1 |
> Has anyone done anything like this? Is it silly to even think that the |
2 |
> hand-applied patches will apply without rejects? |
3 |
|
4 |
I haven't tried myself, but I have read in a few spots that it can't be |
5 |
done. |
6 |
|
7 |
> Or should I be doing a strictly Xen kernel as the host kernel and if I |
8 |
> want SELinux/PaX/GRSecurity, put that in a guest kernel? But doesn't |
9 |
> the guest kernel also have to be patched for xen? In which case the |
10 |
> original question of getting a kernel patched with all four still applies. |
11 |
|
12 |
If you use a new Intel processor with VT support or an AMD processor |
13 |
with Pacifica then you can run unmodified guest kernels. You could then |
14 |
patch your guest kernel with SELinux/PaX/GRSecurity however you pleased. |
15 |
|
16 |
There is possibly a performance hit involved with using the new |
17 |
virtualisation features in the CPU as apposed to porting the guest OS to |
18 |
run under Xen although I am not aware how much. Does anyone else know? |
19 |
|
20 |
I would certainly like to be able to run PaX, GRSecurity and Xen together. |
21 |
|
22 |
Cheers, |
23 |
|
24 |
Brad |
25 |
-- |
26 |
gentoo-hardened@g.o mailing list |