<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened">
    <title>gmane.linux.gentoo.hardened</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5504"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5503"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5502"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5501"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5500"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5499"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5498"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5497"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5496"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5495"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5494"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5493"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5492"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5491"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5490"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5489"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5488"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5487"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5486"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5485"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5504">
    <title>Re: systemd and gentoo</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5504</link>
    <description>&lt;pre&gt;
systemd isn't required, nor are there plans to make it required in Gentoo.  
openrc is the default and will continue to be so.

hal is dead
-mike
&lt;/pre&gt;</description>
    <dc:creator>Mike Frysinger</dc:creator>
    <dc:date>2012-05-22T20:42:08</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5503">
    <title>Re: xattr/acl/cap</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5503</link>
    <description>&lt;pre&gt;
oh and since /dev is tmpfs, hence the need.

&amp;lt; at &amp;gt;original poster.  turn this on, its a good thing :)

&lt;/pre&gt;</description>
    <dc:creator>Anthony G. Basile</dc:creator>
    <dc:date>2012-05-21T16:34:27</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5502">
    <title>Re: Does hardened-sources include the Gentoo patchset?</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5502</link>
    <description>&lt;pre&gt;
Thanks Hinnerk.  I recently discovered the multitude of sys-kernel
packages listed at gpo.zugaina.org and I'm trying to figure them out.

- Grant


&lt;/pre&gt;</description>
    <dc:creator>Grant</dc:creator>
    <dc:date>2012-05-21T06:21:54</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5501">
    <title>Re: xattr/acl/cap</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5501</link>
    <description>&lt;pre&gt;On Mon, May 21, 2012 at 1:46 AM, Anthony G. Basile
&amp;lt;basile-yzvPICuk2ABaTBw8ZCwS0De48wsgrGvP&amp;lt; at &amp;gt;public.gmane.org&amp;gt; wrote:

If I am not mistaken, ConsoleKit uses ACLs to grant the currently
active user access to various /dev nodes. E.g., with ConsoleKit you
don't need to put users into "video", "audio" and "cdrom" groups
anymore (corresponding to v4l, sound, and dvd/cdrom devices), so
access permissions are more fine-grained and based on need.

&lt;/pre&gt;</description>
    <dc:creator>Maxim Kammerer</dc:creator>
    <dc:date>2012-05-21T00:06:35</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5500">
    <title>Re: xattr/acl/cap</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5500</link>
    <description>&lt;pre&gt;
Oh no!  You committed a grave sin asking here ... j/k :)  You can always 
ask and if we don't know then we'll redirect.


Working on it but progress is slow in gentoo.  The biggest obstacles are 
almost out of the way though with portage and tar both supporting xattr 
now but only in ~arch.


Okay this is where I have to redirect you because I'm not aware of this 
particular issue, ie why consolekit needs tmpfs posix acls.  To be 
clear, this means acl support on files that are on a tmpfs system.  This 
was pushed upstream by redhat that needed it for selinux.  But if you're 
not running a selinux system, i'm not sure why consolekit would need this.

In general though, its safe to turn on xattr/acl/caps even if you don't 
use them, and in some cases, eg selinux or the new pax markings, you 
must have xattr.

I don't think this answers your question but it does give you more context.


&lt;/pre&gt;</description>
    <dc:creator>Anthony G. Basile</dc:creator>
    <dc:date>2012-05-20T22:46:31</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5499">
    <title>Re: xattr/acl/cap</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5499</link>
    <description>&lt;pre&gt;
ACLs are actually very nice if you can get over the initial hurdle of
figuring out how they work. They're a lot like permissions on Windows,
except there's a highly confusing mask entry and umask plays into it...

Anyway, a lot of the time with the standard unix permissions you're
forced to give access to some people who don't need it. ACLs make it
possible to do things right.


&lt;/pre&gt;</description>
    <dc:creator>Michael Orlitzky</dc:creator>
    <dc:date>2012-05-20T22:45:55</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5498">
    <title>xattr/acl/cap</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5498</link>
    <description>&lt;pre&gt;Hi!

I'm not sure is this right place to ask…

What is current status for filesystem's xattr, acl and caps?

I'm usually keep all of this disabled in kernel, because I don't use them
and wanna avoid needless complexity. But today consolekit (which I don't
use, but which is installed anyway as someone's dependency) asked me to
enable CONFIG_TMPFS_POSIX_ACL. And I decide to check all this crap once again.

