Gentoo Archives: gentoo-hardened

From: klondike <franxisco1988@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Help testing new hardened profiles structure
Date: Wed, 10 Nov 2010 07:02:28
Message-Id: 4CDA3DA9.7030900@gmail.com
In Reply to: Re: [gentoo-hardened] Help testing new hardened profiles structure by William Throwe
1 El 09/11/10 00:56, William Throwe escribió:
2 > On 2010-11-08 07:43, Anthony G. Basile wrote:
3 >> On 11/08/2010 02:22 AM, Claes Gyllenswärd wrote:
4 >>> 2010/11/8 Anthony G. Basile <basile@××××××××××××××.edu>:
5 >>>> On 11/07/2010 01:47 PM, Claes Gyllenswärd wrote:
6 >>>>> 2010/11/6 Anthony G. Basile <blueness@g.o>:
7 >>>>>> Hi hardened users,
8 >>>>>>
9 >>>>>> You may have heard by now that hardened is thinking of changing its
10 >>>>>> profile structure. The current structure is crazy complex and there is
11 >>>>>> no need for it. Basically we're going to be removing the versioning in
12 >>>>>> our profiles so that instead of
13 >>>>>>
14 >>>>>> [8] hardened/linux/amd64/10.0 *
15 >>>>>> [9] hardened/linux/amd64/10.0/no-multilib
16 >>>>>>
17 >>>>>> you will simply get
18 >>>>>>
19 >>>>>> [8] hardened/linux/amd64/10.0 *
20 >>>>>> [9] hardened/linux/amd64/10.0/no-multilib
21 >>>>>>
22 >>>>>> to profile-config list. (It'll be similar on the other arches). Behind
23 >>>>>> the scenes, we are also deprecating the various "sub-profiles" which
24 >>>>>> aren't even included in the profiles.desc list, like amd64/10.0/desktop,
25 >>>>>> /server, /developer etc.
26 >>>>>>
27 >>>>>> This isn't happening soon, so don't panic! You will get a portage news
28 >>>>>> item when we're about to do the switch and we will proceed slowly.
29 >>>>>>
30 >>>>>> I'm emailing the list to sollicit help in testing, espeically on the
31 >>>>>> minor arches which are slatted to go first. If you'd like to help out,
32 >>>>>> here's how:
33 >>>>>>
34 >>>>>> 1. Record your current list from emerge -ep system and emerge -ep world
35 >>>>>>
36 >>>>>> 2. git clone git://git.overlays.gentoo.org/proj/hardened-dev.git
37 >>>>>>
38 >>>>>> 3. cd hardened-dev
39 >>>>>>
40 >>>>>> 4. git branch profiles origin/profiles
41 >>>>>>
42 >>>>>> 5. git checkout profiles
43 >>>>>>
44 >>>>>> 6. mount --bind profiles/ /usr/portage/profiles
45 >>>>>>
46 >>>>>> 7. Record your emerge -ep system and emerge -ep world, and compare to
47 >>>>>> before.
48 >>>>>>
49 >>>>>> There should be no or only minor changes.
50 >>>>>>
51 >>>>>> Thanks.
52 >>>>>>
53 >>>>>> --
54 >>>>>> Anthony G. Basile, Ph.D.
55 >>>>>> Gentoo Developer
56 >>>>>>
57 >>>>>>
58 >>>>> This made no difference at all on stable amd64, but I never actually
59 >>>>> switched profile, since the instructions don't mention that.
60 >>>>> Should I?
61 >>>> Yeah I probably should have mentioned that you need to do profile-config
62 >>>> list, notice whatever number corresponds to your profile and then
63 >>>> profile-config set <num>
64 >>>>
65 >>>> --
66 >>>> Anthony G. Basile, Ph. D.
67 >>>> Chair of Information Technology
68 >>>> D'Youville College
69 >>>> Buffalo, NY 14201
70 >>>> (716) 829-8197
71 >>>>
72 >>>>
73 >>> Done that too. No difference in the package lists at all.
74 >>> vimdiff pointed out a single dot in portages output, but I assume
75 >>> that's of no concern.
76 >> Thanks, this give me confidence that I haven't broken anything as far as
77 >> amd64 goes.
78 >>
79 >> Any other arches. I have my own results but would like to hear others.
80 >>
81 >>
82 > I see no change in package lists on x86 (fairly minimal install).
83 >
84 > William Throwe
85 >
86 On amd64 all equal except that it tried to apply all the updates back to
87 1Q-2004:
88 There were a lot of lines like:
89 > Performing Global Updates: /usr/portage/profiles/updates/4Q-2010
90 > (Could take a couple of minutes if you have a lot of binary packages.)
91 > .='update pass' *='binary update' #='/var/db update' @='/var/db move'
92 > s='/var/db SLOT move' %='binary move' S='binary SLOT move'
93 > p='update /etc/portage/package.*'
94 > ................
95 > ##

Attachments

File name MIME type
signature.asc application/pgp-signature