1 |
answer #1: see bug #18690 |
2 |
answer #2: it's added to hardened-sources, which will soon host all the patches |
3 |
for this project, as well as extra security/stability and stable performance patches. |
4 |
|
5 |
i'd like more details, we have a couple people (natey in particular) working on systrace |
6 |
and i'm sure he'd like to know what your problem is and look into fixing it. |
7 |
the best way to get something like this in the system is to write a bug. |
8 |
|
9 |
we have long term goals for systrace including writing policies for the bulk |
10 |
of daemons in portage, and adding support for systrace to start-stop-daemon |
11 |
(see bug #18430) |
12 |
|
13 |
if you'd like to talk to us about the project or goals with systrace come by |
14 |
#gentoo-hardened on freenode :) |
15 |
|
16 |
cheers |
17 |
|
18 |
|
19 |
Joshua Brindle |
20 |
|
21 |
>>> Toby Dickenson <tdickenson@×××××××××××××××××.com> 04/03/03 09:55AM >>> |
22 |
This last week I have been taking a look at systrace, since first hearing |
23 |
about it on this list. For a while I have been looking for a "better chroot" |
24 |
for securing some daemons, and I think systrace could be it. |
25 |
|
26 |
Maintaining a systrace policy for a large daemon (I am working with Zope) is |
27 |
easier than for chroot, because there is no need to maintain a seperate set |
28 |
of files (or bind mounts) for the jail. This is particularly obvious when |
29 |
there are multiple instances of each daemon.... They can share one systrace |
30 |
policy, but a chroot solution would need seperate jails for each instance. |
31 |
|
32 |
The performance impact seems negligible, and the ability to log the use of |
33 |
incidental system calls is an unexpected bonus for intrusion detection. |
34 |
|
35 |
|
36 |
Is anyone looking at merging systrace with gentoo-sources? The 2003-03-22 |
37 |
patch has some easily resolved conflicts when merged with gentoo-sources, it |
38 |
compiles fine, but systrace doesnt function correctly when stressed. (more |
39 |
details available on request). |
40 |
|
41 |
-- |
42 |
Toby Dickenson |
43 |
http://www.geminidataloggers.com/people/tdickenson |
44 |
|
45 |
-- |
46 |
gentoo-hardened@g.o mailing list |
47 |
|
48 |
|
49 |
-- |
50 |
gentoo-hardened@g.o mailing list |