Gentoo Archives: gentoo-commits

From: "Anthony G. Basile" <blueness@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] dev/blueness:master commit in: sys-kernel/hardened-sources/
Date: Sun, 30 Oct 2011 13:12:44
Message-Id: 5400c7cea9a6592f20475c1c48816f89e1aa2efa.blueness@gentoo
1 commit: 5400c7cea9a6592f20475c1c48816f89e1aa2efa
2 Author: Anthony G. Basile <blueness <AT> gentoo <DOT> org>
3 AuthorDate: Sun Oct 30 13:12:28 2011 +0000
4 Commit: Anthony G. Basile <blueness <AT> gentoo <DOT> org>
5 CommitDate: Sun Oct 30 13:12:28 2011 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=dev/blueness.git;a=commit;h=5400c7ce
7
8 sys-kernel/hardened-sources: testing patchset 201110250925
9
10 (Portage version: 2.1.10.11/git/Linux x86_64, signed Manifest commit with key 0xD0455535)
11
12 ---
13 sys-kernel/hardened-sources/ChangeLog | 7 +++
14 sys-kernel/hardened-sources/Manifest | 22 +++++++--
15 .../hardened-sources-2.6.32-r73.ebuild | 49 ++++++++++++++++++++
16 .../hardened-sources/hardened-sources-3.0.8.ebuild | 49 ++++++++++++++++++++
17 4 files changed, 123 insertions(+), 4 deletions(-)
18
19 diff --git a/sys-kernel/hardened-sources/ChangeLog b/sys-kernel/hardened-sources/ChangeLog
20 index 2c657be..90626c2 100644
21 --- a/sys-kernel/hardened-sources/ChangeLog
22 +++ b/sys-kernel/hardened-sources/ChangeLog
23 @@ -1,5 +1,12 @@
24
25
26 +*hardened-sources-3.0.8 (30 Oct 2011)
27 +*hardened-sources-2.6.32-r73 (30 Oct 2011)
28 +
29 + 30 Oct 2011; Anthony G. Basile <blueness@g.o>
30 + +hardened-sources-2.6.32-r73.ebuild, +hardened-sources-3.0.8.ebuild:
31 + Testing patchset 201110250925
32 +
33 23 Oct 2011; Anthony G. Basile <blueness@g.o>
34 -hardened-sources-2.6.32-r71.ebuild, -hardened-sources-3.0.7.ebuild:
35 Moved to tree
36
37 diff --git a/sys-kernel/hardened-sources/Manifest b/sys-kernel/hardened-sources/Manifest
38 index 2694fb3..05064a4 100644
39 --- a/sys-kernel/hardened-sources/Manifest
40 +++ b/sys-kernel/hardened-sources/Manifest
41 @@ -1,12 +1,26 @@
42 -----BEGIN PGP SIGNED MESSAGE-----
43 Hash: SHA256
44
45 -MISC ChangeLog 6711 RMD160 1a93a6db7635ea7c6933c03ca3ccb8f324ee5ed4 SHA1 c2bcfc512e1b80b619d54339a74ac5ea60c4b98b SHA256 4d870474618a0a70f37ac3271d6ebbf1f6bfd51922fd9c74d10d9c6e68d2774e
46 +DIST deblob-2.6.32 84094 RMD160 394f46ec5b869638a7bc2e87beb118167c9bd6cb SHA1 1a2a1efb72126609d9e3b9be99ae5be2751efd06 SHA256 de625f0bd221c9c38d4453f1b709622f222d86a0ae9350d2b7b0e17795e6de6d
47 +DIST deblob-3.0 102531 RMD160 d3ea6f04cd4d6c7f652f4532e7558f931d3952d1 SHA1 3702cec9da20b8c1141e0fee2549fd475e203812 SHA256 4c9d98faabc226602891e6eb36634f1c228017bb90f0d3ceaa42d41d4b27df0f
48 +DIST deblob-check-2.6.32 247608 RMD160 840bf8a229ea79810519eee6241edb85b78a6562 SHA1 d45a24eb16e5ac956c0fcddbc1ac4d67e326c7b8 SHA256 da1aecdf3ab7f1207b90642d303e52262ccc2ed9e49739b729512b88950d17f3
49 +DIST deblob-check-3.0 377076 RMD160 8a4f53f0a34c46fc6a2aae5878225851d7bf13e1 SHA1 b1b356f55f63746bba284644db8585d15f3da06f SHA256 72ab3f74cbcde9d453f8a4e30fd6a6339812806fe6dab3b632c1c68b90b0b104
50 +DIST genpatches-2.6.32-43.base.tar.bz2 979911 RMD160 d221c448adb8116fa328304f7cde9ce92f6c5432 SHA1 6038e46e09e8dccbf80563998fc9ebd14718d0e3 SHA256 92f71a7ac87fd7117ce28e1666e8c95473cd4b4701a78984c2ba4b87d0a8c705
51 +DIST genpatches-2.6.32-43.extras.tar.bz2 24897 RMD160 fac4ce9c15953ad811b2c500b0145f2eebea5e2d SHA1 8f9cdf4bc06dc5e806698d93c002798faa53fda1 SHA256 309841a94e96d7076bca7fb547caae9786e24258e032da242f64768a413ddbf0
52 +DIST genpatches-3.0-8.base.tar.bz2 216509 RMD160 4ca8618b482a013adea3b5a66222975288c3f589 SHA1 68caec5b7080ab7140ad09ec7caa3414f185e5f8 SHA256 857d6ccd8bf965ec82c944c229218fb71a37c0c13f26228dc69c4e556dbfa17d
53 +DIST genpatches-3.0-8.extras.tar.bz2 17207 RMD160 0f04fef1fe76c9b9cbe7c497faae19b015caff72 SHA1 89935647c22c0a8b98dd568e97312ca64378a263 SHA256 ec88ca4408c668a2c4d2d25c3d4a8c67fad4bb08133db91bbb929c0053305fda
54 +DIST hardened-patches-2.6.32-75.extras.tar.bz2 503981 RMD160 e1fd0769e595f15c8646b537b90c610d6e3f1726 SHA1 ccb4161fc4d1d2965df75d7f0975581a5bae196d SHA256 eb950ae795deda34a599cde01250270693aba782168dbb741f884da0db6ff3a2
55 +DIST hardened-patches-3.0.8-1.extras.tar.bz2 484808 RMD160 86d667c9428bc622ac18cc6a7e97b71b2374e97a SHA1 c5d91f02ab7a723413e376f5292e08ac0554b547 SHA256 53007d9c3174243af0f9f812bc274098cd3cd9471835360d6884bab169f17ef8
56 +DIST linux-2.6.32.tar.bz2 64424138 RMD160 b93742cbaf8174f2200d2dbef0d47a26c618039c SHA1 410b4fc818023bfef60064e973ff0ab46d3bfb19 SHA256 5099786d80b8407d98a619df00209c2353517f22d804fdd9533b362adcb4504e
57 +DIST linux-3.0.tar.bz2 76753134 RMD160 e20c9564ec0c8128e28a4c038986d4d93bbe34bb SHA1 45b64bffc860f70ab7956da4493c488010714650 SHA256 64b0228b54ce39b0b2df086109a7b737cde58e3df4f779506ddcaccee90356a0
58 +EBUILD hardened-sources-2.6.32-r73.ebuild 1835 RMD160 8bb8d8be2bb6227fcf41a9cb6d3c1ef2512df0f3 SHA1 46204307229946c28c1b3275f26df0253a487488 SHA256 1edf485c1a409bf8072b7c3453d9d9543cb3648eb24f6845a53062f24b069796
59 +EBUILD hardened-sources-3.0.8.ebuild 1783 RMD160 b619e60b4b217ddfeaa27c986827854598023c42 SHA1 3d9f60a2d47f041f089a3f7543acec69548cb1a0 SHA256 0c6f2f20756bb13b5a58aecedde883fbd9f3d1824e2ca25efc4a8d71e4188e7f
60 +MISC ChangeLog 6952 RMD160 1d567424265677eb04bbf0f31f3d364568b2fa04 SHA1 05c00cffeae6ad9f36342e928dd44134cc8411d2 SHA256 a99593b1ad643d14e4de208ee12d53325bbca5f2570e1ec882e1c6619d989ee1
61 MISC metadata.xml 578 RMD160 7ea189a37d0f863ae9c52170bb85df27d21686fb SHA1 4765c25d7770a69f7b9dda2b1accc8ff27b74ad0 SHA256 64140e091b51002a5355d8fcfd351f2f39ed63da68af3a5751fc2058d0d03813
62 -----BEGIN PGP SIGNATURE-----
63 Version: GnuPG v2.0.17 (GNU/Linux)
64
65 -iEYEAREIAAYFAk6j+GMACgkQl5yvQNBFVTVhpQCdGy9EKylojbeqoWpByYSn+Fs2
66 -0t4AnAqKMGsHoYr27PKg9ekr0oqUxsFU
67 -=FSDK
68 +iEYEAREIAAYFAk6tTTwACgkQl5yvQNBFVTWZYACeLvxZn1dqu9rc1o4+Mdl5zONW
69 +CxoAmgNOBSNCAIIRR16AwzCZer2BiPXN
70 +=JYrb
71 -----END PGP SIGNATURE-----
72
73 diff --git a/sys-kernel/hardened-sources/hardened-sources-2.6.32-r73.ebuild b/sys-kernel/hardened-sources/hardened-sources-2.6.32-r73.ebuild
74 new file mode 100644
75 index 0000000..e4ee7cb
76 --- /dev/null
77 +++ b/sys-kernel/hardened-sources/hardened-sources-2.6.32-r73.ebuild
78 @@ -0,0 +1,49 @@
79 +# Copyright 1999-2011 Gentoo Foundation
80 +# Distributed under the terms of the GNU General Public License v2
81 +# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-2.6.32-r72.ebuild,v 1.1 2011/10/30 00:35:55 blueness Exp $
82 +
83 +EAPI="4"
84 +
85 +ETYPE="sources"
86 +K_WANT_GENPATCHES="base extras"
87 +K_GENPATCHES_VER="43"
88 +K_DEBLOB_AVAILABLE="1"
89 +
90 +inherit kernel-2
91 +detect_version
92 +
93 +HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-75"
94 +HGPV_URI="http://dev.gentoo.org/~blueness/hardened-sources/hardened-patches/hardened-patches-${HGPV}.extras.tar.bz2"
95 +SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}"
96 +
97 +UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2"
98 +UNIPATCH_EXCLUDE="2000_fix-broken-backport-for-ipv6-tunnels.patch 4200_fbcondecor-0.9.6.patch"
