summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorGordon Malm <gengor@gentoo.org>2008-09-13 01:53:51 +0000
committerGordon Malm <gengor@gentoo.org>2008-09-13 01:53:51 +0000
commitfd8332ad19dac1e9896cc61287760bbf592c72cd (patch)
treeaec9bf528042a30c70201b549776e522933c20a0 /sys-kernel
parentUnmask x11-drm 20080710, since a modules.d solution has been committed. (diff)
downloadgentoo-2-fd8332ad19dac1e9896cc61287760bbf592c72cd.tar.gz
gentoo-2-fd8332ad19dac1e9896cc61287760bbf592c72cd.tar.bz2
gentoo-2-fd8332ad19dac1e9896cc61287760bbf592c72cd.zip
Add 2.6.25-r7, fixing bug #237473 (CVE-2008-3525) and a PaX bug.
(Portage version: 2.1.4.4)
Diffstat (limited to 'sys-kernel')
-rw-r--r--sys-kernel/hardened-sources/ChangeLog8
-rw-r--r--sys-kernel/hardened-sources/hardened-sources-2.6.25-r7.ebuild51
2 files changed, 58 insertions, 1 deletions
diff --git a/sys-kernel/hardened-sources/ChangeLog b/sys-kernel/hardened-sources/ChangeLog
index 46e8ebefde83..5f0b6f1f0c09 100644
--- a/sys-kernel/hardened-sources/ChangeLog
+++ b/sys-kernel/hardened-sources/ChangeLog
@@ -1,6 +1,12 @@
# ChangeLog for sys-kernel/hardened-sources
# Copyright 2000-2008 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/ChangeLog,v 1.239 2008/09/10 21:25:24 gengor Exp $
+# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/ChangeLog,v 1.240 2008/09/13 01:53:51 gengor Exp $
+
+*hardened-sources-2.6.25-r7 (13 Sep 2008)
+
+ 13 Sep 2008; Gordon Malm <gengor@gentoo.org>
+ +hardened-sources-2.6.25-r7.ebuild:
+ Add 2.6.25-r7, fixing bug #237473 (CVE-2008-3525) and a PaX bug.
10 Sep 2008; Gordon Malm <gengor@gentoo.org>
hardened-sources-2.6.25-r4.ebuild, hardened-sources-2.6.25-r5.ebuild,
diff --git a/sys-kernel/hardened-sources/hardened-sources-2.6.25-r7.ebuild b/sys-kernel/hardened-sources/hardened-sources-2.6.25-r7.ebuild
new file mode 100644
index 000000000000..2bcb9122a668
--- /dev/null
+++ b/sys-kernel/hardened-sources/hardened-sources-2.6.25-r7.ebuild
@@ -0,0 +1,51 @@
+# Copyright 1999-2008 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-2.6.25-r7.ebuild,v 1.1 2008/09/13 01:53:51 gengor Exp $
+
+ETYPE="sources"
+K_WANT_GENPATCHES="base extras"
+K_GENPATCHES_VER="10"
+
+inherit kernel-2
+detect_version
+
+HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-8"
+HGPV_URI="http://dev.gentoo.org/~gengor/distfiles/${CATEGORY}/${PN}/hardened-patches-${HGPV}.extras.tar.bz2
+ mirror://gentoo/hardened-patches-${HGPV}.extras.tar.bz2"
+SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}"
+
+UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2"
+UNIPATCH_EXCLUDE="4200_fbcondecor-0.9.4.patch"
+
+DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})"
+HOMEPAGE="http://www.gentoo.org/proj/en/hardened/"
+IUSE=""
+
+KEYWORDS="~alpha ~amd64 ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86"
+
+pkg_postinst() {
+ kernel-2_pkg_postinst
+
+ local GRADM_COMPAT="sys-apps/gradm-2.1.12*"
+
+ ewarn
+ ewarn "As of ${CATEGORY}/${PN}-2.6.24 the predefined"
+ ewarn "\"Hardened [Gentoo]\" grsecurity level has been removed."
+ ewarn "Two improved predefined security levels replace it:"
+ ewarn "\"Hardened Gentoo [server]\" and \"Hardened Gentoo [workstation]\""
+ ewarn
+ ewarn "Those who intend to use one of these predefined grsecurity levels"
+ ewarn "should read the help associated with the level. Users importing a"
+ ewarn "kernel configuration from a kernel prior to ${PN}-2.6.24,"
+ ewarn "should review their selected grsecurity/PaX options carefully."
+ ewarn
+ ewarn
+ ewarn "Users of grsecurity's RBAC system must ensure they are using"
+ ewarn "${GRADM_COMPAT}, which is compatible with kernel series ${OKV}."
+ ewarn "Therefore, it is strongly recommended that the following command is"
+ ewarn "issued prior to booting a ${P} series kernel for"
+ ewarn "the first time:"
+ ewarn
+ ewarn "emerge -na =${GRADM_COMPAT}"
+ ewarn
+}