From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) by finch.gentoo.org (Postfix) with ESMTP id 508071381F3 for ; Wed, 14 Nov 2012 00:43:15 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id DC381E043A; Wed, 14 Nov 2012 00:43:07 +0000 (UTC) Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) (using TLSv1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 48D3EE043A for ; Wed, 14 Nov 2012 00:43:07 +0000 (UTC) Received: from hornbill.gentoo.org (hornbill.gentoo.org [94.100.119.163]) (using TLSv1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.gentoo.org (Postfix) with ESMTPS id 2BE0B33DA94 for ; Wed, 14 Nov 2012 00:43:06 +0000 (UTC) Received: from localhost.localdomain (localhost [127.0.0.1]) by hornbill.gentoo.org (Postfix) with ESMTP id AFD33E5436 for ; Wed, 14 Nov 2012 00:43:04 +0000 (UTC) From: "Anthony G. Basile" To: gentoo-commits@lists.gentoo.org Content-Transfer-Encoding: 8bit Content-type: text/plain; charset=UTF-8 Reply-To: gentoo-dev@lists.gentoo.org, "Anthony G. Basile" Message-ID: <1352853765.e944ba0ee464b67b58593409b4cd3a4adc4f47ef.blueness@gentoo> Subject: [gentoo-commits] dev/blueness:master commit in: sys-kernel/hardened-sources/ X-VCS-Repository: dev/blueness X-VCS-Files: sys-kernel/hardened-sources/Manifest sys-kernel/hardened-sources/hardened-sources-2.6.32-r139.ebuild sys-kernel/hardened-sources/hardened-sources-3.2.33-r2.ebuild sys-kernel/hardened-sources/hardened-sources-3.6.6-r1.ebuild X-VCS-Directories: sys-kernel/hardened-sources/ X-VCS-Committer: blueness X-VCS-Committer-Name: Anthony G. Basile X-VCS-Revision: e944ba0ee464b67b58593409b4cd3a4adc4f47ef X-VCS-Branch: master Date: Wed, 14 Nov 2012 00:43:04 +0000 (UTC) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-commits@lists.gentoo.org X-Archives-Salt: cda95b81-b2ba-4efb-8979-642158e0a65c X-Archives-Hash: ad087f861e18781fdea4435c7a26f51b commit: e944ba0ee464b67b58593409b4cd3a4adc4f47ef Author: Anthony G. Basile gentoo org> AuthorDate: Wed Nov 14 00:42:45 2012 +0000 Commit: Anthony G. Basile gentoo org> CommitDate: Wed Nov 14 00:42:45 2012 +0000 URL: http://git.overlays.gentoo.org/gitweb/?p=dev/blueness.git;a=commit;h=e944ba0e sys-kernel/hardened-sources: testing patchset 20121112 --- sys-kernel/hardened-sources/Manifest | 12 ++-- .../hardened-sources-2.6.32-r139.ebuild | 51 ++++++++++++++++++++ .../hardened-sources-3.2.33-r2.ebuild | 50 +++++++++++++++++++ .../hardened-sources-3.6.6-r1.ebuild | 50 +++++++++++++++++++ 4 files changed, 157 insertions(+), 6 deletions(-) diff --git a/sys-kernel/hardened-sources/Manifest b/sys-kernel/hardened-sources/Manifest index 2095a72..351e4e7 100644 --- a/sys-kernel/hardened-sources/Manifest +++ b/sys-kernel/hardened-sources/Manifest @@ -10,13 +10,13 @@ DIST genpatches-3.2-16.base.tar.bz2 445530 SHA256 3a3d16b7ffa401598bd131a7e8b299 DIST genpatches-3.2-16.extras.tar.bz2 17208 SHA256 7f60ab18e2965d024b7a36327577bcc771061f2cfac221ed475a6fd6b2ab89c7 SHA512 bea678f7eb56eb992c99d9c49b8d1602228dec00e7fd255432ca30847aae9d4d223bb9ab27f5e72ad422e0d0f2ac319fa590d5fe0e53824b415d6d8bba686add WHIRLPOOL 875f72ab9b81e1cc7a7a06d42783c04204987cfd49042f3cf19b1ed80b0d91f8fdaaf13152b7a22a0d0c1eb9a22719d83eaa9c4fcf9d2024e62420332f081019 DIST genpatches-3.6-8.base.tar.bz2 158928 SHA256 