Gentoo Archives: gentoo-hardened

From: Maxim Kammerer <mk@×××.su>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] hardened-sources-3.2.11 + i965 + x.org: possible regression
Date: Thu, 17 May 2012 18:02:22
Message-Id: CAHsXYDC7Q1QWnCsWSqWq23uHZdJan93h_uR4U4raWc0Bv_QZ6Q@mail.gmail.com
In Reply to: Re: [gentoo-hardened] hardened-sources-3.2.11 + i965 + x.org: possible regression by "Tóth Attila"
1 On Thu, May 17, 2012 at 5:40 PM, "Tóth Attila" <atoth@××××××××××.hu> wrote:
2 > How would I change the way /dev gets mounted? I don't have noexec as an
3 > option listed by mount for the udev entry.
4
5 I mount devtmpfs on /dev in initramfs, but you can add an entry to
6 /etc/fstab, too — see /etc/init.d/udev-mount for details (referring to
7 OpenRC 0.9.8.4 here).
8
9 > In my policy file Xorg is permitted to execute /dev/mem: is that no longer
10 > needed? I use the radeon driver, not the proprietary.
11
12 I didn't encounter any issues with radeon. Apparently, executing
13 /dev/mem is not needed for any open-source Xorg drivers in portage
14 tree. The only issue I have seen is that sometimes there is a /dev/mem
15 *write* failure when FB_UVESA kernel module is loaded, but that is
16 caused by GRKERNSEC_KMEM, not /dev noexec, and is apparently harmless
17 (however, I use v86d[x86emu], so YMMV).
18
19 --
20 Maxim Kammerer
21 Liberté Linux (discussion / support: http://dee.su/liberte-contribute)

Replies