Gentoo Archives: gentoo-hardened

From: Matt Poletiek <chill550@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] My first hardened install
Date: Sun, 20 May 2007 12:03:15
Message-Id: 1d624cdd0705200500s54cdf10fsfb88fdab369b9332@mail.gmail.com
In Reply to: Re: [gentoo-hardened] My first hardened install by Michael
1 Well kernel only didn't work, recompiling paxtest only didn't work
2 either. It feels like a safe assumption that compat-vdso affects glibc
3 somehow, but I still cant validate that it was the culprit in the
4 first place :S
5
6 On 5/20/07, Michael <mycroes@××××××.nl> wrote:
7 > I don't think you need to recompile your userland/toolchain. How many
8 > package do you think use the kernel config when compiling? Or use output
9 > generated by the kernel that would differ when using compat-vdso or
10 > whatever? Whether it's needed or not, yo're better off by first trying
11 > kernel only, but I'm about 99% sure you don't need to recompile your
12 > userland. Since you're using a hardened stage compiler flags should all
13 > be set correctly too, and that's what really matters...
14 > Regards,
15 >
16 > Michael
17 >
18 > Op zondag 20-05-2007 om 04:32 uur [tijdzone -0600], schreef Matt
19 > Poletiek:
20 > > Im guessing this might require a toolchain/userland rebuild if
21 > > COMPAT_VDSO is the culprit since a recompile-reboot didnt change the
22 > > output of paxtest. Can anyone validate this?
23 > >
24 > > On 5/20/07, Matt Poletiek <chill550@×××××.com> wrote:
25 > > > Yup, I sure do have that enabled. I am pretty sure I didnt check it so
26 > > > as far as I know its enabled by default in the
27 > > > hardened-gentoo-2.6.21-r1 package.
28 > > >
29 > > > Compiling the new kernel now. Again, anyone expect ill have to rebuild
30 > > > any of the toolchain/userland?
31 > > >
32 > > > Thanks for all the help so far guys!
33 > > >
34 > > > On 5/20/07, pageexec@××××××××.hu <pageexec@××××××××.hu> wrote:
35 > > > > On 20 May 2007 at 2:19, Matt Poletiek wrote:
36 > > > >
37 > > > > > PaX --->
38 > > > > > Non-executable pages --->
39 > > > > > [*] Enforce non-executable pages
40 > > > > >
41 > > > > > is the only option I see. I hope im blind :S
42 > > > >
43 > > > > you probably enabled COMPAT_VDSO, chances are you you don't really
44 > > > > need that on gentoo ;-).
45 > > > >
46 > > > > --
47 > > > > gentoo-hardened@g.o mailing list
48 > > > >
49 > > > >
50 > > >
51 > > >
52 > > > --
53 > > > Matthew Poletiek
54 > > > www.chill-fu.net
55 > > >
56 > >
57 > >
58 > > --
59 > > Matthew Poletiek
60 > > www.chill-fu.net
61 >
62 > --
63 > gentoo-hardened@g.o mailing list
64 >
65 >
66
67
68 --
69 Matthew Poletiek
70 www.chill-fu.net
71 --
72 gentoo-hardened@g.o mailing list