5a79567b0d12a2684255543a14dc38db46c75abda01a2871cc22bfa74d5852de SHA512 74ef54ab9f31a88acfba6f0a39029e1038f1a174bf905a6bf2e2ad89a31c3bbf4209e5fa3f2decbe077c468fbd9926207e453b41401f5b810cee84b185445d59 WHIRLPOOL e2cdc52cb8d3bff37a7bf40d77352b616e177131847570a5dd73cf7a20b8c038fbea192b5d02b5b3e859870d27dae982a344c4080af2f2e681548eed5acac236 DIST genpatches-3.6-8.extras.tar.bz2 17038 SHA256 bf6be402ec3ef125ecaf626379f777a262e2f6776d8f5115ac0834f1e3d18b25 SHA512 614c845d474890ad0fd4271ea133464626498c3877d49c1df9940cfb2bc2a68a13828b6cae590a0d5619cf21521fe119fab782714d0bc37c287e0bba29f22fdf WHIRLPOOL ef8c9a76be1ac027b3d01e47bf22dbe178b2b68e85f4ace1186aedd89e513ff010d6e50e1392e17dde3bfebabcff07c348b04163398c43c045d6e37e78caf954 -DIST hardened-patches-2.6.32-142.extras.tar.bz2 886856 SHA256 18ddbf81fdfc187988240c1ab480697150590a9e7a217f8c67958132470e4eb1 SHA512 122a0d0759ae5796ac71043d6eba0b9a7cf132db384058b98ef7ab82b0a3052334ae43057e31ce2331ef674fd6c6b64fe17ff4b1c1b7fe1beae947c6245b9f32 WHIRLPOOL c3b72ee7aeeacae14ed13a16727b8fe77e35c28597b3828433717af1e28359abc2ebeb9f325604e1d580e8a82b234f08c25e84143fd5d899d1c76bab091908cf -DIST hardened-patches-3.2.33-2.extras.tar.bz2 917011 SHA256 c4bc8cf6d98a076b15ac10f27fecddcd3da94041d4ad1894df4bcf5b0ba1f872 SHA512 8519a8e11ca77403e1e1e28f805e8eb986d1b0e4bd581ee401722321243f49d1ea14347cae80530e23b555509477290e5929d8b056178ef1813d3bb222c3fc6c WHIRLPOOL 7735dc096a71e3b305bd05a6e5882c75fd95ed46b042eb3c206b6c9422a0d96002057853a60398a8233a1c8cb5e6bd72678384ff704cb0c6a5b315617bfa0af3 -DIST hardened-patches-3.6.6-1.extras.tar.bz2 583883 SHA256 45f6f78c49a8437bdfa97136b50d7322c7fa1fcf5ad8f4d191985538659c2271 SHA512 406f22a480c39c5afce754d7fb1cfe6fd3650ac710793b4e19c18f181b55862036c5daef34d7a75843a978a70fdb6acc9277b662bf389ce568887101e39f1662 WHIRLPOOL 49802a7dfc9eb61a6f236bf3ef914400d0f0d0253ebe71d027cee3d11d2e98df6c4a29279a74185721f96ffdf3b5f888bf006c03391e496a1f8e05e5657b63ed +DIST hardened-patches-2.6.32-143.extras.tar.bz2 877841 SHA256 b10fc69ffd14a4f5f696095e9b823a0743d8a83db07f22122f30af8bf2947736 SHA512 a3be0ca9b66cc495937fa305c7691b020ba4c5945a1d6cd874294878109cc6137656559ded699e0695c385deb8bf7f72a6061739a45bbda7b12c34cb964722de WHIRLPOOL a28a1971b0e78db3ca24f7a07e554994cfdf74faf8fa6dece3b37c82ed4cb6da68e8a09e05ff3e55869c5bf5e55f29a73cc81d20e6150d7eb612ce03db6423f8 +DIST hardened-patches-3.2.33-3.extras.tar.bz2 924900 SHA256 d48ff37d78199d489d3652cd1eb209065f4a2b45e49a19bb24a3ef7e6efe3e8c SHA512 1bfeb06aedbcae9e1252655fbddd9ec776c07cb1900d21332aceb1f24d3aaa2b0162459309a88eba995b0f01aa3bd34ee45a3884c8b13bc28c7b8398acf2bf17 WHIRLPOOL 63b04bf89ca18cdd915ac7ba28473a733ae7f62ee5be01a69d7404a623695bcba34594074231054793229ff2f6b0185a78f522f276641f4fc31b042788ec6f3a +DIST hardened-patches-3.6.6-2.extras.tar.bz2 584767 SHA256 95071bbecc45385da8d4d5fbe474ad0078dfb1cc44af40c2badde8e5b7639aea SHA512 6e29fabf14f2d5c1352c6dde94ff61479a22987ba47c535f81a7e76c92151e9567033ae0888775784d5cd64b979659e5f60f8bed906e4bfbaf75a4f04a304ea6 WHIRLPOOL d787aca2829fc80351b0361878b13710b7e2d470587aac33465a3aa9b73190de0cc6d98b04971bd56c480894c3d6cb50e372f8d41ca705ca3d4c91a186297d64 DIST linux-2.6.32.tar.bz2 64424138 SHA256 5099786d80b8407d98a619df00209c2353517f22d804fdd9533b362adcb4504e SHA512 