I may be wrong here, but after glance look at it I got this impression:

XATTR
    Needed only if you use ACL or CAPS (or wanna play with custom file
    attributes).
ACL
    Not sure about consolekit requirement above, but otherwise it looks
    useless (if you don't need to use complicated file permissions).
CAPS
    Looks promising, it's always good to remove suid bit, BUT:
    a)looks like only app which uses it now on my workstation is
wireshark, even /bin/ping is still installed suid
    b)pam_cap.so doesn't used by default (not sure why) so you can't change
user's default capabilities using /etc&lt;/pre&gt;</description>
    <dc:creator>Alex Efros</dc:creator>
    <dc:date>2012-05-20T21:35:51</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5497">
    <title>Re: Does hardened-sources include the Gentoo patchset?</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5497</link>
    <description>&lt;pre&gt;-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 20.05.2012 22:09, Grant wrote:

The ebuild names GENPATCHES_URI as a downloadsource.
In the Changelog are entries like:

14 May 2012; Anthony G. Basile &amp;lt;blueness-aBrp7R+bbdUdnm+yROfE0A&amp;lt; at &amp;gt;public.gmane.org&amp;gt;
  +hardened-sources-3.2.17.ebuild:
  Based on 3.2.17 + genpatches-3.2-14 + grsecurity-2.9-3.2.17-201205131657

Therefore I would dare to say: yes, they do. ;)

WKR
Hinnerk
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.19 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQEcBAEBAgAGBQJPuVI5AAoJEJwwOFaNFkYcfF0H/RO6O4aKBbonbQDYiw0WGBlk
U9kOediVzA0vmfiFAPmwzxmGZWhda7rgS9oq6kFWFkk4/6njcdpQOnwOS2pnbx6B
7Z/Lp0wOlh4dd57xX/kn04IqZSsa7U9Q10Hm/G+bD3BiUn+fZLiRononC55874mi
3z6OZBa1ZA3xr4w4sYB8pze+a5rNNHQiqR9W6yCJop9PLwbQ7090HXmbutTt6Qdl
YzaWCQ2aFk1sfKfNxB5f1t591HusCuD0meTxvFQpSBsYIlfw5ml8WlEXepg0+/po
qKu8AzZXpJSn+pKcjd3Br0J3vSE8GjOPnbFWib58xrh7kxOaFeMjmoFtrmC9jMM=
=gP3l
-----END PGP SIGNATURE-----


&lt;/pre&gt;</description>
    <dc:creator>Hinnerk van Bruinehsen</dc:creator>
    <dc:date>2012-05-20T20:21:13</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5496">
    <title>Does hardened-sources include the Gentoo patchset?</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5496</link>
    <description>&lt;pre&gt;Does anyone know if hardened-sources includes the Gentoo patchset?

- Grant


&lt;/pre&gt;</description>
    <dc:creator>Grant</dc:creator>
    <dc:date>2012-05-20T20:09:35</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5495">
    <title>Re: hardened-sources-3.2.11 + i965 + x.org: possible regression</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5495</link>
    <description>&lt;pre&gt;On Thu, May 17, 2012 at 6:04 AM, Anthony G. Basile
&amp;lt;basile-yzvPICuk2ABaTBw8ZCwS0De48wsgrGvP&amp;lt; at &amp;gt;public.gmane.org&amp;gt; wrote:

Bugged, #416637.  Only attached one .config since it's now clear
precisely what set of options creates this.


&lt;/pre&gt;</description>
    <dc:creator>RB</dc:creator>
    <dc:date>2012-05-19T16:09:46</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5494">
    <title>Re: hardened-sources-3.2.11 + i965 + x.org: possible regression</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5494</link>
    <description>&lt;pre&gt;
None intentionally, and none unintentionally that I can tell.
SLUB_DEBUG is on, but that's forced on by having SLUB as the
allocator.  DEBUG_KERNEL is also on, but so I can enable TIMER_STATS
(for xfce4-power-manager).


&lt;/pre&gt;</description>
    <dc:creator>RB</dc:creator>
    <dc:date>2012-05-19T06:22:42</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5493">
    <title>Re: hardened-sources-3.2.11 + i965 + x.org: possible regression</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5493</link>
    <description>&lt;pre&gt;

do you have any slab debugging options enabled by any chance?



&lt;/pre&gt;</description>
    <dc:creator>PaX Team</dc:creator>
    <dc:date>2012-05-18T22:18:14</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5492">
    <title>Re: hardened-sources-3.2.11 + i965 + x.org: possible regression</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5492</link>
    <description>&lt;pre&gt;On Fri, May 18, 2012 at 2:11 AM, Hinnerk van Bruinehsen
&amp;lt;h.v.bruinehsen-j/7cz5qe3tpn68oJJulU0Q&amp;lt; at &amp;gt;public.gmane.org&amp;gt; wrote:

That's because (as I just found by testing) PAX_KERNEXEC "mitigates"
the oops.  To put it in something of a boolean form, the following
produces the crashes:

PAX_MEMORY_UDEREF &amp;amp;&amp;amp; !(PAX_MEMORY_UDEREF &amp;amp;&amp;amp; PAX_KERNEXEC)


&lt;/pre&gt;</description>
    <dc:creator>RB</dc:creator>
    <dc:date>2012-05-18T19:29:24</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5491">
    <title>Re: systemd and gentoo</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5491</link>
    <description>&lt;pre&gt;On Fri, 18 May 2012 10:29:41 +0000
Pavel Labushev wrote:


has regex matching now

Fair enough but for me, I prefer a simple and scripted init system.


&lt;/pre&gt;</description>
    <dc:creator>Kevin Chadwick</dc:creator>
    <dc:date>2012-05-18T10:39:56</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5490">
    <title>Re: systemd and gentoo</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5490</link>
    <description>&lt;pre&gt;On Fri, 18 May 2012 08:56:03 +0100
Kevin Chadwick &amp;lt;ma1l1ists-/E1597aS9LT10XsdtD+oqA&amp;lt; at &amp;gt;public.gmane.org&amp;gt; wrote:


sysvinit:
- adding/removing/stopping a service requires editing inittab or ad-hoc
solutions
- no integrated logging
- no dependency tracking system

monit:
- depends on external systems like OpenRC =&amp;gt; might fail to restart
a service due to possible bugs in its complicated init script
- separate configuration files =&amp;gt; more work to write them and keep in
sync with OpenRC configuration
- does pid file inspection and periodic signalling instead of wait(2)
=&amp;gt; racy: might fail to restart a crashed service if its pid file
contains a pid of some running but unrelated process
- requires extra configuration not to restart a service when it was
temporarily shut down by administrator

supervise (daemontools) is like runit. There's nothing wrong with it,
yet it has some limitations that minit was designed to overcome:
http://www.fefe.de/minit/minit-linux-kongress2004.pdf
&lt;/pre&gt;</description>
    <dc:creator>Pavel Labushev</dc:creator>
    <dc:date>2012-05-18T10:29:41</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5489">
    <title>Re: hardened-sources-3.2.11 + i965 + x.org: possible regression</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5489</link>
    <description>&lt;pre&gt;-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 18.05.2012 09:18, Matthew Thode wrote:

For me X works fine with UDEREF enabled. I'm using xorg-server-1.12.1
and xf86-video-intel-2.19.0. (2 laptops, 1 core2 duo, 1 first
generation i5, if that has got something to do with it)

WKR
Hinnerk


PS: Issuing grep -i pax on my .config I get:

# PaX
CONFIG_PAX_KERNEXEC_PLUGIN=y
CONFIG_PAX_PER_CPU_PGD=y
CONFIG_PAX=y
# PaX Control
# CONFIG_PAX_SOFTMODE is not set
CONFIG_PAX_EI_PAX=y
CONFIG_PAX_PT_PAX_FLAGS=y
CONFIG_PAX_XATTR_PAX_FLAGS=y
# CONFIG_PAX_NO_ACL_FLAGS is not set
CONFIG_PAX_HAVE_ACL_FLAGS=y
# CONFIG_PAX_HOOK_ACL_FLAGS is not set
CONFIG_PAX_NOEXEC=y
CONFIG_PAX_PAGEEXEC=y
# CONFIG_PAX_EMUTRAMP is not set
CONFIG_PAX_MPROTECT=y
# CONFIG_PAX_MPROTECT_COMPAT is not set
# CONFIG_PAX_ELFRELOCS is not set
CONFIG_PAX_KERNEXEC=y
CONFIG_PAX_KERNEXEC_PLUGIN_METHOD_BTS=y
CONFIG_PAX_KERNEXEC_PLUGIN_METHOD="bts"
CONFIG_PAX_ASLR=y
CONFIG_PAX_RANDKSTACK=y
CONFIG_PAX_RANDUSTACK=y
CONFIG_PAX_RANDMMAP=y
CONFIG_PAX_MEMORY_STACKL&lt;/pre&gt;</description>
    <dc:creator>Hinnerk van Bruinehsen</dc:creator>
    <dc:date>2012-05-18T08:11:06</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5488">
    <title>Re: systemd and gentoo</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5488</link>
    <description>&lt;pre&gt;On Fri, 18 May 2012 02:56:06 +0000
Pavel Labushev wrote:


What's wrong with init respawn or supervise and/or monit?


&lt;/pre&gt;</description>
    <dc:creator>Kevin Chadwick</dc:creator>
    <dc:date>2012-05-18T07:56:03</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5487">
    <title>Re: systemd and gentoo</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5487</link>
    <description>&lt;pre&gt;On Fri, 18 May 2012 03:01:00 +0200
Tóth Attila wrote:


Your too polite, you mean, Somebody should give some people a slap for
breaking unix philosophies and not understanding what Unix is already
capable of.

I've already disabled consolekit and udisks. They bring little to the
table and cause problems for administartion and configuration. I haven't
decided on systemd yet but it looks potentially troublesome to me.


&lt;/pre&gt;</description>
    <dc:creator>Kevin Chadwick</dc:creator>
    <dc:date>2012-05-18T07:52:08</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5486">
    <title>Re: hardened-sources-3.2.11 + i965 + x.org: possible regression</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5486</link>
    <description>&lt;pre&gt;must be why I never hit it (I enable kernexec but leave uderef disabled
for virt).

&lt;/pre&gt;</description>
    <dc:creator>Matthew Thode</dc:creator>
    <dc:date>2012-05-18T07:18:17</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5485">
    <title>Re: systemd and gentoo</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5485</link>
    <description>&lt;pre&gt;Hi!

On Fri, May 18, 2012 at 02:56:06AM +0000, Pavel Labushev wrote:

Actually, if you decide to go this way, you probably find packages from my
overlay 'powerman' is good starting point:
- Use my sys-process/runit instead of ebuild in main portage.
  My version doesn't install boot scripts /etc/runit/{1,2,3}, because
  examples of these files installed by portage version of runit are trying
  to boot system using gentoo usual way, thus turning runit into mostly
  senseless drop-in replacement for /sbin/init.
- My package power-misc/runit-scripts provide /etc/runit/{1,2,3} boot
  scripts implemented in native for runit way. They are very small (about
  200 lines bash script used to completely boot and initialize system)
  and easy to update for your needs.
- My packages runit-service/service-* will provide you with scripts to run
  many daemons under runit supervision.

Together these packages provide complete replacement for gentoo default
boot scripts and services (in /etc/init.d/*). I'm using this for man&lt;/pre&gt;</description>
    <dc:creator>Alex Efros</dc:creator>
    <dc:date>2012-05-18T04:51:47</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.linux.gentoo.hardened/5484">
    <title>Re: systemd and gentoo</title>
    <link>http://permalink.gmane.org/gmane.linux.gentoo.hardened/5484</link>
    <description>&lt;pre&gt;On Fri, 18 May 2012 03:01:00 +0200
"Tóth Attila" &amp;lt;atoth-J1cgac+wqeJaB7pSnPOuKA&amp;lt; at &amp;gt;public.gmane.org&amp;gt; wrote:


My humble advise: try making your own custom scripts for runit, minit or
similar minimalistic supervisor together with sudo or su for PAM
support (setuid-root isn't required for root-&amp;gt;unprivileged uid
changes). It's simple, fast, maintainable and could be documented
without much effort.
&lt;/pre&gt;</description>
    <dc:creator>Pavel Labushev</dc:creator>
    <dc:date>2012-05-18T02:56:06</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.linux.gentoo.hardened">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.linux.gentoo.hardened</link>
  </textinput>
</rdf:RDF>

