Gentoo Archives: gentoo-security

From: Joshua Brindle <method@g.o>
To: gentoo-security@l.g.o, gentoo-hardened@l.g.o
Subject: [gentoo-security] Re: [gentoo-hardened] Systrace resurrection
Date: Wed, 26 Apr 2006 13:44:51
Message-Id: 444F77BA.9020008@gentoo.org
In Reply to: [gentoo-security] Systrace resurrection by Andrea Barisani
1 Andrea Barisani wrote:
2 > Hi folks!
3 >
4 > I'd like to announce that Systrace is back in the portage tree, it consists
5 > of two packages:
6 >
7 > sys-apps/systrace
8 >
9 >
10 No, remove it.
11 > the userspace application that now features a ptrace backend in case the
12 > kernel patch is not installed.
13 >
14 > sys-kernel/systrace-sources
15 >
16 > this is standard kernel with our base patchset + systrace patch.
17 >
18 > We are trying to get this in hardened-sources as well, as I said you don't
19 > need the kernel patch to try this out, granted that the ptrace backend is
20 > much slower and really useful only for testing/debugging purposes, in the
21 > long run the patch is the way to go.
22 >
23 >
24 Absolutely not.
25 > Testing/feedback is appreciated.
26 >
27 >
28
29 Systrace has a broken security model which allows, among other things,
30 privilege escalation. It is our (hardened) opinion that it is harmful to
31 security and the cause of hardened. I ask you to remove it. If you don't
32 we cannot and will not support it, and will discourage its use among our
33 users.
34 --
35 gentoo-security@g.o mailing list

Replies

Subject Author
[gentoo-security] Re: [gentoo-hardened] Systrace resurrection Andrea Barisani <lcars@g.o>