Gentoo Archives: gentoo-hardened

From: Brad Plant <bplant@×××××××××××.au>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Obtaining a Xen/SELinux/PaX/GRSecurity kernel
Date: Sun, 07 May 2006 05:32:35
Message-Id: 445D8570.90809@westnet.com.au
In Reply to: [gentoo-hardened] Obtaining a Xen/SELinux/PaX/GRSecurity kernel by Kevin
1 > Has anyone done anything like this? Is it silly to even think that the
2 > hand-applied patches will apply without rejects?
3
4 I haven't tried myself, but I have read in a few spots that it can't be
5 done.
6
7 > Or should I be doing a strictly Xen kernel as the host kernel and if I
8 > want SELinux/PaX/GRSecurity, put that in a guest kernel? But doesn't
9 > the guest kernel also have to be patched for xen? In which case the
10 > original question of getting a kernel patched with all four still applies.
11
12 If you use a new Intel processor with VT support or an AMD processor
13 with Pacifica then you can run unmodified guest kernels. You could then
14 patch your guest kernel with SELinux/PaX/GRSecurity however you pleased.
15
16 There is possibly a performance hit involved with using the new
17 virtualisation features in the CPU as apposed to porting the guest OS to
18 run under Xen although I am not aware how much. Does anyone else know?
19
20 I would certainly like to be able to run PaX, GRSecurity and Xen together.
21
22 Cheers,
23
24 Brad
25 --
26 gentoo-hardened@g.o mailing list