99 +
100 +DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})"
101 +HOMEPAGE="http://www.gentoo.org/proj/en/hardened/"
102 +IUSE="deblob"
103 +
104 +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86"
105 +
106 +pkg_postinst() {
107 + kernel-2_pkg_postinst
108 +
109 + local GRADM_COMPAT="sys-apps/gradm-2.2.2*"
110 +
111 + ewarn
112 + ewarn "Hardened Gentoo provides three different predefined grsecurity level:"
113 + ewarn "[server], [workstation], and [virtualization]."
114 + ewarn
115 + ewarn "Those who intend to use one of these predefined grsecurity levels"
116 + ewarn "should read the help associated with the level. Users importing a"
117 + ewarn "kernel configuration from a kernel prior to ${PN}-2.6.32,"
118 + ewarn "should review their selected grsecurity/PaX options carefully."
119 + ewarn
120 + ewarn "Users of grsecurity's RBAC system must ensure they are using"
121 + ewarn "${GRADM_COMPAT}, which is compatible with ${PF}."
122 + ewarn "It is strongly recommended that the following command is issued"
123 + ewarn "prior to booting a ${PF} kernel for the first time:"
124 + ewarn
125 + ewarn "emerge -na =${GRADM_COMPAT}"
126 + ewarn
127 +}
128
129 diff --git a/sys-kernel/hardened-sources/hardened-sources-3.0.8.ebuild b/sys-kernel/hardened-sources/hardened-sources-3.0.8.ebuild
130 new file mode 100644
131 index 0000000..fb434f7
132 --- /dev/null
133 +++ b/sys-kernel/hardened-sources/hardened-sources-3.0.8.ebuild
134 @@ -0,0 +1,49 @@
135 +# Copyright 1999-2011 Gentoo Foundation
136 +# Distributed under the terms of the GNU General Public License v2
137 +# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-3.0.7-r1.ebuild,v 1.1 2011/10/30 00:29:16 blueness Exp $
138 +
139 +EAPI="4"
140 +
141 +ETYPE="sources"
142 +K_WANT_GENPATCHES="base extras"
143 +K_GENPATCHES_VER="8"
144 +K_DEBLOB_AVAILABLE="1"
145 +
146 +inherit kernel-2
147 +detect_version
148 +
149 +HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-1"
150 +HGPV_URI="http://dev.gentoo.org/~blueness/hardened-sources/hardened-patches/hardened-patches-${HGPV}.extras.tar.bz2"
151 +SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}"
152 +
153 +UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2"
154 +UNIPATCH_EXCLUDE="4200_fbcondecor-0.9.6.patch"
155 +
156 +DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})"
157 +HOMEPAGE="http://www.gentoo.org/proj/en/hardened/"
158 +IUSE="deblob"
159 +
160 +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86"
161 +
162 +pkg_postinst() {
163 + kernel-2_pkg_postinst
164 +
165 + local GRADM_COMPAT="sys-apps/gradm-2.2.2*"
166 +
167 + ewarn
168 + ewarn "Hardened Gentoo provides three different predefined grsecurity level:"
169 + ewarn "[server], [workstation], and [virtualization]."
170 + ewarn
171 + ewarn "Those who intend to use one of these predefined grsecurity levels"
172 + ewarn "should read the help associated with the level. Users importing a"
173 + ewarn "kernel configuration from a kernel prior to ${PN}-2.6.32,"
174 + ewarn "should review their selected grsecurity/PaX options carefully."
175 + ewarn
176 + ewarn "Users of grsecurity's RBAC system must ensure they are using"
177 + ewarn "${GRADM_COMPAT}, which is compatible with ${PF}."
178 + ewarn "It is strongly recommended that the following command is issued"
179 + ewarn "prior to booting a ${PF} kernel for the first time:"
180 + ewarn
181 + ewarn "emerge -na =${GRADM_COMPAT}"
182 + ewarn
183 +}