Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <basile@××××××××××××××.edu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] hardened-sources-3.2.11 + i965 + x.org: possible regression
Date: Thu, 17 May 2012 15:02:14
Message-Id: 4FB4E930.10304@opensource.dyc.edu
In Reply to: Re: [gentoo-hardened] hardened-sources-3.2.11 + i965 + x.org: possible regression by RB
1 On 05/17/2012 12:16 AM, RB wrote:
2 > On Wed, May 16, 2012 at 5:40 PM, "Tóth Attila"<atoth@××××××××××.hu> wrote:
3 >> What's the difference between your kernel konfig and Liberté Linux
4 >> 2012.1's kernel konfig? Because you told it worked for you.
5 >
6 > Quite a lot, not the least of which theirs is a 32-bit kernel and
7 > mine's 64-bit. The 'diff -u' between them is 5k lines long, and
8 > instead of going through that line-by-line my intent is to take the
9 > quickest path first: start with Liberté's config on 3.3.6 and start
10 > adding my own settings until it breaks. Plus, this "old" machine is
11 > slow, it takes at least 30 minutes to compile a kernel, and given a
12 > day job it's going to take a little while to test.
13
14 Please open a bug, attach both config files. It would be useful if you
15 also identify on which options it breaks. Liberte, last I looked, has
16 quite a few hardening features off. Pay attention to GRKERNSEC_IO,
17 PAX_PAGEEXEC, PAX_KERNEXEC, PAX_MEMORY_UDEREF.
18
19 Make sure its not a toolchain issue. It is not if you keep everything
20 the same and just boot on kernel and it works, the other and it doesn't.
21
22 I don't have this card so it would be difficult for me debug this for you.
23
24 --
25 Anthony G. Basile, Ph. D.
26 Chair of Information Technology
27 D'Youville College
28 Buffalo, NY 14201
29 (716) 829-8197

Replies