Gentoo Archives: gentoo-commits

From: "Anthony G. Basile" <blueness@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] dev/blueness:master commit in: sys-kernel/hardened-sources/
Date: Wed, 23 Nov 2011 01:55:40
Message-Id: e10ab8c1f75ae712508b2272cc0420b0d4a1491d.blueness@gentoo
1 commit: e10ab8c1f75ae712508b2272cc0420b0d4a1491d
2 Author: Anthony G. Basile <blueness <AT> gentoo <DOT> org>
3 AuthorDate: Wed Nov 23 01:55:22 2011 +0000
4 Commit: Anthony G. Basile <blueness <AT> gentoo <DOT> org>
5 CommitDate: Wed Nov 23 01:55:22 2011 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=dev/blueness.git;a=commit;h=e10ab8c1
7
8 sys-kernel/hardened-sources: testing patchset 20111120
9
10 (Portage version: 2.1.10.11/git/Linux x86_64, signed Manifest commit with key 0xD0455535)
11
12 ---
13 sys-kernel/hardened-sources/ChangeLog | 7 +++
14 sys-kernel/hardened-sources/Manifest | 22 +++++++--
15 .../hardened-sources-2.6.32-r77.ebuild | 49 ++++++++++++++++++++
16 .../hardened-sources-3.1.1-r1.ebuild | 49 ++++++++++++++++++++
17 4 files changed, 123 insertions(+), 4 deletions(-)
18
19 diff --git a/sys-kernel/hardened-sources/ChangeLog b/sys-kernel/hardened-sources/ChangeLog
20 index b54dcf4..eb4ba22 100644
21 --- a/sys-kernel/hardened-sources/ChangeLog
22 +++ b/sys-kernel/hardened-sources/ChangeLog
23 @@ -1,5 +1,12 @@
24
25
26 +*hardened-sources-3.1.1-r1 (23 Nov 2011)
27 +*hardened-sources-2.6.32-r77 (23 Nov 2011)
28 +
29 + 23 Nov 2011; Anthony G. Basile <blueness@g.o>
30 + +hardened-sources-2.6.32-r77.ebuild, +hardened-sources-3.1.1-r1.ebuild:
31 + testing patchset 20111120
32 +
33 19 Nov 2011; Anthony G. Basile <blueness@g.o> Manifest:
34 testing patchset 20111118
35
36
37 diff --git a/sys-kernel/hardened-sources/Manifest b/sys-kernel/hardened-sources/Manifest
38 index 16ed254..5aef54a 100644
39 --- a/sys-kernel/hardened-sources/Manifest
40 +++ b/sys-kernel/hardened-sources/Manifest
41 @@ -1,12 +1,26 @@
42 -----BEGIN PGP SIGNED MESSAGE-----
43 Hash: SHA256
44
45 -MISC ChangeLog 8671 RMD160 bd47539aad993aa170583b4e524efd8b315858b8 SHA1 4f203d22aa455454360e9ea52c66eac17659640b SHA256 fc01be8f9b7351110532a06040d00f9068c7714bb51097c86a8321ffab528a56
46 +DIST deblob-2.6.32 84094 RMD160 394f46ec5b869638a7bc2e87beb118167c9bd6cb SHA1 1a2a1efb72126609d9e3b9be99ae5be2751efd06 SHA256 de625f0bd221c9c38d4453f1b709622f222d86a0ae9350d2b7b0e17795e6de6d
47 +DIST deblob-3.1 103909 RMD160 723d36ef2574419417bbf30eda6a83aaa91922d7 SHA1 39d2c6e69f4e3b84e112b6e3e9389c983976fe4b SHA256 9dcf6f981cb3681f8afab0a4f814aebd6c2f46f8e635d2f35657d8344ef6b30e
48 +DIST deblob-check-2.6.32 247608 RMD160 840bf8a229ea79810519eee6241edb85b78a6562 SHA1 d45a24eb16e5ac956c0fcddbc1ac4d67e326c7b8 SHA256 da1aecdf3ab7f1207b90642d303e52262ccc2ed9e49739b729512b88950d17f3
49 +DIST deblob-check-3.1 405438 RMD160 da7efe959bc7c0017214daa764fcb486ff4434f2 SHA1 397157d3f6bf225f8cc4f48b6c05bc56482c2934 SHA256 77d125ae5466049fb3f1fe39ddb9320b66239de782a348c66133de591049db43
50 +DIST genpatches-2.6.32-44.base.tar.bz2 1012021 RMD160 37aae12613e8d5e0f3cb0ad5f6057a83846e5bdc SHA1 3f4a864c30fd445eff30b480b0b5654c5758b219 SHA256 f00a36ff4e30785eca0816bf1a698b358213e59c5786799b5bddd8322da1c633
51 +DIST genpatches-2.6.32-44.extras.tar.bz2 24902 RMD160 9e8d686ce4e2bb36e6f6310835b96f64ad8d0f08 SHA1 29ed146cfcfb4470b0f2cea9b4dad07b359c31df SHA256 e105210bca94660f3292751fea0db38c7dea50ea2c5a729faa1dbc9fb348442f
