Re: Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal
"Francisco Blas Izquierdo Riera (klondike)" <[email protected]> Wed, 16 Aug 2017 16:37:14 +0200
| Newsgroups | gmane.linux.gentoo.hardened |
|---|---|
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --COF4dNMWMPDh7WFs3TUneoOPSMaIqoi7s Content-Type: multipart/mixed; boundary="fuJsb4lKDtjNcDn5Ojkij6OicfEb8Q2Fa" From: "Francisco Blas Izquierdo Riera (klondike)" <[email protected]> To: [email protected] Message-ID: <0db73725-f828-cfc3-0416-c07a502ed08f-aBrp7R+bbdUdnm+yROfE0A@public.gmane.org> Subject: Re: [gentoo-hardened] Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal References: <c5b21580-d44b-c683-8e33-fa83f8552a1f-aBrp7R+bbdUdnm+yROfE0A@public.gmane.org> <9dfffef9-e2fc-dc97-6258-219de98e8b13-aBrp7R+bbdUdnm+yROfE0A@public.gmane.org> <bdc66209-8bb9-f645-9714-8d3116a85e8e-aBrp7R+bbdUdnm+yROfE0A@public.gmane.org> <4eb0e157-b944-7833-66bd-7ed4a63ea179-/[email protected]> In-Reply-To: <4eb0e157-b944-7833-66bd-7ed4a63ea179-/[email protected]> --fuJsb4lKDtjNcDn5Ojkij6OicfEb8Q2Fa Content-Type: multipart/alternative; boundary="------------028B5C9CA80A7F31930E34BA" This is a multi-part message in MIME format. --------------028B5C9CA80A7F31930E34BA Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable El 16/08/17 a las 15:36, Robert Sharp escribi=C3=B3: > On 16/08/17 11:09, Francisco Blas Izquierdo Riera (klondike) wrote: >> El 16/08/17 a las 09:40, Marek Szuba escribi=C3=B3: >>> Two tiny bits of formal nitpicking from my side: >>> - it's "grsecurity" (not a typo, they do use a lowercase g except wh= en >>> the name appears at the beginning of a sentence), not "grsec"; >>> - the patches were not *distributed by* grsecurity, they *are* >>> grsecurity. The vendor's name is Open Source Security, Inc. >> Nowadays it is, but this hasn't always been the case. You'll notice th= e >> presence of a /dev/grsec and you'll also find grsec referenced accross= >> some old patches. Anyways I changed it. >> >> The same applies to Open Source Security, Inc. the company was founded= >> on 2008 but grsecurity has been around for much longer. That's why I >> prefer to refer to Brad Spengler and The PaX team here as they are sti= ll >> the real upstream behind Open Source Security, Inc. >> >> > Would anyone like to outline a simple process to migrate from > hardened-sources + hardened tool-chain to gentoo-sources? > Unless you want to drop userspace hardening (which most likely you don't as it is still useful on vanilla kernels) a simple copy of the .config file to gentoo sources followed by make oldconfig will work in the vast majority of cases. > Presumably if I just drag my config file across it will cause all > sorts of problems? > Nah, not really, as long as you do oldconfig you should be fine. Most of the config changes were compatimentalized under the grsecurity section. > Do I need to work backwards through the hardening guide, for example? > Definitively not :) --------------028B5C9CA80A7F31930E34BA Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html> <head> <meta content=3D"text/html; charset=3Dutf-8" http-equiv=3D"Content-Ty= pe"> </head> <body bgcolor=3D"#FFFFFF" text=3D"#000000"> <div class=3D"moz-cite-prefix">El 16/08/17 a las 15:36, Robert Sharp escribi=C3=B3:<br> </div> <blockquote cite=3D"mid:4eb0e157-b944-7833-66bd-7ed4a63ea179-/[email