o_O I don't see grsecurity there! Am I blind? .config - Linux Kernel v2.6.36-hardened-r5 Configuration ────────────────────────────────────────────────────────────────────────────── ┌─────────────────────────── Security options ────────────────────────────┐ │ Arrow keys navigate the menu. <Enter> selects submenus --->. │ │ Highlighted letters are hotkeys. Pressing <Y> includes, <N> excludes, │ │ <M> modularizes features. Press <Esc><Esc> to exit, <?> for Help, </> │ │ for Search. Legend: [*] built-in [ ] excluded <M> module < > │ │ ┌─────────────────────────────────────────────────────────────────────┐ │ │ │ -*- Enable access key retention support │ │ │ │ [*] Enable the /proc/keys file by which keys may be viewed │ │ │ │ [*] Enable different security models │ │ │ │ [ ] Enable the securityfs filesystem │ │ │ │ [*] Socket and Networking Security Hooks │ │ │ │ [ ] XFRM (IPSec) Networking Security Hooks │ │ │ │ [ ] Security hooks for pathname based access control │ │ │ │ [ ] Enable Intel(R) Trusted Execution Technology (Intel(R) TXT) │ │ │ │ [ ] NSA SELinux Support │ │ │ │ [ ] Simplified Mandatory Access Control Kernel Support │ │ │ │ [ ] TOMOYO Linux Support │ │ │ │ [ ] AppArmor support (NEW) │ │ │ │ [ ] Integrity Measurement Architecture(IMA) │ │ │ │ Default security module (Unix Discretionary Access Controls) │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ └─────────────────────────────────────────────────────────────────────┘ │ ├─────────────────────────────────────────────────────────────────────────┤ │ <Select> < Exit > < Help > │ └─────────────────────────────────────────────────────────────────────────┘
On Wed, Dec 08, 2010 at 11:37:28PM -0500, Anthony G. Basile wrote: > Hi everyone, > > I need to fast track stabilize hardened-sources-2.6.32-r30 and > hardened-sources-2.6.36-r5 because of a local root exploit on all > earlier kernels. The ebuilds just hit the tree. > > Can I get feedback on how those kernels fair on x86 and amd64 arches? I > don't want to introduce new bugs that can be avoided. I hope to mark > them stable in about one week. > > Thanks. > > -- > Anthony G. Basile, Ph.D. > Gentoo Developer