52 +DIST genpatches-3.1-4.base.tar.bz2 107620 RMD160 ffc262a61b4da49a60c09ee666b696405d956389 SHA1 1c8d681e62cf837295012369c2d28daabb1387f6 SHA256 8a025365b17b4b7ed4a5c2e03315932b3ce7c1aa76206a96a80157c57c95f6f4
53 +DIST genpatches-3.1-4.extras.tar.bz2 17200 RMD160 fa8aa6ba8bc1e554758017d371769536d025bdc1 SHA1 47240cdc21d69d2af05d0b2bd7dcbb1615508f86 SHA256 b108dbf3b5ddad1701cacd2f1c936a63b60d1a4cd86fd7f9311230e3bacac56b
54 +DIST hardened-patches-2.6.32-79.extras.tar.bz2 511382 RMD160 a834552cec03b09c1621d263b6ba91af6707b5e3 SHA1 819ace7c9672ec64d1a659d75c012456060bd015 SHA256 29e67427383fffb1808971995d23471abf0b36831838207353196842c0a64918
55 +DIST hardened-patches-3.1.1-2.extras.tar.bz2 483003 RMD160 ee59a32244dd5819c90d8162e42bc1d41206e159 SHA1 0ecc015e1facc85f4b554fdd5b48af16ed383f35 SHA256 e81a34081b9a6a31430f9da16444892985dee7b794b3d6090029921ebfad9f56
56 +DIST linux-2.6.32.tar.bz2 64424138 RMD160 b93742cbaf8174f2200d2dbef0d47a26c618039c SHA1 410b4fc818023bfef60064e973ff0ab46d3bfb19 SHA256 5099786d80b8407d98a619df00209c2353517f22d804fdd9533b362adcb4504e
57 +DIST linux-3.1.tar.bz2 77190238 RMD160 f9a3ce57b9f20a1402ef340792d3c223140ce1d2 SHA1 ac792701561b1cd4279302b8bb8f474731762ad1 SHA256 2573d2378c754b0c602b57586e9311e5b38c5d1e6c137f02873833633a4b9359
58 +EBUILD hardened-sources-2.6.32-r77.ebuild 1787 RMD160 390aa42b08f1606526d8482875348fff88b1beb6 SHA1 2097f9446e5bfe52d16d81ee53f78562c576da74 SHA256 80018cbed4459cc3a4c115403ab2b77935a0f869b5aed17fc93f4fca76dbf872
59 +EBUILD hardened-sources-3.1.1-r1.ebuild 1780 RMD160 36475878df89fbc69157be105bdf44200805e0e9 SHA1 24134ac754c3442b451b5d1733646ecf55fb6a89 SHA256 55aa89bcf6be3a64852ae40a939faf0b136cf753612c0359ca4e597d2d61fd75
60 +MISC ChangeLog 8914 RMD160 d7707487f04c77cc7da052f18ebb1e86cbb34fe5 SHA1 bfbded1f1ba3efdd3176fcc532e30fec57e14195 SHA256 ac0b048f8f3e1d63fc8a3e16a1988d2bfae55bd15f64b6e12ce3a4895c79b624
61 MISC metadata.xml 578 RMD160 7ea189a37d0f863ae9c52170bb85df27d21686fb SHA1 4765c25d7770a69f7b9dda2b1accc8ff27b74ad0 SHA256 64140e091b51002a5355d8fcfd351f2f39ed63da68af3a5751fc2058d0d03813
62 -----BEGIN PGP SIGNATURE-----
63 Version: GnuPG v2.0.17 (GNU/Linux)
64
65 -iEUEAREIAAYFAk7JevcACgkQl5yvQNBFVTVknACgloAmiObTlDasqmu0jcmfVRR4
66 -mJ0Al1jrrBmDvQFb4jGwHcpUDmREYZs=
67 -=xBkb
68 +iEYEAREIAAYFAk7MUooACgkQl5yvQNBFVTVxTwCfTw7qPdKNcyVPiMUZkwquVMPF
69 +d+IAoKDb6gyf0ofaWhBhbbD26nAxQ5Gv
70 +=GIQh
71 -----END PGP SIGNATURE-----
72
73 diff --git a/sys-kernel/hardened-sources/hardened-sources-2.6.32-r77.ebuild b/sys-kernel/hardened-sources/hardened-sources-2.6.32-r77.ebuild
74 new file mode 100644
75 index 0000000..3ab8137
76 --- /dev/null
77 +++ b/sys-kernel/hardened-sources/hardened-sources-2.6.32-r77.ebuild
78 @@ -0,0 +1,49 @@
79 +# Copyright 1999-2011 Gentoo Foundation
80 +# Distributed under the terms of the GNU General Public License v2
81 +# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-2.6.32-r76.ebuild,v 1.1 2011/11/19 18:52:26 blueness Exp $
82 +
83 +EAPI="4"
84 +
85 +ETYPE="sources"
86 +K_WANT_GENPATCHES="base extras"
87 +K_GENPATCHES_VER="44"
88 +K_DEBLOB_AVAILABLE="1"
89 +
90 +inherit kernel-2
91 +detect_version
92 +
93 +HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-79"
94 +HGPV_URI="http://dev.gentoo.org/~blueness/hardened-sources/hardened-patches/hardened-patches-${HGPV}.extras.tar.bz2"
95 +SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}"
96 +
97 +UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2"
98 +UNIPATCH_EXCLUDE="4200_fbcondecor-0.9.6.patch"
