Gentoo Archives: gentoo-hardened

From: Alexander Tsoy <alexander@××××.me>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Cleaning up the hardened profiles
Date: Sun, 27 Jan 2013 19:19:17
Message-Id: 1359314509.2454.5.camel@Nokia-N900
In Reply to: [gentoo-hardened] Cleaning up the hardened profiles by "Anthony G. Basile"
1 On вс 27 янв 2013 18:32:19 MSK, Anthony G. Basile <basile@××××××××××××××.edu> wrote:
2
3 > Hi everyone,
4 >
5 > The number of profiles in gentoo is growing *again* with the addition of
6 > release 13.0 profiles.  Because of the way stacking works, adding these
7 > to hardened means a repetition of code in a way that is not good.  I'll
8 > decide how to proceed in a week or so, let everyone know and then
9 > implement something.  Right now I'm leaning towards "test" profiles for
10 > amd64 and x86 and after some good period of testing (6 months?) just
11 > switch all of hardened from 10.0 to 13.0.
12 >
13 > While I'm at the business of rethinking the profiles, I've been
14 > wondering, does anyone use the /desktop, /developer, /server sub
15 > profiles?  I've officially only listed the following
16 >
17 >      [18]  hardened/linux/amd64 *
18 >      [19]  hardened/linux/amd64/selinux
19 >      [20]  hardened/linux/amd64/no-multilib
20 >      [21]  hardened/linux/amd64/no-multilib/selinux
21 >
22 > for amd64, and similarly for other arches.  But there also exist
23 > profiles like:
24 >
25 >          hardened/linux/amd64/desktop
26 >          hardened/linux/amd64/developer
27 >          hardened/linux/amd64/server
28 >
29 > for ia64, ppc, ppc64 and x86.  I didn't even bother to add these for
30 > mips or arm.  These are not listed in profiles.desc, so you can't
31 > eselect them, but a user could manually create those links.
32 >
33 > If no one is using them, I'll mark them deprecated, and dump them in a
34 > month or two.
35 >
36 > Comments?
37
38 I've never used these subprofiles.
39
40 --
41 Alexander Tsoy

Replies

Subject Author
Re: [gentoo-hardened] Cleaning up the hardened profiles czernitko <czernitko@×××××.com>