Gentoo Logo
Gentoo Spaceship




Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-hardened
Navigation:
Lists: gentoo-hardened: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-hardened@g.o
From: RB <aoz.syn@...>
Subject: Re: "How hard" is Linux kernel-side hardening?
Date: Mon, 21 Sep 2009 09:46:15 -0600
On Mon, Sep 21, 2009 at 09:10, Marco Venutti <veeenrg@...> wrote:
> I see the GR-Security, provided in Hardened Gentoo,
> is not the bare patch, but an "itself-patched" version,
> so I'm wondering if these improvements become
> part of the (following releases of the) official patch,

The Gentoo patches for the hardened kernel are largely cosmetic,
changing configure-time portions to fit the Gentoo world-view.  For
the 2.6.29 kernel, they:

 - Remove 'grsec' from the kernel's version text
 - Reduce the compile-time warnings produced by grsecurity
 - Allow PaX to be enabled without enabling grsecurity
 - Set different (Gentoo-appropriate) default GIDs for the logging &
restriction portions
 - Add Gentoo's profiles (server, workstation, etc.) for grsecuriity
 - Add the source IP to SELinux AVC messages (the only functional change)
 - Completely remove the ability to enable COMPAT_VDSO

> or not; I'm asking this just because, if improvements
> are not included in the official patch, maybe it's better,
> for me, to use the gentoo-hardened-kernel-source,
> not-so-up-to-date, but improved!

Gentoo's hardened-sources is probably the way you want to go,
regardless.  It incorporates the latest version of grsecurity for the
given kernel version, and despite of being "behind" the kernel curve,
it's highly stable.


References:
"How hard" is Linux kernel-side hardening?
-- Marco Venutti
Re: "How hard" is Linux kernel-side hardening?
-- Pavel Labushev
Re: "How hard" is Linux kernel-side hardening?
-- Marco Venutti
Navigation:
Lists: gentoo-hardened: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: "How hard" is Linux kernel-side hardening?
Next by thread:
Release of Tin Hat 20091003
Previous by date:
Re: "How hard" is Linux kernel-side hardening?
Next by date:
Re: "How hard" is Linux kernel-side hardening?


Updated Jun 28, 2012

Summary: Archive of the gentoo-hardened mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.