739c67875dcb1a80412a034e7d3dddfb6aea4d7a77f12b572fb5afbb827e6ab5a682df7501c0982966e85948ddf7251b8dc5eeb064b2d264025160d8a903bc82 WHIRLPOOL 762dfd7f4c062fdcda00b7fc45ead0f8cb4e321027769a12d92640012f5768c2033da95f24491adfcd6eb453c2658978d4f170e73e4f8a5ccd263efcbe00429d DIST linux-3.2.tar.bz2 78147838 SHA256 c881fc2b53cf0da7ca4538aa44623a7de043a41f76fd5d0f51a31f6ed699d463 SHA512 1f57b98e8da34b10f37ce94e0f13a994c111d483b104c27a8f58a4a55013a73a9f1ffcebb597be63ce0dfadb92201e93b0e072ba49bac0033026aceb0840c812 WHIRLPOOL 3dc893bde09f064e4614183964a4b9feaab938ca7a739f46f825818a577884eae815f195b52a4c55c571345de59d7ba09631fb68dac481a0837b24868ce60e3d DIST linux-3.6.tar.bz2 82296001 SHA256 88ae0a20fd39ecae79db0ce8f9397922fae33c8b06a54ed2c883c861126c9771 SHA512 cbaefc2c4c8ab2251c3345b7b2c88d55a49e3468d8b177b05dd6d96a802efa9a052b1a1ecab8b71298bac97f45259516d88253838332b4fdb4307780ebcddce9 WHIRLPOOL e17e3800951f0c3af21015d1a1c99698d0ef70815bd4f131dd60b30baef70d4c255988857533a9a7c058388c2febfcf02d12cde2a7ed46b24fa85aeb260c0251 -EBUILD hardened-sources-2.6.32-r138.ebuild 1820 SHA256 29dc8453b6ef259e922ed7a46d96b741b73775633e2d61f8e794938b40d1274c SHA512 01e340065d054ac57f95d6d8b10153679eb818ac0a24ddeeac854ad692583a8d1e4c7e1438a470feef9f2aa4c409f45063167101efdca47c13b1e2827228b623 WHIRLPOOL c74eab3664a6a03c2a559d7e2130cbebdd3f02161e6143cab59ab2b619cff420ef61f2c140367fe6a47784b22aae999bbaa2728f7c4198228ce785a45a47eadc -EBUILD hardened-sources-3.2.33-r1.ebuild 1813 SHA256 6fa2e820a646b833e57a92394b0b58b8c27c3fa68032eb595a81541b70d455e1 SHA512 eccd5bb4da1ff9cf808a41967ec587ee472cef43eafc01c00c8842b30fb936be814d37c7c0510587770b726843e7e42a065d520337b6eb1ca8a2a39a1251c8a8 WHIRLPOOL 42d70222f0dda02a656a2612534139110f8330cc899a4a81ca3f5c4a383a6e3fbf93436f80fd4b2ec7a49bf64ec5adb9108ff734f00e276d57401eb419492686 -EBUILD hardened-sources-3.6.6.ebuild 1811 SHA256 bbc777d56a9cc2458f895fd7c9ff96ede3fb0c3a6188e7dd1e172f46d07fa95a SHA512 51039ca603922eb8a0dc7937b43d55cc36fdc43a38e090cf82a68c4c8d43030da890630185eaffe20d11597102218189457bfdb7d853fb44d7f06ed25fdf6c57 WHIRLPOOL 54ffe21cab1f5c5da01bf5ea8e247ccf4a16587b435b94ab70080d733a9e41b929c6b234d99da562411555262c7f2343812a09dc740bcb9459056ffc42dbd3ad +EBUILD hardened-sources-2.6.32-r139.ebuild 1820 SHA256 f16455d01a5bc253f918012ef140b343015b31027b5c1a7d1682a1ecac0797fc SHA512 265785d0af4f02889d52d94f1370559a42be3f69b1d4a48c0a3e03c0e4f656dae8d94bac4dc8e55b4c15c3b5e7ae41898c7e23fb9e2547edf5ce2e8d37aac5b8 WHIRLPOOL 69484e181920af6e40e773a501750d7ae7704b2c90dbb3903a4900df8ffe460498548aba193eed652c2e56553bb36e4e538e86fba67837e18f013e7f3c58d8cd +EBUILD hardened-sources-3.2.33-r2.ebuild 1816 SHA256 57c5e36872bef3dd2fece752c07ac0bb97b98138b83dc1a551e0e792f2f86397 SHA512 37f1982f969742f89ea18ff0e0214ddb0f0307ee7ddde18bd9ea968af38aeb38a3c8194291981b46bc6bb38187ae53509db7ff03b15659b39388ce02b70bf6e4 WHIRLPOOL 4016a5ad0e63c7be114361960775e597830fab082c76e52bdbc26587cd102e6a5afae328d5193f6400d90789995c93b4e1f0af28f7a9f8d1985d3fae82fc4f59 +EBUILD hardened-sources-3.6.6-r1.ebuild 1811 SHA256 c15f58e1b6f36ba21300bdc5bf00cf760c70213240b9195de66857ce62f1aad7 SHA512 d8cb01cd2dcf35348e1716f1c7d1747f37d327b58f0d55721c67d2328eeef3f63ce01aee877dc50db8b2f8fd970a631d9338aedf67c46fbf80e72355a19666f2 WHIRLPOOL 