Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <basile@××××××××××××××.edu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Help testing new hardened profiles structure
Date: Mon, 08 Nov 2010 12:02:40
Message-Id: 4CD7F05F.1000108@opensource.dyc.edu
In Reply to: Re: [gentoo-hardened] Help testing new hardened profiles structure by "Claes Gyllenswärd"
1 On 11/08/2010 02:22 AM, Claes Gyllenswärd wrote:
2 > 2010/11/8 Anthony G. Basile <basile@××××××××××××××.edu>:
3 >> On 11/07/2010 01:47 PM, Claes Gyllenswärd wrote:
4 >>> 2010/11/6 Anthony G. Basile <blueness@g.o>:
5 >>>>
6 >>>> Hi hardened users,
7 >>>>
8 >>>> You may have heard by now that hardened is thinking of changing its
9 >>>> profile structure. The current structure is crazy complex and there is
10 >>>> no need for it. Basically we're going to be removing the versioning in
11 >>>> our profiles so that instead of
12 >>>>
13 >>>> [8] hardened/linux/amd64/10.0 *
14 >>>> [9] hardened/linux/amd64/10.0/no-multilib
15 >>>>
16 >>>> you will simply get
17 >>>>
18 >>>> [8] hardened/linux/amd64/10.0 *
19 >>>> [9] hardened/linux/amd64/10.0/no-multilib
20 >>>>
21 >>>> to profile-config list. (It'll be similar on the other arches). Behind
22 >>>> the scenes, we are also deprecating the various "sub-profiles" which
23 >>>> aren't even included in the profiles.desc list, like amd64/10.0/desktop,
24 >>>> /server, /developer etc.
25 >>>>
26 >>>> This isn't happening soon, so don't panic! You will get a portage news
27 >>>> item when we're about to do the switch and we will proceed slowly.
28 >>>>
29 >>>> I'm emailing the list to sollicit help in testing, espeically on the
30 >>>> minor arches which are slatted to go first. If you'd like to help out,
31 >>>> here's how:
32 >>>>
33 >>>> 1. Record your current list from emerge -ep system and emerge -ep world
34 >>>>
35 >>>> 2. git clone git://git.overlays.gentoo.org/proj/hardened-dev.git
36 >>>>
37 >>>> 3. cd hardened-dev
38 >>>>
39 >>>> 4. git branch profiles origin/profiles
40 >>>>
41 >>>> 5. git checkout profiles
42 >>>>
43 >>>> 6. mount --bind profiles/ /usr/portage/profiles
44 >>>>
45 >>>> 7. Record your emerge -ep system and emerge -ep world, and compare to
46 >>>> before.
47 >>>>
48 >>>> There should be no or only minor changes.
49 >>>>
50 >>>> Thanks.
51 >>>>
52 >>>> --
53 >>>> Anthony G. Basile, Ph.D.
54 >>>> Gentoo Developer
55 >>>>
56 >>>>
57 >>>
58 >>> This made no difference at all on stable amd64, but I never actually
59 >>> switched profile, since the instructions don't mention that.
60 >>> Should I?
61 >>
62 >> Yeah I probably should have mentioned that you need to do profile-config
63 >> list, notice whatever number corresponds to your profile and then
64 >> profile-config set <num>
65 >>
66 >> --
67 >> Anthony G. Basile, Ph. D.
68 >> Chair of Information Technology
69 >> D'Youville College
70 >> Buffalo, NY 14201
71 >> (716) 829-8197
72 >>
73 >>
74 >
75 > Done that too. No difference in the package lists at all.
76 > vimdiff pointed out a single dot in portages output, but I assume
77 > that's of no concern.
78
79 Thanks, this give me confidence that I haven't broken anything as far as
80 amd64 goes.
81
82 Any other arches. I have my own results but would like to hear others.
83
84
85 --
86 Anthony G. Basile, Ph. D.
87 Chair of Information Technology
88 D'Youville College
89 Buffalo, NY 14201
90 (716) 829-8197

Replies

Subject Author
Re: [gentoo-hardened] Help testing new hardened profiles structure William Throwe <wthrowe@×××.EDU>