99 +
100 +DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})"
101 +HOMEPAGE="http://www.gentoo.org/proj/en/hardened/"
102 +IUSE="deblob"
103 +
104 +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86"
105 +
106 +pkg_postinst() {
107 + kernel-2_pkg_postinst
108 +
109 + local GRADM_COMPAT="sys-apps/gradm-2.2.2*"
110 +
111 + ewarn
112 + ewarn "Hardened Gentoo provides three different predefined grsecurity level:"
113 + ewarn "[server], [workstation], and [virtualization]."
114 + ewarn
115 + ewarn "Those who intend to use one of these predefined grsecurity levels"
116 + ewarn "should read the help associated with the level. Users importing a"
117 + ewarn "kernel configuration from a kernel prior to ${PN}-2.6.32,"
118 + ewarn "should review their selected grsecurity/PaX options carefully."
119 + ewarn
120 + ewarn "Users of grsecurity's RBAC system must ensure they are using"
121 + ewarn "${GRADM_COMPAT}, which is compatible with ${PF}."
122 + ewarn "It is strongly recommended that the following command is issued"
123 + ewarn "prior to booting a ${PF} kernel for the first time:"
124 + ewarn
125 + ewarn "emerge -na =${GRADM_COMPAT}"
126 + ewarn
127 +}
128
129 diff --git a/sys-kernel/hardened-sources/hardened-sources-3.1.1-r1.ebuild b/sys-kernel/hardened-sources/hardened-sources-3.1.1-r1.ebuild
130 new file mode 100644
131 index 0000000..ed95940
132 --- /dev/null
133 +++ b/sys-kernel/hardened-sources/hardened-sources-3.1.1-r1.ebuild
134 @@ -0,0 +1,49 @@
135 +# Copyright 1999-2011 Gentoo Foundation
136 +# Distributed under the terms of the GNU General Public License v2
137 +# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-3.1.1.ebuild,v 1.1 2011/11/19 18:57:05 blueness Exp $
138 +
139 +EAPI="4"
140 +
141 +ETYPE="sources"
142 +K_WANT_GENPATCHES="base extras"
143 +K_GENPATCHES_VER="4"
144 +K_DEBLOB_AVAILABLE="1"
145 +
146 +inherit kernel-2
147 +detect_version
148 +
149 +HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-2"
150 +HGPV_URI="http://dev.gentoo.org/~blueness/hardened-sources/hardened-patches/hardened-patches-${HGPV}.extras.tar.bz2"
151 +SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}"
152 +
153 +UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2"
154 +UNIPATCH_EXCLUDE="4200_fbcondecor-0.9.6.patch"
155 +
156 +DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})"
157 +HOMEPAGE="http://www.gentoo.org/proj/en/hardened/"
158 +IUSE="deblob"
159 +
160 +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86"
161 +
162 +pkg_postinst() {
163 + kernel-2_pkg_postinst
164 +
165 + local GRADM_COMPAT="sys-apps/gradm-2.2.2*"
166 +
167 + ewarn
168 + ewarn "Hardened Gentoo provides three different predefined grsecurity level:"
169 + ewarn "[server], [workstation], and [virtualization]."
170 + ewarn
171 + ewarn "Those who intend to use one of these predefined grsecurity levels"
172 + ewarn "should read the help associated with the level. Users importing a"
173 + ewarn "kernel configuration from a kernel prior to ${PN}-2.6.32,"
174 + ewarn "should review their selected grsecurity/PaX options carefully."
175 + ewarn
176 + ewarn "Users of grsecurity's RBAC system must ensure they are using"
177 + ewarn "${GRADM_COMPAT}, which is compatible with ${PF}."
178 + ewarn "It is strongly recommended that the following command is issued"
179 + ewarn "prior to booting a ${PF} kernel for the first time:"
180 + ewarn
181 + ewarn "emerge -na =${GRADM_COMPAT}"
182 + ewarn
183 +}