1 |
Andrea Barisani wrote: |
2 |
> Hi folks! |
3 |
> |
4 |
> I'd like to announce that Systrace is back in the portage tree, it consists |
5 |
> of two packages: |
6 |
> |
7 |
> sys-apps/systrace |
8 |
> |
9 |
> |
10 |
No, remove it. |
11 |
> the userspace application that now features a ptrace backend in case the |
12 |
> kernel patch is not installed. |
13 |
> |
14 |
> sys-kernel/systrace-sources |
15 |
> |
16 |
> this is standard kernel with our base patchset + systrace patch. |
17 |
> |
18 |
> We are trying to get this in hardened-sources as well, as I said you don't |
19 |
> need the kernel patch to try this out, granted that the ptrace backend is |
20 |
> much slower and really useful only for testing/debugging purposes, in the |
21 |
> long run the patch is the way to go. |
22 |
> |
23 |
> |
24 |
Absolutely not. |
25 |
> Testing/feedback is appreciated. |
26 |
> |
27 |
> |
28 |
|
29 |
Systrace has a broken security model which allows, among other things, |
30 |
privilege escalation. It is our (hardened) opinion that it is harmful to |
31 |
security and the cause of hardened. I ask you to remove it. If you don't |
32 |
we cannot and will not support it, and will discourage its use among our |
33 |
users. |
34 |
-- |
35 |
gentoo-security@g.o mailing list |