Gentoo Archives: gentoo-hardened

From: Matthew Thode <prometheanfire@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] hardened-sources-3.2.11 + i965 + x.org: possible regression
Date: Thu, 17 May 2012 18:02:47
Message-Id: 4FB51E47.8010403@gentoo.org
In Reply to: Re: [gentoo-hardened] hardened-sources-3.2.11 + i965 + x.org: possible regression by Maxim Kammerer
1 On 05/17/2012 10:08 AM, Maxim Kammerer wrote:
2 > On Thu, May 17, 2012 at 5:40 PM, "Tóth Attila" <atoth@××××××××××.hu> wrote:
3 >> How would I change the way /dev gets mounted? I don't have noexec as an
4 >> option listed by mount for the udev entry.
5 >
6 > I mount devtmpfs on /dev in initramfs, but you can add an entry to
7 > /etc/fstab, too — see /etc/init.d/udev-mount for details (referring to
8 > OpenRC 0.9.8.4 here).
9 >
10 >> In my policy file Xorg is permitted to execute /dev/mem: is that no longer
11 >> needed? I use the radeon driver, not the proprietary.
12 >
13 > I didn't encounter any issues with radeon. Apparently, executing
14 > /dev/mem is not needed for any open-source Xorg drivers in portage
15 > tree. The only issue I have seen is that sometimes there is a /dev/mem
16 > *write* failure when FB_UVESA kernel module is loaded, but that is
17 > caused by GRKERNSEC_KMEM, not /dev noexec, and is apparently harmless
18 > (however, I use v86d[x86emu], so YMMV).
19 >
20 Is there a bug open for this?
21
22 --
23 -- Matthew Thode (prometheanfire)

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies