summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAnthony G. Basile <blueness@gentoo.org>2012-02-25 19:57:31 +0000
committerAnthony G. Basile <blueness@gentoo.org>2012-02-25 19:57:31 +0000
commitbf7921e4535547548e27d6120dafa601ffc58efc (patch)
tree4edfc4d654660d20adb0142c5e35b6b24fd2a456 /sys-kernel/hardened-sources
parentold (diff)
downloadgentoo-2-bf7921e4535547548e27d6120dafa601ffc58efc.tar.gz
gentoo-2-bf7921e4535547548e27d6120dafa601ffc58efc.tar.bz2
gentoo-2-bf7921e4535547548e27d6120dafa601ffc58efc.zip
Based on 3.2.7 + genpatches-3.2-9 + grsecurity-2.9-3.2.7-201202251203
Based on 2.6.32.57 + genpatches-2.6.32-48 + grsecurity-2.9-2.6.32.57-201202251202 (Portage version: 2.1.10.44/cvs/Linux x86_64)
Diffstat (limited to 'sys-kernel/hardened-sources')
-rw-r--r--sys-kernel/hardened-sources/ChangeLog15
-rw-r--r--sys-kernel/hardened-sources/hardened-sources-2.6.32-r92.ebuild52
-rw-r--r--sys-kernel/hardened-sources/hardened-sources-3.2.7.ebuild51
3 files changed, 117 insertions, 1 deletions
diff --git a/sys-kernel/hardened-sources/ChangeLog b/sys-kernel/hardened-sources/ChangeLog
index 47c1f3a6ce44..32f3496bedcb 100644
--- a/sys-kernel/hardened-sources/ChangeLog
+++ b/sys-kernel/hardened-sources/ChangeLog
@@ -1,6 +1,19 @@
# ChangeLog for sys-kernel/hardened-sources
# Copyright 1999-2012 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/ChangeLog,v 1.543 2012/02/18 18:41:27 blueness Exp $
+# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/ChangeLog,v 1.544 2012/02/25 19:57:31 blueness Exp $
+
+*hardened-sources-3.2.7 (25 Feb 2012)
+
+ 25 Feb 2012; Anthony G. Basile <blueness@gentoo.org>
+ +hardened-sources-2.6.32-r92.ebuild, +hardened-sources-3.2.7.ebuild:
+ Based on 3.2.7 + genpatches-3.2-9 + grsecurity-2.9-3.2.7-201202251203
+
+*hardened-sources-2.6.32-r92 (25 Feb 2012)
+
+ 25 Feb 2012; Anthony G. Basile <blueness@gentoo.org>
+ +hardened-sources-2.6.32-r92.ebuild:
+ Based on 2.6.32.57 + genpatches-2.6.32-48 +
+ grsecurity-2.9-2.6.32.57-201202251202
18 Feb 2012; Anthony G. Basile <blueness@gentoo.org>
-hardened-sources-2.6.32-r89.ebuild, hardened-sources-2.6.32-r90.ebuild:
diff --git a/sys-kernel/hardened-sources/hardened-sources-2.6.32-r92.ebuild b/sys-kernel/hardened-sources/hardened-sources-2.6.32-r92.ebuild
new file mode 100644
index 000000000000..af2634747603
--- /dev/null
+++ b/sys-kernel/hardened-sources/hardened-sources-2.6.32-r92.ebuild
@@ -0,0 +1,52 @@
+# Copyright 1999-2012 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-2.6.32-r92.ebuild,v 1.1 2012/02/25 19:57:31 blueness Exp $
+
+EAPI="4"
+
+ETYPE="sources"
+K_WANT_GENPATCHES="base extras"
+K_GENPATCHES_VER="48"
+K_DEBLOB_AVAILABLE="1"
+
+inherit kernel-2
+detect_version
+
+HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-94"
+HGPV_URI="http://dev.gentoo.org/~blueness/hardened-sources/hardened-patches/hardened-patches-${HGPV}.extras.tar.bz2"
+SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}"
+
+UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2"
+UNIPATCH_EXCLUDE="4200_fbcondecor-0.9.6.patch"
+! use xtpax && UNIPATCH_EXCLUDE+=" 4425_grsec_enable_xtpax.patch"
+
+DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})"
+HOMEPAGE="http://www.gentoo.org/proj/en/hardened/"
+IUSE="deblob -xtpax"
+
+KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86"
+
+RDEPEND=">=sys-devel/gcc-4.5"
+
+pkg_postinst() {
+ kernel-2_pkg_postinst
+
+ local GRADM_COMPAT="sys-apps/gradm-2.9"
+
+ ewarn
+ ewarn "Hardened Gentoo provides three different predefined grsecurity level:"
+ ewarn "[server], [workstation], and [virtualization]."
+ ewarn
+ ewarn "Those who intend to use one of these predefined grsecurity levels"
+ ewarn "should read the help associated with the level. Users importing a"
+ ewarn "kernel configuration from a kernel prior to ${PN}-2.6.32,"
+ ewarn "should review their selected grsecurity/PaX options carefully."
+ ewarn
+ ewarn "Users of grsecurity's RBAC system must ensure they are using"
+ ewarn "${GRADM_COMPAT}, which is compatible with ${PF}."
+ ewarn "It is strongly recommended that the following command is issued"
+ ewarn "prior to booting a ${PF} kernel for the first time:"
+ ewarn
+ ewarn "emerge -na =${GRADM_COMPAT}"
+ ewarn
+}
diff --git a/sys-kernel/hardened-sources/hardened-sources-3.2.7.ebuild b/sys-kernel/hardened-sources/hardened-sources-3.2.7.ebuild
new file mode 100644
index 000000000000..008bc1685c6f
--- /dev/null
+++ b/sys-kernel/hardened-sources/hardened-sources-3.2.7.ebuild
@@ -0,0 +1,51 @@
+# Copyright 1999-2012 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-3.2.7.ebuild,v 1.1 2012/02/25 19:57:31 blueness Exp $
+
+EAPI="4"
+
+ETYPE="sources"
+K_WANT_GENPATCHES="base extras"
+K_GENPATCHES_VER="9"
+K_DEBLOB_AVAILABLE="1"
+
+inherit kernel-2
+detect_version
+
+HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-1"
+HGPV_URI="http://dev.gentoo.org/~blueness/hardened-sources/hardened-patches/hardened-patches-${HGPV}.extras.tar.bz2"
+SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}"
+
+UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2"
+UNIPATCH_EXCLUDE="4200_fbcondecor-0.9.6.patch"
+! use xtpax && UNIPATCH_EXCLUDE+=" 4425_grsec_enable_xtpax.patch"
+
+DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})"
+HOMEPAGE="http://www.gentoo.org/proj/en/hardened/"
+IUSE="deblob -xtpax"
+
+KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc ~x86"
+
+RDEPEND=">=sys-devel/gcc-4.5"
+
+pkg_postinst() {
+ kernel-2_pkg_postinst
+
+ local GRADM_COMPAT="sys-apps/gradm-2.9"
+
+ ewarn
+ ewarn "Hardened Gentoo provides three different predefined grsecurity level:"
+ ewarn "[server], [workstation], and [virtualization]. Those who intend to"
+ ewarn "use one of these predefined grsecurity levels should read the help"
+ ewarn "associated with the level. Because some options require >=gcc-4.5,"
+ ewarn "users with more, than one version of gcc installed should use gcc-config"
+ ewarn "to select a compatible version."
+ ewarn
+ ewarn "Users of grsecurity's RBAC system must ensure they are using"
+ ewarn "${GRADM_COMPAT}, which is compatible with ${PF}."
+ ewarn "It is strongly recommended that the following command is issued"
+ ewarn "prior to booting a ${PF} kernel for the first time:"
+ ewarn
+ ewarn "emerge -na =${GRADM_COMPAT}"
+ ewarn
+}