5.ebuild
130 new file mode 100644
131 index 0000000..fd369f2
132 --- /dev/null
133 +++ b/sys-kernel/hardened-sources/hardened-sources-3.1.5.ebuild
134 @@ -0,0 +1,49 @@
135 +# Copyright 1999-2011 Gentoo Foundation
136 +# Distributed under the terms of the GNU General Public License v2
137 +# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-3.1.4-r1.ebuild,v 1.1 2011/12/10 14:07:32 blueness Exp $
138 +
139 +EAPI="4"
140 +
141 +ETYPE="sources"
142 +K_WANT_GENPATCHES="base extras"
143 +K_GENPATCHES_VER="8"
144 +K_DEBLOB_AVAILABLE="1"
145 +
146 +inherit kernel-2
147 +detect_version
148 +
149 +HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-1"
150 +HGPV_URI="http://dev.gentoo.org/~blueness/hardened-sources/hardened-patches/hardened-patches-${HGPV}.extras.tar.bz2"
151 +SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}"
152 +
153 +UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2"
154 +UNIPATCH_EXCLUDE="4200_fbcondecor-0.9.6.patch"
155 +
156 +DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})"
157 +HOMEPAGE="http://www.gentoo.org/proj/en/hardened/"
158 +IUSE="deblob"
159 +
160 +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86"
161 +
162 +pkg_postinst() {
163 + kernel-2_pkg_postinst
164 +
165 + local GRADM_COMPAT="sys-apps/gradm-2.2.2*"
166 +
167 + ewarn
168 + ewarn "Hardened Gentoo provides three different predefined grsecurity level:"
169 + ewarn "[server], [workstation], and [virtualization]."
170 + ewarn
171 + ewarn "Those who intend to use one of these predefined grsecurity levels"
172 + ewarn "should read the help associated with the level. Users importing a"
173 + ewarn "kernel configuration from a kernel prior to ${PN}-2.6.32,"
174 + ewarn "should review their selected grsecurity/PaX options carefully."
175 + ewarn
176 + ewarn "Users of grsecurity's RBAC system must ensure they are using"
177 + ewarn "${GRADM_COMPAT}, which is compatible with ${PF}."
178 + ewarn "It is strongly recommended that the following command is issued"
179 + ewarn "prior to booting a ${PF} kernel for the first time:"
180 + ewarn
181 + ewarn "emerge -na =${GRADM_COMPAT}"
182 + ewarn
183 +}