Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
2.6.24-dark3: Splicer
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Unsupported Software
View previous topic :: View next topic  
Author Message
predatorfreak
l33t
l33t


Joined: 13 Jan 2005
Posts: 708
Location: USA, Michigan.

PostPosted: Mon Feb 11, 2008 5:46 am    Post subject: 2.6.24-dark3: Splicer Reply with quote

Emergency fast-release (built, boot tested and ran for a couple hours now) to fix the security problem in vmsplice. Also fixes issues with realtime-lsm causing build failures due to improper/lack-of ifdefs on the sysctl bits (sorry about that folks, I forgot to build test without it).

Quote:

Release: 2.6.24-dark3
Patchset produced by: predatorfreak

Comments: Fix build problems caused by not enabling realtime-lsm, add a security patch for vmsplice.

Build and boot-test certified: Built with a modified Arch Linux kernel26 config, booted on my system, seems to run fine.

Additional Information: To adjust the CFS granularity, use sysctl kernel.sched_granularity_ns = VAL, where VAL is the proper value.
Realtime LSM can be controlled through sysctl kernel.rt_any (if set to 1, any process can become realtime, unrestricted), sysctl kernel.rt_gid
(when set to a valid group ID number, any programs run in that group or by a user in that group can become realtime) and sysctl kernel.rt_mlock
(when set to 1, programs affected by the previous two options can utilise mlock).

Patch list:
mainline/patch-2.6.24.1
mainline/plug-vmsplice-security-hole.patch
assorted-fixes/gcc-4.3.0-compilation-fix-2.patch
ck/mm-swap_prefetch-41.patch
ck/mm-lots_watermark.diff
ck/mm-kswapd_inherit_prio-1.patch
ck/mm-prio_dependant_scan-2.patch
ck/mm-background_scan-2.patch
ck/mm-filesize_dependant_lru_cache_add.patch
ck/kconfig-expose_vmsplit_option.patch
genpatches/2700_usbaudio-logitech-id.patch
dark/powertop-2.6.24.patch
dark/netfilter-ipset-and-u32.patch
dark/realtime-lsm-static.patch
dark/dark-tag.patch


Download patch: http://www.dcaf-security.org/dark-sources/patch-2.6.24-dark3.patch.bz2
Download broken-out: http://www.dcaf-security.org/dark-sources/broken-out-2.6.24-dark3.tar.bz2
_________________
System: predatorbox
Distro: Arch Linux x86_64
Current projects: blackhole, convmedia and anything else I cook up.


Last edited by predatorfreak on Mon Feb 11, 2008 5:02 pm; edited 1 time in total
Back to top
View user's profile Send private message
hirakendu
Guru
Guru


Joined: 24 Jan 2007
Posts: 386
Location: san diego

PostPosted: Mon Feb 11, 2008 8:12 am    Post subject: Reply with quote

ah, i guess in your emergency fastness, the thread was named 2.6.23 instead of 2.6.24 ;). aside, hopefully one day i'll start using hardened gentoo :).
_________________
Helium Sources || Gentoo Minimal Livecd
Back to top
View user's profile Send private message
tranquilcool
Veteran
Veteran


Joined: 25 Mar 2005
Posts: 1179

PostPosted: Mon Feb 11, 2008 11:48 am    Post subject: Reply with quote

compiles and is running great.
thanks!
_________________
this is a strange strange world.
Back to top
View user's profile Send private message
predatorfreak
l33t
l33t


Joined: 13 Jan 2005
Posts: 708
Location: USA, Michigan.

PostPosted: Mon Feb 11, 2008 5:02 pm    Post subject: Reply with quote

hirakendu wrote:
ah, i guess in your emergency fastness, the thread was named 2.6.23 instead of 2.6.24 ;). aside, hopefully one day i'll start using hardened gentoo :).


Yep, guess I went a tad TOO fast.
_________________
System: predatorbox
Distro: Arch Linux x86_64
Current projects: blackhole, convmedia and anything else I cook up.
Back to top
View user's profile Send private message
PLum
Tux's lil' helper
Tux's lil' helper


Joined: 20 May 2004
Posts: 108
Location: /dev/world/poland/gliwice

PostPosted: Mon Feb 11, 2008 6:34 pm    Post subject: Reply with quote

hey predatorfreak, how about refreshing the archlinux PKGBUILD ?
Back to top
View user's profile Send private message
predatorfreak
l33t
l33t


Joined: 13 Jan 2005
Posts: 708
Location: USA, Michigan.

PostPosted: Mon Feb 11, 2008 7:36 pm    Post subject: Reply with quote

PLum wrote:
hey predatorfreak, how about refreshing the archlinux PKGBUILD ?


Don't run Arch anymore, can't test it. My policy is generally to never endorse or make things that I cannot test which package my work.
_________________
System: predatorbox
Distro: Arch Linux x86_64
Current projects: blackhole, convmedia and anything else I cook up.
Back to top
View user's profile Send private message
PLum
Tux's lil' helper
Tux's lil' helper


Joined: 20 May 2004
Posts: 108
Location: /dev/world/poland/gliwice

PostPosted: Tue Feb 12, 2008 2:50 pm    Post subject: Reply with quote

predatorfreak wrote:

Don't run Arch anymore, can't test it. My policy is generally to never endorse or make things that I cannot test which package my work.


oh why ?, then i will try to make one and if it works post link here ...
Back to top
View user's profile Send private message
predatorfreak
l33t
l33t


Joined: 13 Jan 2005
Posts: 708
Location: USA, Michigan.

PostPosted: Tue Feb 12, 2008 6:05 pm    Post subject: Reply with quote

PLum wrote:
predatorfreak wrote:

Don't run Arch anymore, can't test it. My policy is generally to never endorse or make things that I cannot test which package my work.


oh why ?, then i will try to make one and if it works post link here ...


I don't support things packaging my work which I cannot test for stability and quality reasons, I left Arch because they broke too many packages on me regularly.
_________________
System: predatorbox
Distro: Arch Linux x86_64
Current projects: blackhole, convmedia and anything else I cook up.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Unsupported Software All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum