Gentoo Archives: gentoo-hardened

From: Ned Ludd <solar@g.o>
To: gentoo-hardened@g.o
Subject: Re: [gentoo-hardened] Grsecurity 2 in hardened-sources
Date: Mon, 09 Jun 2003 21:07:28
Message-Id: 1055192829.13370.344.camel@simple
In Reply to: Re: [gentoo-hardened] Grsecurity 2 in hardened-sources by Joshua Brindle
1 On Mon, 2003-06-09 at 16:12, Joshua Brindle wrote:
2 > I'd rather you use SLOT's, this is what they are for..
3 > otherwise in a few months you are going to have a
4 > sys-apps/gradm2 and you won't be able to move it
5 > (you can but it's overly complicated).
6 >
7 > you can just have gradm-1 in slot one that installs to
8 > /usr/sbin/gradm and gradm-2 in slot two that installs to
9 > /usr/sbin/gradm2 and they won't conflict, you could even
10 > give them different policy directories so that they don't
11 > collide.
12
13 > You could then have both slots merged in next to each other
14 > and it wouldn't be an issue..
15
16 I dont see how this could/would prevent users that have ~arch keywords
17 from installing gradm-2 when using -sources other than hardened-sources.
18
19 Ok say we have ~arch in our keywords and we are using
20 gentoo-sources-2.4.20-r5(grsecurity 1.9.x) and we do emerge world
21 the next time we come back to this box it would end up having >=gradm-2
22 installed and we would not be able to enable/disable the acl system.
23
24 > the apache apache2 slot mess is really not SLOT'S fault, it's
25 > something different altogether, we have plenty of apps that
26 > have been happily slotted for a very long time (db, gtk, et al)
27
28 SLOTS do not seem to properly address who is using what sources. Example
29 ever had a box running apache1 and had ~x86 in your keywords and did
30 'emerge world' portage will override your previous install of apache1
31 and force you to use apache2 [doh!]. This is my concern with gradm-1 &
32 gradm-2.
33
34 If you or anybody on this list knows of a way to make this behave
35 correctly with these settings then please by all meens submit your
36 ebuild for gradm-2.0_pre4 (or fix portage so it honors whats installed
37 already when using ~arch flags)
38
39 --
40 Ned Ludd <solar@g.o>
41 Gentoo Linux (Hardened)
42
43
44 --
45 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Grsecurity 2 in hardened-sources Jesse Jacobs <jesse@×××××××××××.net>