From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([208.92.234.80] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1RvuEQ-0002v0-MW for garchives@archives.gentoo.org; Fri, 10 Feb 2012 17:25:58 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 4DE1BE0517; Fri, 10 Feb 2012 17:25:44 +0000 (UTC) Received: from svr-us4.tirtonadi.com (svr-us4.tirtonadi.com [69.65.43.212]) by pigeon.gentoo.org (Postfix) with ESMTP id 0D2CFE0517 for ; Fri, 10 Feb 2012 17:24:42 +0000 (UTC) Received: from mail-ww0-f53.google.com ([74.125.82.53]) by svr-us4.tirtonadi.com with esmtpsa (TLSv1:RC4-SHA:128) (Exim 4.69) (envelope-from ) id 1RvuDF-003AgQ-QQ for gentoo-user@lists.gentoo.org; Sat, 11 Feb 2012 00:24:45 +0700 Received: by wgbdr12 with SMTP id dr12so2935211wgb.10 for ; Fri, 10 Feb 2012 09:24:39 -0800 (PST) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-user@lists.gentoo.org Reply-to: gentoo-user@lists.gentoo.org MIME-Version: 1.0 Received: by 10.180.80.35 with SMTP id o3mr4080831wix.5.1328894679160; Fri, 10 Feb 2012 09:24:39 -0800 (PST) Received: by 10.223.103.4 with HTTP; Fri, 10 Feb 2012 09:24:38 -0800 (PST) Received: by 10.223.103.4 with HTTP; Fri, 10 Feb 2012 09:24:38 -0800 (PST) In-Reply-To: <4F34D0D0.3040606@fu-berlin.de> References: <4F312D9A.4030908@fu-berlin.de> <4F3288C1.2070906@fu-berlin.de> <4F34D0D0.3040606@fu-berlin.de> Date: Sat, 11 Feb 2012 00:24:38 +0700 Message-ID: Subject: Re: [gentoo-user] Re: OT: SeAndroid build on a Gentoo System? From: Pandu Poluan To: gentoo-user@lists.gentoo.org Content-Type: multipart/alternative; boundary=f46d044287f24b983504b89f674e X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - svr-us4.tirtonadi.com X-AntiAbuse: Original Domain - lists.gentoo.org X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12] X-AntiAbuse: Sender Address Domain - poluan.info X-Archives-Salt: 2fb66d30-6664-422a-8af6-29ebc27e9d49 X-Archives-Hash: a2d5ff298975b440ede83809429b3fa8 --f46d044287f24b983504b89f674e Content-Type: text/plain; charset=UTF-8 On Feb 10, 2012 3:13 PM, "Hinnerk van Bruinehsen" < h.v.bruinehsen@fu-berlin.de> wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > On 08.02.2012 16:23, James wrote: > > Hinnerk van Bruinehsen fu-berlin.de> writes: > > > > > >> I own a Galaxy Nexus - up to now I encountered a bug in finding > >> the tools.jar of JDK (Google helped here) and a problem due to > >> the fact that I use hardened for building (TEXTREL, I think). > >> I'll try a stage 3 non hardened chroot later... > > > > How do you like the G. Nexus so far? Who is your (cell) service > > provider? > > > > I'm not sure I posted this link: > > http://marc.info/?l=selinux&r=1&b=201201&w=4 > > > > Note. Russell Coker (dev for SElinux and SEandroid) is very cool > > and has his up and running on Debian (Wheezy). If you get stuck, > > you can search him out for help. In my experiences with Russell, he > > is very friendly and helpful, particularly on the last "thingy" he > > is focused on, like SEandroid..... > > > > thanks for keeping me posted, James > > > It seems as if I'm not able to setup a proper build-environment with > hardened (due to chroot hardening the chroot isn't an option, either). > I'll try to find time to test it on a non-hardened host or in a vm > (which seems like a bad option, too, due to hardened restrictions). > > > If I get any further, I'll try to post some updates. > > Concerning the phone: I'm very happy with it, as it is. It's a big > upgrade from my old Wildfire. > My cell service provider is Vodafone (Germany). > > With kind regards, > Hinnerk > There are grsec knobs in sysctl that you can temporarily disable to "weaken" chroot for awhile. aW simple reboot will return these knobs to its default secure settings. (There's a thread I started when I have trouble doing things in a chroot, and the solution was to temporarily stable done grkernelsec features before going into chroot) Rgds, --f46d044287f24b983504b89f674e Content-Type: text/html; charset=UTF-8


On Feb 10, 2012 3:13 PM, "Hinnerk van Bruinehsen" <h.v.bruinehsen@fu-berlin.de> wrote:
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> On 08.02.2012 16:23, James wrote:
> > Hinnerk van Bruinehsen <h.v.bruinehsen <at> fu-berlin.de> writes:
> >
> >
> >> I own a Galaxy Nexus - up to now I encountered a bug in finding
> >> the tools.jar of JDK (Google helped here) and a problem due to
> >> the fact that I use hardened for building (TEXTREL, I think).
> >> I'll try a stage 3 non hardened chroot later...
> >
> > How do you like the G. Nexus so far? Who is your (cell) service
> > provider?
> >
> > I'm not sure I posted this link:
> > http://marc.info/?l=selinux&r=1&b=201201&w=4
> >
> > Note. Russell Coker (dev for SElinux and SEandroid) is very cool
> > and has his up and running on Debian (Wheezy). If you get stuck,
> > you can search him out for help. In my experiences with Russell, he
> > is very friendly and helpful, particularly on the last "thingy" he
> > is focused on, like SEandroid.....
> >
> > thanks for keeping me posted, James
> >
> It seems as if I'm not able to setup a proper build-environment with
> hardened (due to chroot hardening the chroot isn't an option, either).
> I'll try to find time to test it on a non-hardened host or in a vm
> (which seems like a bad option, too, due to hardened restrictions).
>
>
> If I get any further, I'll try to post some updates.
>
> Concerning the phone: I'm very happy with it, as it is. It's a big
> upgrade from my old Wildfire.
> My cell service provider is Vodafone (Germany).
>
> With kind regards,
> Hinnerk
>

There are grsec knobs in sysctl that you can temporarily disable to "weaken" chroot for awhile. aW simple reboot will return these knobs to its default secure settings.

(There's a thread I started when I have trouble doing things in a chroot, and the solution was to temporarily stable done grkernelsec features before going into chroot)

Rgds,

--f46d044287f24b983504b89f674e--