Gentoo Archives: gentoo-hardened

From: Michael <mycroes@××××××.nl>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] My first hardened install
Date: Sun, 20 May 2007 11:43:47
Message-Id: 1179661316.1718.4.camel@Pundit-p1-ah2
In Reply to: Re: [gentoo-hardened] My first hardened install by Matt Poletiek
1 I don't think you need to recompile your userland/toolchain. How many
2 package do you think use the kernel config when compiling? Or use output
3 generated by the kernel that would differ when using compat-vdso or
4 whatever? Whether it's needed or not, yo're better off by first trying
5 kernel only, but I'm about 99% sure you don't need to recompile your
6 userland. Since you're using a hardened stage compiler flags should all
7 be set correctly too, and that's what really matters...
8 Regards,
9
10 Michael
11
12 Op zondag 20-05-2007 om 04:32 uur [tijdzone -0600], schreef Matt
13 Poletiek:
14 > Im guessing this might require a toolchain/userland rebuild if
15 > COMPAT_VDSO is the culprit since a recompile-reboot didnt change the
16 > output of paxtest. Can anyone validate this?
17 >
18 > On 5/20/07, Matt Poletiek <chill550@×××××.com> wrote:
19 > > Yup, I sure do have that enabled. I am pretty sure I didnt check it so
20 > > as far as I know its enabled by default in the
21 > > hardened-gentoo-2.6.21-r1 package.
22 > >
23 > > Compiling the new kernel now. Again, anyone expect ill have to rebuild
24 > > any of the toolchain/userland?
25 > >
26 > > Thanks for all the help so far guys!
27 > >
28 > > On 5/20/07, pageexec@××××××××.hu <pageexec@××××××××.hu> wrote:
29 > > > On 20 May 2007 at 2:19, Matt Poletiek wrote:
30 > > >
31 > > > > PaX --->
32 > > > > Non-executable pages --->
33 > > > > [*] Enforce non-executable pages
34 > > > >
35 > > > > is the only option I see. I hope im blind :S
36 > > >
37 > > > you probably enabled COMPAT_VDSO, chances are you you don't really
38 > > > need that on gentoo ;-).
39 > > >
40 > > > --
41 > > > gentoo-hardened@g.o mailing list
42 > > >
43 > > >
44 > >
45 > >
46 > > --
47 > > Matthew Poletiek
48 > > www.chill-fu.net
49 > >
50 >
51 >
52 > --
53 > Matthew Poletiek
54 > www.chill-fu.net
55
56 --
57 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] My first hardened install Matt Poletiek <chill550@×××××.com>