From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by finch.gentoo.org (Postfix) with ESMTPS id 85A11138334 for ; Fri, 3 Jan 2020 14:49:04 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 79658E0BF4; Fri, 3 Jan 2020 14:49:02 +0000 (UTC) Received: from smtp.gentoo.org (dev.gentoo.org [IPv6:2001:470:ea4a:1:5054:ff:fec7:86e4]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id C8E25E0BF1 for ; Fri, 3 Jan 2020 14:49:01 +0000 (UTC) Received: from [192.168.178.24] (x4d06678e.dyn.telefonica.de [77.6.103.142]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) (Authenticated sender: toralf@gentoo.org) by smtp.gentoo.org (Postfix) with ESMTPSA id A322934DCBD for ; Fri, 3 Jan 2020 14:49:00 +0000 (UTC) Subject: Re: [gentoo-dev] Vanilla sources To: gentoo-dev@lists.gentoo.org References: <3197490.ugo6OjCCXa@daneel.sf-tec.de> <1794534.0xJHuh4lKC@crazyhorse> <19015309.XG3PSQ8cOu@daneel.sf-tec.de> <5537134e-0412-862d-e105-94c678229b46@gentoo.org> <2dd351b3-0f71-4960-ffde-2f5a99ab161d@gentoo.org> <9b48db99-19dc-617b-c0d4-ffa0216b43be@gentoo.org> From: =?UTF-8?Q?Toralf_F=c3=b6rster?= Autocrypt: addr=toralf@gentoo.org; prefer-encrypt=mutual; keydata= mQENBFkkk3EBCAC86NQf0FQU51jotnOidwT8Qdy8BQWN4JvjlPz9AGK9GdKW2qf4vuoVVQh6 QV67zCo9uFj7tqA8ZwSaCgcFhKxyidD7o4S9cR2uVZHRa++EbNwqyaHAUQS2yN5MMUsQvSoF jdsQ9xBVgOgkWMVmQ4ztdGGdpMgksUps42+28OiCm9JnSirD36Ij44aSBnv0HuYe6RVFhvAC TZvSWmCT7wkIvtcNSd1w+6+93yafHgy9Nq4ssQByJApkLl3mQ9EEAhOP7IzEe8ngMd7tP1J+ R9rDVy1qsKICc9yLFymT3OGwnCMsvFbQHJTZBnt8nMp1eKJf92I98IeF0UmWyFQEfcKpABEB AAG0I1RvcmFsZiBGw7Zyc3RlciA8dG9yYWxmQGdlbnRvby5vcmc+iQFUBBMBCAA+AhsDBQsJ CAcCBhUICQoLAgQWAgMBAh4BAheAFiEE9Fss6CRzaFtvbcqtIyF9p5uIj0UFAls6jZ0FCQXZ HK8ACgkQIyF9p5uIj0WulAf+Mj9txJqBpgFKrlsLBNKtpj0Mjd0/t68DsbvD60nmVJesrVMD 7xE6HbYP5MxilDMQHITzXcxmOOfMT2J94nClhtV4YXfb5aIHaWRS/U6HvZzKheR9uG7RFmTi ZvX2Iz/f5ZdDjFfGoYZ+165SAfUqgUeWkJIW4/W0uv9Q/fo5TTkc3R9+1+UcR/r0EeiCdEj6 a6O3v5WOyUzT+J4z+Q48X088Qkf9npjPgTw/GlLT2rjU+6gb58pBEXc7szfrCIU4w86T8dfW ImxA7K5SmQjCtGk6wx7cDpFoUB4SZWPO8k0TXhSEFBCuVl7TwFPng4YsJSBSxvCFyT9nZXF9 OV9Mq7kBDQRZJJNxAQgA6ItIJ88i54lwLn25NreWYwc+J1k+wg6eRgzAtJebkhOY4rMYzyVz jq9D8HXavcGdT8S1xQLUZ/5afAvppW3fJmEcgu7pmWKmSrHEhV7Lx9VGuU9EToQhvruVcYLn v453He9kVOh/SDREndKzlsfBe+5+gV7YoF0Vxqa4+f4pOet+DjoM7wgAR0BAoPjQp5BkTJ/W 7g8y6fBAb418KD5NqGV0pCdmNKTFvnY4zB4gFpwBPBUUqrzjry4prBpEFvnfp15ZjoGlow0/ 4hxALFxL+d9IyHkwyw09P8F+jlVkEPeD2zwxB9dFrSIfawEL+Je6+krhgMWRGqME9inHRRgi 4QARAQABiQE2BBgBCAAgAhsMFiEE9Fss6CRzaFtvbcqtIyF9p5uIj0UFAlkkqXQACgkQIyF9 p5uIj0UJuQf+JQa2NfoG1iPct4gFW0YkzGqGa9Aa571aQAKNrzLqgGeRgluFwlzpZct2tgr3 jXhAv3Jhu7D7ungzO04zB1w7sX4HDze5DxbUpeb6qoO7ByWyaZVhWocvDrGruVo5titY5dEv YKaDtmMgUw7zwzeaRJ0VHQatnxe6n0lqZP4KV2ZLEEcqoz1p8ftAtnXY3wLdyWGOSuPsQXcy 4Uq7uFT9ou4KBGo0Lj3zOuBHHoOslMaat78hzPdwGP/b57NS7pNMnduIwaNsAy/RCNRWNW12 DxNSLNt6JnqTPCA1/esLHzsXzflWgtbY0W7wiO+YKhObreLc4jKLoNWfHk6xetCDsg== Message-ID: Date: Fri, 3 Jan 2020 15:48:54 +0100 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.3.1 Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@lists.gentoo.org Reply-to: gentoo-dev@lists.gentoo.org X-Auto-Response-Suppress: DR, RN, NRN, OOF, AutoReply MIME-Version: 1.0 In-Reply-To: Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="nuUibsRNaRlmvUbxJjkQpNeVP5DCwizKE" X-Archives-Salt: 90d28ea6-f58e-4beb-84b8-c70e75a2c3e5 X-Archives-Hash: 959c50b61ce8e76ba906050de055bd7d This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --nuUibsRNaRlmvUbxJjkQpNeVP5DCwizKE Content-Type: multipart/mixed; boundary="RY7qthyEeEU4LUJr2lpVhvqUwtiknCISZ"; protected-headers="v1" From: =?UTF-8?Q?Toralf_F=c3=b6rster?= To: gentoo-dev@lists.gentoo.org Message-ID: Subject: Re: [gentoo-dev] Vanilla sources References: <3197490.ugo6OjCCXa@daneel.sf-tec.de> <1794534.0xJHuh4lKC@crazyhorse> <19015309.XG3PSQ8cOu@daneel.sf-tec.de> <5537134e-0412-862d-e105-94c678229b46@gentoo.org> <2dd351b3-0f71-4960-ffde-2f5a99ab161d@gentoo.org> <9b48db99-19dc-617b-c0d4-ffa0216b43be@gentoo.org> In-Reply-To: --RY7qthyEeEU4LUJr2lpVhvqUwtiknCISZ Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: quoted-printable On 1/3/20 3:46 PM, Rich Freeman wrote: > If OpenRC contains a vulnerability wouldn't it make more sense to set > this as part of OpenRC, Indeed. Furthermore there's a nifty page https://kernsec.org/wiki/index.php/Kerne= l_Self_Protection_Project/Recommended_Settings which yields for me to this /etc/sysctl.d/local.conf : # Restrict potential illegal access via links #=20 fs.protected_hardlinks =3D 1 fs.protected_symlinks =3D 1=20 # # https://kernsec.org/wiki/index.php/Kernel_Self_Protection_Project#CONFI= Gs # # Try to keep kernel address exposures out of various /proc files (kallsy= ms, modules, etc). kernel.kptr_restrict =3D 1 # Avoid kernel memory address exposures via dmesg. kernel.dmesg_restrict =3D 1 # Block non-uid-0 profiling (needs distro patch, otherwise this is the sa= me as "=3D 2") kernel.perf_event_paranoid =3D 3 # Turn off kexec, even if it's built in. kernel.kexec_load_disabled =3D 1 # Avoid non-ancestor ptrace access to running processes and their credent= ials. kernel.yama.ptrace_scope =3D 1 # Disable User Namespaces, as it opens up a large attack surface to unpri= vileged users. user.max_user_namespaces =3D 0 # Turn off unprivileged eBPF access. kernel.unprivileged_bpf_disabled =3D 1 # Turn on BPF JIT hardening, if the JIT is enabled. net.core.bpf_jit_harden =3D 2 --=20 Toralf PGP 23217DA7 9B888F45 --RY7qthyEeEU4LUJr2lpVhvqUwtiknCISZ-- --nuUibsRNaRlmvUbxJjkQpNeVP5DCwizKE Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEE9Fss6CRzaFtvbcqtIyF9p5uIj0UFAl4PVFkACgkQIyF9p5uI j0VlQwf+LY6lfVAbKKCtcbEY8YD78NJvwgHhhu0EinB/umkujbFuKndsyt4VBMJH 053C+1OS9/++PVmUv27KI7HjIlECBF9k0Yp23Ih1Rmz9cio6oKHO8bqNtjq79duj zlfJvbRiLcG9QtY5knletuGsMtPQY7zu1pZaZ1s3XFLN9Y8hYSzXYiFGmFhZ2Nqi Qie0esVV9xQjoYii4G52aXaT/pT6LxHFKFOhiGH5tDHaCLP22BeBdou0dHZcSfku iAlcyWeKppY42uOBEZGfYtY9g7vBDkK4C0Uaw4TtsV0UwvR/pHCHReePuuxujP8C MCUKO5AtuZepTigzg8C2+xFzOHjHKg== =Rucj -----END PGP SIGNATURE----- --nuUibsRNaRlmvUbxJjkQpNeVP5DCwizKE--