53c6faca53419bae169c02efa4418e2f627990772e5e8a25a4f90e8e4c0443fc331f81d174fd857a3b229234c0315902e4b773292223dfc0e2e009df393af874 MISC metadata.xml 576 SHA256 53e0d3bfb958bcbf62457a89abe76a7a6f5a2b1df5decb04bf8b840184cc5828 SHA512 aabb8324fc608a74fecda5e4fff0f29d47d34ff20bdea2af8a69726772268d7b3b9d2639cd9c2308b3c79b89d9e923d2a96b212e7cfe59a0bf0008e3fb1c7e6a WHIRLPOOL 11fc891bd478667fe4ca5d203b366fdcf1680dac31bf997ea7c707c6f00a1c03b6ca7a00045b75dc1604e9eb57c2cab03a12f46318320ed6abdb5d6feb06b71f diff --git a/sys-kernel/hardened-sources/hardened-sources-2.6.32-r139.ebuild b/sys-kernel/hardened-sources/hardened-sources-2.6.32-r139.ebuild new file mode 100644 index 0000000..8cbc53c --- /dev/null +++ b/sys-kernel/hardened-sources/hardened-sources-2.6.32-r139.ebuild @@ -0,0 +1,51 @@ +# Copyright 1999-2012 Gentoo Foundation +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-2.6.32-r138.ebuild,v 1.1 2012/11/08 15:06:32 blueness Exp $ + +EAPI="4" + +ETYPE="sources" +K_WANT_GENPATCHES="base extras" +K_GENPATCHES_VER="48" +K_DEBLOB_AVAILABLE="1" + +inherit kernel-2 +detect_version + +HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-143" +HGPV_URI="http://dev.gentoo.org/~blueness/hardened-sources/hardened-patches/hardened-patches-${HGPV}.extras.tar.bz2" +SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}" + +UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2" +UNIPATCH_EXCLUDE="4200_fbcondecor-0.9.6.patch" + +DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})" +HOMEPAGE="http://www.gentoo.org/proj/en/hardened/" +IUSE="deblob" + +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86" + +RDEPEND=">=sys-devel/gcc-4.5" + +pkg_postinst() { + kernel-2_pkg_postinst + + local GRADM_COMPAT="sys-apps/gradm-2.9.1*" + + ewarn + ewarn "Hardened Gentoo provides three different predefined grsecurity level:" + ewarn "[server], [workstation], and [virtualization]." + ewarn + ewarn "Those who intend to use one of these predefined grsecurity levels" + ewarn "should read the help associated with the level. Users importing a" + ewarn "kernel configuration from a kernel prior to ${PN}-2.6.32," + ewarn "should review their selected grsecurity/PaX options carefully." + ewarn + ewarn "Users of grsecurity's RBAC system must ensure they are using" + ewarn "${GRADM_COMPAT}, which is compatible with ${PF}." + ewarn "It is strongly recommended that the following command is issued" + ewarn "prior to booting a ${PF} kernel for the first time:" + ewarn + ewarn "emerge -na =${GRADM_COMPAT}" + ewarn +} diff --git a/sys-kernel/hardened-sources/hardened-sources-3.2.33-r2.ebuild b/sys-kernel/hardened-sources/hardened-sources-3.2.33-r2.ebuild new file mode 100644 index 0000000..7d038b6 --- /dev/null +++ b/sys-kernel/hardened-sources/hardened-sources-3.2.33-r2.ebuild @@ -0,0 +1,50 @@ +# Copyright 1999-2012 Gentoo Foundation +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-3.2.33-r1.ebuild,v 1.1 2012/11/08 15:08:24 blueness Exp $ + +EAPI="4" + +ETYPE="sources" +K_WANT_GENPATCHES="base extras" +K_GENPATCHES_VER="16" +K_DEBLOB_AVAILABLE="1" + +inherit kernel-2 +detect_version + +HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-3" +HGPV_URI="http://dev.gentoo.org/~blueness/hardened-sources/hardened-patches/hardened-patches-${HGPV}.extras.tar.bz2" +SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}" + +UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2" +UNIPATCH_EXCLUDE="4200_fbcondecor-0.9.6.patch" + +DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})" +HOMEPAGE="http://www.gentoo.org/proj/en/hardened/" +IUSE="deblob" + +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86" + +RDEPEND=">=sys-devel/gcc-4.5" + +pkg_postinst() { + kernel-2_pkg_postinst + + local GRADM_COMPAT="sys-apps/gradm-2.9.1*" + + ewarn + ewarn "Hardened Gentoo provides three different predefined grsecurity level:" + ewarn "[server], [workstation], and [virtualization]. Those who intend to" + ewarn "use one of these predefined grsecurity levels should read the help" + ewarn "associated with the level. Because some options require >=gcc-4.5," + ewarn "users with more, than one version of gcc installed should use gcc-config" + ewarn "to select a compatible version." + ewarn + ewarn "Users of grsecurity's RBAC system must ensure they are using" + ewarn "${GRADM_COMPAT}, which is compatible with ${PF}." + ewarn "It is strongly recommended that the following command is issued" + ewarn "prior to booting a ${PF} kernel for the first time:" + ewarn + ewarn "emerge -na =${GRADM_COMPAT}" + ewarn +} diff --git a/sys-kernel/hardened-sources/hardened-sources-3.6.6-r1.ebuild b/sys-kernel/hardened-sources/hardened-sources-3.6.6-r1.ebuild new file mode 100644 index 0000000..dbb3f56 --- /dev/null +++ b/sys-kernel/hardened-sources/hardened-sources-3.6.6-r1.ebuild @@ -0,0 +1,50 @@ +# Copyright 1999-2012 Gentoo Foundation +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-3.6.6.ebuild,v 1.1 2012/11/08 15:10:23 blueness Exp $ + +EAPI="4" + +ETYPE="sources" +K_WANT_GENPATCHES="base extras" +K_GENPATCHES_VER="8" +K_DEBLOB_AVAILABLE="1" + +inherit kernel-2 +detect_version + +HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-2" +HGPV_URI="http://dev.gentoo.org/~blueness/hardened-sources/hardened-patches/hardened-patches-${HGPV}.extras.tar.bz2" +SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}" + +UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2" +UNIPATCH_EXCLUDE="4200_fbcondecor-0.9.6.patch" + +DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})" +HOMEPAGE="http://www.gentoo.org/proj/en/hardened/" +IUSE="deblob" + +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86" + +RDEPEND=">=sys-devel/gcc-4.5" + +pkg_postinst() { + kernel-2_pkg_postinst + + local GRADM_COMPAT="sys-apps/gradm-2.9.1*" + + ewarn + ewarn "Hardened Gentoo provides three different predefined grsecurity level:" + ewarn "[server], [workstation], and [virtualization]. Those who intend to" + ewarn "use one of these predefined grsecurity levels should read the help" + ewarn "associated with the level. Because some options require >=gcc-4.5," + ewarn "users with more, than one version of gcc installed should use gcc-config" + ewarn "to select a compatible version." + ewarn + ewarn "Users of grsecurity's RBAC system must ensure they are using" + ewarn "${GRADM_COMPAT}, which is compatible with ${PF}." + ewarn "It is strongly recommended that the following command is issued" + ewarn "prior to booting a ${PF} kernel for the first time:" + ewarn + ewarn "emerge -na =${GRADM_COMPAT}" + ewarn +}