Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: Status new selinux reference policy
Date: Fri, 29 Sep 2006 01:41:58
Message-Id: 1159493950.20983.11.camel@gorn.pebenito.net
In Reply to: Re: [gentoo-hardened] Re: Status new selinux reference policy by Andy Dustman
1 On Tue, 2006-09-26 at 20:36 -0400, Andy Dustman wrote:
2 > So what's the status of Gentoo SELinux these days? The handbook seems
3 > to be updated in the last month, so I guess it's not dead. Just hard
4 > for me (as a non-dev) to see much going on. I have noticed though that
5 > glibc-2.4 and gcc-4 are still masked, which makes me think this is
6 > what was previously referred to by a "non-broken toolchain"? Or are
7 > migration problems the real issue (based on comments in package.mask)?
8 > Are anywhere close to having a selinux/2006.1 profile or is 2007.0
9 > more realistic? And for a new installation, it looks like it might be
10 > best to avoid 2006.1 in favor of 2006.0 or earlier, since 2006.1 has
11 > glibc-2.4 and gcc-4.1.
12
13 Waiting for the next SELinux toolchain release, which has fixes we need
14 for the refpolicy configuration that will be used. I'm told this should
15 be released in the next week or so. This is the toolchain we're
16 referring to. Glibc 2.4 and gcc 4.1 being masked is because the
17 hardened compiler is not available in gcc yet. However, SELinux
18 userland now needs glibc 2.4, so unfortunately people running hardened
19 SELinux systems will be in trouble until the hardened compiler is
20 available for gcc 4.1.
21
22 The policy ebuilds and eclass are ready, and the docs are mostly
23 written. We just need the next toolchain release (which also blocks
24 refpolicy's release). Then we'll put out a profile and then those that
25 want to test can do so.
26
27 --
28 Chris PeBenito
29 <pebenito@g.o>
30 Developer,
31 Hardened Gentoo Linux
32
33 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
34 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] Re: Status new selinux reference policy "Marek Wróbel" <smbmarek@×××××××××××.pl>