public inbox for gentoo-hardened@lists.gentoo.org
 help / color / mirror / Atom feed
From: Tom Hendrikx <tom@whyscream.net>
To: gentoo-hardened@lists.gentoo.org
Subject: Re: [gentoo-hardened] Please test hardened-sources 2.6.32-r88 and 3.2.2
Date: Fri, 03 Feb 2012 15:11:36 +0100	[thread overview]
Message-ID: <4F2BEB18.9090604@whyscream.net> (raw)
In-Reply-To: <4F2BD518.2090702@whyscream.net>

On 03/02/12 13:37, Tom Hendrikx wrote:
> On 03/02/12 03:50, Brian Kroth wrote:
>> Tom Hendrikx <tom@whyscream.net> 2012-02-02 21:42:
>>> On 27/01/12 14:37, Anthony G. Basile wrote:
>>>> Hi everyone,
>>>>
>>>> I just added hardened-sources 2.6.32-r88 and 3.2.2 to the tree. They
>>>> address CVE-2012-0056. I've tested and they do indeed resist the
>>>> exploit. I will be stabilizing them within 24 hours. However, I feel
>>>> very uncomfortable doing so because I don't want to trade one set of
>>>> problems with another. If anyone has time to test, let me know if you
>>>> encounter any issues.
>>>>
>>>
>>> I am still using 2.6.* sources here on one machine pending resolution of
>>> bug https://bugs.gentoo.org/show_bug.cgi?id=386721 (if it will ever
>>> happen :/ ).
>>
>> Are those open-vm kernel modules still necessary? It was my
>> understanding that most/all of the guest modules for more efficient
>> virtual hardware support were included in the mainline kernel now:
>> <http://kernelnewbies.org/Linux_2_6_33#head-b1a0ddbc804d228802ce8aebd37d9fd6513ccb01>
>>
>
> I did some more investigation. None of the three in-tree
> open-vm-tools-kmod ebuilds compile against 2.6.32-r89, building a
> 3.2.2-r1 kernel now to test against that.

The same goes for 3.2.2-r1: none of the -kmod packages build against it. 
this means that the state of the -kmod package is a security issue, 
since it cannot be used with a non-vulnerable -hardened kernel. I'll add 
this to the bug report.

>
> I thought that I needed the -kmod package to run open-vm-tools in the
> guest, but after some more research this might only apply when you want
> drag-and-drop support (useless for (headless) server). The open-vm-tools
> ebuilds list the -kmod package as a hard RDEPEND though. I'll do some
> tests later today/during the weekend.
>

Just booted a 3.2.2-r1-hardened kernel, and vmware-tools stuff seems to 
run fine with the in-kernel vmware support. Not sure about performance 
etc, but it boots, generates no errors and VSphere in the host reports 
no issues either.

We might just need an updated open-vm-tools package that only depends on 
the in-kernel stuff, and no longer on the -kmod package. I'll try to 
followup with the vmware people, as this is getting OT here ;)

--
Tom



      reply	other threads:[~2012-02-03 14:11 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-01-27 13:37 [gentoo-hardened] Please test hardened-sources 2.6.32-r88 and 3.2.2 Anthony G. Basile
2012-01-27 16:02 ` "Tóth Attila"
2012-01-27 16:06   ` "Tóth Attila"
2012-01-27 17:38     ` [gentoo-hardened] Please test hardened-sources 2.6.32-r88 and3.2.2 radegand
2012-01-28  5:41       ` Anthony G. Basile
2012-01-28 19:21         ` [gentoo-hardened] " 7v5w7go9ub0o
2012-01-28 18:26           ` pageexec
2012-01-28 20:16             ` 7v5w7go9ub0o
2012-01-28 20:46               ` 7v5w7go9ub0o
2012-01-29 10:38               ` Alex Efros
2012-01-29 17:33                 ` 7v5w7go9ub0o
2012-01-28 20:41         ` [gentoo-hardened] " Radek Madej
2012-01-27 18:18 ` [gentoo-hardened] Re: Please test hardened-sources 2.6.32-r88 and 3.2.2 7v5w7go9ub0o
2012-02-02 20:42 ` [gentoo-hardened] " Tom Hendrikx
2012-02-02 20:47   ` Francisco Blas Izquierdo Riera (klondike)
2012-02-03  2:50   ` Brian Kroth
2012-02-03 12:37     ` Tom Hendrikx
2012-02-03 14:11       ` Tom Hendrikx [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4F2BEB18.9090604@whyscream.net \
    --to=tom@whyscream.net \
    --cc=gentoo-hardened@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox