1 |
On Tue, 2006-09-26 at 20:36 -0400, Andy Dustman wrote: |
2 |
> So what's the status of Gentoo SELinux these days? The handbook seems |
3 |
> to be updated in the last month, so I guess it's not dead. Just hard |
4 |
> for me (as a non-dev) to see much going on. I have noticed though that |
5 |
> glibc-2.4 and gcc-4 are still masked, which makes me think this is |
6 |
> what was previously referred to by a "non-broken toolchain"? Or are |
7 |
> migration problems the real issue (based on comments in package.mask)? |
8 |
> Are anywhere close to having a selinux/2006.1 profile or is 2007.0 |
9 |
> more realistic? And for a new installation, it looks like it might be |
10 |
> best to avoid 2006.1 in favor of 2006.0 or earlier, since 2006.1 has |
11 |
> glibc-2.4 and gcc-4.1. |
12 |
|
13 |
Waiting for the next SELinux toolchain release, which has fixes we need |
14 |
for the refpolicy configuration that will be used. I'm told this should |
15 |
be released in the next week or so. This is the toolchain we're |
16 |
referring to. Glibc 2.4 and gcc 4.1 being masked is because the |
17 |
hardened compiler is not available in gcc yet. However, SELinux |
18 |
userland now needs glibc 2.4, so unfortunately people running hardened |
19 |
SELinux systems will be in trouble until the hardened compiler is |
20 |
available for gcc 4.1. |
21 |
|
22 |
The policy ebuilds and eclass are ready, and the docs are mostly |
23 |
written. We just need the next toolchain release (which also blocks |
24 |
refpolicy's release). Then we'll put out a profile and then those that |
25 |
want to test can do so. |
26 |
|
27 |
-- |
28 |
Chris PeBenito |
29 |
<pebenito@g.o> |
30 |
Developer, |
31 |
Hardened Gentoo Linux |
32 |
|
33 |
Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
34 |
Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |