Gentoo Logo
Gentoo Spaceship

Installation:
Gentoo Handbook
Installation Docs

Documentation:
Home
Listing
About Gentoo
Philosophy
Social Contract

Resources:
Bug Tracker
Developer List
Discussion Forums
Gentoo BitTorrents
Gentoo Linux Enhancement Proposals
IRC Channels
Mailing Lists
Mirrors
Name and Logo Guidelines
Online Package Database
Security Announcements
Staffing Needs
Supporting Vendors
View our CVS

Graphics:
Logos and themes
Icons
ScreenShots

Miscellaneous Resources:
Gentoo Linux Store
Gentoo-hosted projects
IBM dW/Intel article archive




List Archive: gentoo-hardened
Navigation:
Lists: gentoo-hardened: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-hardened@g.o
From: RB <aoz.syn@...>
Subject: Re: "How hard" is Linux kernel-side hardening?
Date: Mon, 21 Sep 2009 09:46:15 -0600
On Mon, Sep 21, 2009 at 09:10, Marco Venutti <veeenrg@...> wrote:
> I see the GR-Security, provided in Hardened Gentoo,
> is not the bare patch, but an "itself-patched" version,
> so I'm wondering if these improvements become
> part of the (following releases of the) official patch,

The Gentoo patches for the hardened kernel are largely cosmetic,
changing configure-time portions to fit the Gentoo world-view.  For
the 2.6.29 kernel, they:

 - Remove 'grsec' from the kernel's version text
 - Reduce the compile-time warnings produced by grsecurity
 - Allow PaX to be enabled without enabling grsecurity
 - Set different (Gentoo-appropriate) default GIDs for the logging &
restriction portions
 - Add Gentoo's profiles (server, workstation, etc.) for grsecuriity
 - Add the source IP to SELinux AVC messages (the only functional change)
 - Completely remove the ability to enable COMPAT_VDSO

> or not; I'm asking this just because, if improvements
> are not included in the official patch, maybe it's better,
> for me, to use the gentoo-hardened-kernel-source,
> not-so-up-to-date, but improved!

Gentoo's hardened-sources is probably the way you want to go,
regardless.  It incorporates the latest version of grsecurity for the
given kernel version, and despite of being "behind" the kernel curve,
it's highly stable.


References:
"How hard" is Linux kernel-side hardening?
-- Marco Venutti
Re: "How hard" is Linux kernel-side hardening?
-- Pavel Labushev
Re: "How hard" is Linux kernel-side hardening?
-- Marco Venutti
Navigation:
Lists: gentoo-hardened: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: "How hard" is Linux kernel-side hardening?
Next by thread:
Release of Tin Hat 20091003
Previous by date:
Re: "How hard" is Linux kernel-side hardening?
Next by date:
Re: "How hard" is Linux kernel-side hardening?


Updated Nov 22, 2009

Donate to support our development efforts.

Gentoo Centric Hosting: vr.org

VR Hosted

Tek Alchemy

Tek Alchemy

SevenL.net

SevenL.net

php|architect

php|architect

Copyright 2001-2007 Gentoo Foundation, Inc. Questions, Comments? Email www@gentoo.org.