Gentoo Archives: gentoo-dev

From: Andrew Savchenko <bircoph@g.o>
To: gentoo-dev@l.g.o
Subject: [gentoo-dev] Re: News Item: OpenAFS no longer needs kernel option DEBUG_RODATA
Date: Mon, 08 Aug 2016 07:47:57
Message-Id: 20160808104740.c5fceb31f57a96e60462e3af@gentoo.org
In Reply to: [gentoo-dev] Re: News Item: OpenAFS no longer needs kernel option DEBUG_RODATA by Andrew Savchenko
1 On Mon, 1 Aug 2016 14:08:57 +0300 Andrew Savchenko wrote:
2 > Hi,
3 >
4 > On Wed, 20 Jul 2016 13:13:49 -0400 NP-Hardass wrote:
5 > > This is the first draft of a news item describing a packaging change for
6 > > OpenAFS so that we no longer require the DEBUG_RODATA be turned off.
7 >
8 > This is a second try with rewording of the first paragraph, since
9 > it was suggested that it is a bit awkward.
10 >
11 > Title: OpenAFS no longer needs kernel option DEBUG_RODATA
12 > Author: NP-Hardass <NP-Hardass@g.o>
13 > Author: Andrew Savchenko <bircoph@g.o>
14 > Content-Type: text/plain
15 > Posted: 2016-07-23
16 > Revision: 1
17 > News-Item-Format: 1.0
18 > Display-If-Installed: <=net-fs/openafs-kernel-1.6.18.2
19 > Display-If-Keyword: amd64
20 > Display-If-Keyword: ~amd64-linux
21 > Display-If-Keyword: ~sparc
22 > Display-If-Keyword: x86
23 > Display-If-Keyword: ~x86-linux
24 >
25 > As a result of bug #127084 [1], it was determined that OpenAFS's
26 > kernel module required that the kernel's data structures be
27 > read-write (CONFIG_DEBUG_RODATA=n). With recent OpenAFS versions
28 > this limitation is no longer required. We tested the latest version
29 > of OpenAFS with Linux kernels from 3.4 till 4.6, and determined that
30 > OpenAFS kernel module works fine with CONFIG_DEBUG_RODATA=y.
31 >
32 > Starting with net-fs/openafs-kernel-1.6.18.2, this condition is no
33 > longer forced in the ebuild. Considering the security implications
34 > of having CONFIG_DEBUG_RODATA turned off, it is highly advised that
35 > you adjust your kernel config accordingly. Please note that the
36 > default setting for CONFIG_DEBUG_RODATA is "y" and unless you have
37 > another reason for keeping it disabled, we highly recommend that
38 > you re-enable CONFIG_DEBUG_RODATA.
39 >
40 > [1] https://bugs.gentoo.org/show_bug.cgi?id=127084
41
42 No comments for a week => submitted.
43
44 Best regards,
45 Andrew Savchenko