From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) by finch.gentoo.org (Postfix) with ESMTP id AED461381F3 for ; Wed, 5 Jun 2013 14:56:46 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 265BDE095A; Wed, 5 Jun 2013 14:56:46 +0000 (UTC) Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) (using TLSv1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 5F86BE0957 for ; Wed, 5 Jun 2013 14:47:12 +0000 (UTC) Received: from [192.168.3.7] (cpe-69-207-16-110.buffalo.res.rr.com [69.207.16.110]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: blueness) by smtp.gentoo.org (Postfix) with ESMTPSA id 61AE333D3D6 for ; Wed, 5 Jun 2013 14:47:11 +0000 (UTC) Message-ID: <51AF4F8A.2040501@gentoo.org> Date: Wed, 05 Jun 2013 10:47:38 -0400 From: "Anthony G. Basile" Reply-To: Gentoo Development User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20130518 Thunderbird/17.0.6 Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo development announcement list X-BeenThere: gentoo-dev-announce@lists.gentoo.org MIME-Version: 1.0 To: gentoo-dev-announce@lists.gentoo.org Subject: [gentoo-dev-announce] hardened uclibc: security-enhanced, fully featured XFCE4 desktop for amd64, built on uClibc Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Archives-Salt: 3d38bb9c-bed8-4bfe-a97a-13f88400c269 X-Archives-Hash: 451e2d393203a47b74dc9c8015eb6e90 Hi everyone, I'd like to announce a new (fun?) initiative of the hardened uClibc subproject: a security-enhanced, fully featured XFCE4 desktop for amd64, built on uClibc, codenamed "Lilblue", after the little blue penguin of New Zealand [1], a smaller cousin of the Gentoo. The hardened uClibc subproject aims at producing hardened stage3s for amd64, mips (isa=mips32r2/mipsel3, abi=o32), armv7a (softfloat) and i686 [2]. Recent improvements in uClibc and bugfixes in various Gentoo packages, both downstream and upstream, now make it possible to build an entire desktop system replacing glibc with uClibc. So, in addition to the stage3s, we are now releasing a fully featured XFCE4 desktop for arch=amd64. It does *not* depend on busybox to provide its core utilities like most uClibc systems, but coreutils, util-linux and all the usual system packages you find on a generic Gentoo system. The tarball bundles about 800 packages including ephiphany, claws, hexchat, abiword, gqview, transmission, vinagre, etc. We have plans to provide binpkgs for up to 7000 packages in all. The hardening includes all of the usual toolchain and kernel hardening you get in regular hardened glibc-based Gentoo. The project has been in development for a year but should be considered experimental. A user base of ... uhm ... one ... does not really qualify it to be labeled as "safe for production" [3]. However, I have had no issues with it (minor bugs of course) and I use it on a daily basis. For the average user, the main advantage is speed and the system does feel "snappy". For developers, its fun to dig into bugs which revolve around what functions are provided by your standard C lib: is this POSIX or a GNU-ism? should I fix the package or add a new function to uClibc? what is the best way to implement this fix so it ports across different *libcs? what do I do about this package whose build system is braindead and doesn't understand libdir? If you have too much time on your hands and you're into that kind of "fun" we have a project for you! On a serious note, the main reason for this initiative is to explore and expand the usefulness of an alternative standard C library. The home page is at [4] and a freecode.com announcement at [5]. It can be downloaded from any gentoo mirror [6] at [mirror]/gentoo/experimental/amd64/uclibc/desktop-amd64-uclibc-hardened-[date].tar.bz2. The date of the first release is 20130531. Ref. [1] https://en.wikipedia.org/wiki/Little_Penguin [2] http://www.gentoo.org/proj/en/hardened/uclibc/index.xml [3] This is not entirely true. I would like to thank my students for testing, especially Devan Franchini . [4] http://www.gentoo.org/proj/en/hardened/uclibc/lilblue.xml [5] https://freecode.com/projects/lilblue-linux [6] http://www.gentoo.org/main/en/mirrors2.xml -- Anthony G. Basile, Ph.D. Gentoo Linux Developer [Hardened] E-Mail : blueness@gentoo.org GnuPG FP : 1FED FAD9 D82C 52A5 3BAB DC79 9384 FA6E F52D 4BBA GnuPG ID : F52D4BBA