protected]= g" type=3D"cite"> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Du= tf-8"> <div class=3D"moz-cite-prefix">On 16/08/17 11:09, Francisco Blas Izquierdo Riera (klondike) wrote:<br> </div> <blockquote type=3D"cite" cite=3D"mid:bdc66209-8bb9-f645-9714-8d3116a85e8e-aBrp7R+bbdUdnm+yROfE0A@public.gmane.org"> <pre wrap=3D"">El 16/08/17 a las 09:40, Marek Szuba escribi=C3=B3= : </pre> <blockquote type=3D"cite"> <pre wrap=3D"">Two tiny bits of formal nitpicking from my side:= - it's "grsecurity" (not a typo, they do use a lowercase g except when the name appears at the beginning of a sentence), not "grsec"; - the patches were not *distributed by* grsecurity, they *are* grsecurity. The vendor's name is Open Source Security, Inc. </pre> </blockquote> <pre wrap=3D"">Nowadays it is, but this hasn't always been the ca= se. You'll notice the presence of a /dev/grsec and you'll also find grsec referenced accross some old patches. Anyways I changed it. The same applies to Open Source Security, Inc. the company was founded on 2008 but grsecurity has been around for much longer. That's why I prefer to refer to Brad Spengler and The PaX team here as they are still the real upstream behind Open Source Security, Inc. </pre> </blockquote> <p><font face=3D"Arial">Would anyone like to outline a simple process to migrate from hardened-sources + hardened tool-chain to gentoo-sources?</font></p> </blockquote> <font face=3D"Arial">Unless you want to drop userspace hardening (which most likely you don't as it is still useful on vanilla kernels) a simple copy of the .config file to gentoo sources followed by make oldconfig will work in the vast majority of cases.<br> <br> </font> <blockquote cite=3D"mid:4eb0e157-b944-7833-66bd-7ed4a63ea179-/[email protected]= g" type=3D"cite"> <p><font face=3D"Arial">Presumably if I just drag my config file across it will cause all sorts of problems?</font></p> </blockquote> <font face=3D"Arial">Nah, not really, as long as you do oldconfig you= should be fine. Most of the config changes were compatimentalized under the grsecurity section.<br> <br> </font> <blockquote cite=3D"mid:4eb0e157-b944-7833-66bd-7ed4a63ea179-/[email protected]= g" type=3D"cite"> <p><font face=3D"Arial"> Do I need to work backwards through the hardening guide, for example?</font></p> </blockquote> Definitively not :)<br> </body> </html> --------------028B5C9CA80A7F31930E34BA-- --fuJsb4lKDtjNcDn5Ojkij6OicfEb8Q2Fa-- --COF4dNMWMPDh7WFs3TUneoOPSMaIqoi7s Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- iQIxBAEBCgAbBQJZlFibFBxrbG9uZGlrZUBnZW50b28ub3JnAAoJEPS90u/o/3j5 Wn0P/RAIRatIi/gHxKR2oCRLZ9P+TwElktYR/rTxzpaV3XHxliXdujLqbsfYU6oQ soLuHj/NCI7pcpTWRtdzFoT6+oSjf/IrA8/otf4sd3lIeAC0vp5NmXjOxnIOoJaP 8tYl5W2M5vUBwda/NzhRJZ4o5YXvxuK+iqswukjOJvXNOUl8XwdiMZkH9pjANSJ1 fbu56Nis3qdst1RjNdk+jRSkYHWY6v3iTJLbR/Xk9YAK4tQ6zAbvNDcbxb1UCUTm qvfb8jCwgToKFM6ABTmEiBHFdPXEAHsbtz9sCBqC6om8egDl8MOLlJXxUtdFVq70 2uJxY6iVJNPNiLbrOsbex3DELyBi1/RUH0Q3N+cjhwuZ8I1mwmL3uuH0mSknKYeO uv6rM1QjpHSzp07BMytNUWi9DyU5Vu/Dv+nWfTQHpqYML18im001RLgEqz7V/R/l lYS1k8AvBxLHnTTMXecxQXhUmAl8PrF6aud4++nqAY80B4fTTJBHRUOHYKJO2Ohv ZAIxs9XgoaH7f701DKC2QZqXNUqxvI99ZDuZf9od9o4RzeAgv74Djgi3bNDVYOYK O4piUsQ1gAEohL9ndZLimVSCC5TdUD4QDRsw1x3XHd2WLqIdElu8jvPtuHNIf5s+ Zo+CaVNB1HMXZ6u4N9WIt7UHUuY0h6tn7W2VBBhMKvCd5WDl =d2QR -----END PGP SIGNATURE----- --COF4dNMWMPDh7WFs3TUneoOPSMaIqoi7s--