Gentoo Archives: gentoo-user

From: Pandu Poluan <pandu@××××××.info>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: OT: SeAndroid build on a Gentoo System?
Date: Fri, 10 Feb 2012 17:25:58
Message-Id: CAA2qdGVe4oNz+EsWyupYTpCPx5GSj0Qz4N9ojJaeGE2hzRogtg@mail.gmail.com
In Reply to: Re: [gentoo-user] Re: OT: SeAndroid build on a Gentoo System? by Hinnerk van Bruinehsen
1 On Feb 10, 2012 3:13 PM, "Hinnerk van Bruinehsen" <
2 h.v.bruinehsen@×××××××××.de> wrote:
3 >
4 > -----BEGIN PGP SIGNED MESSAGE-----
5 > Hash: SHA1
6 >
7 > On 08.02.2012 16:23, James wrote:
8 > > Hinnerk van Bruinehsen <h.v.bruinehsen <at> fu-berlin.de> writes:
9 > >
10 > >
11 > >> I own a Galaxy Nexus - up to now I encountered a bug in finding
12 > >> the tools.jar of JDK (Google helped here) and a problem due to
13 > >> the fact that I use hardened for building (TEXTREL, I think).
14 > >> I'll try a stage 3 non hardened chroot later...
15 > >
16 > > How do you like the G. Nexus so far? Who is your (cell) service
17 > > provider?
18 > >
19 > > I'm not sure I posted this link:
20 > > http://marc.info/?l=selinux&r=1&b=201201&w=4
21 > >
22 > > Note. Russell Coker (dev for SElinux and SEandroid) is very cool
23 > > and has his up and running on Debian (Wheezy). If you get stuck,
24 > > you can search him out for help. In my experiences with Russell, he
25 > > is very friendly and helpful, particularly on the last "thingy" he
26 > > is focused on, like SEandroid.....
27 > >
28 > > thanks for keeping me posted, James
29 > >
30 > It seems as if I'm not able to setup a proper build-environment with
31 > hardened (due to chroot hardening the chroot isn't an option, either).
32 > I'll try to find time to test it on a non-hardened host or in a vm
33 > (which seems like a bad option, too, due to hardened restrictions).
34 >
35 >
36 > If I get any further, I'll try to post some updates.
37 >
38 > Concerning the phone: I'm very happy with it, as it is. It's a big
39 > upgrade from my old Wildfire.
40 > My cell service provider is Vodafone (Germany).
41 >
42 > With kind regards,
43 > Hinnerk
44 >
45
46 There are grsec knobs in sysctl that you can temporarily disable to
47 "weaken" chroot for awhile. aW simple reboot will return these knobs to its
48 default secure settings.
49
50 (There's a thread I started when I have trouble doing things in a chroot,
51 and the solution was to temporarily stable done grkernelsec features before
52 going into chroot)
53
54 Rgds,