Re: Linux kernel hardening - link restrictions

2012-03-04 Thread Adam D. Barratt
On 04.03.2012 12:11, Adam D. Barratt wrote: On 04.03.2012 11:22, Ansgar Burchardt wrote: "Adam D. Barratt" writes: sounds like a reasonable plan to me, cc:ing debian-release to get a comment on this, and cc:ing the at maintainer too. (Predictably enough) I'd like to see a debdiff before a f

Re: Linux kernel hardening - link restrictions

2012-03-04 Thread Adam D. Barratt
On 04.03.2012 11:22, Ansgar Burchardt wrote: "Adam D. Barratt" writes: sounds like a reasonable plan to me, cc:ing debian-release to get a comment on this, and cc:ing the at maintainer too. (Predictably enough) I'd like to see a debdiff before a final ack, but in principle it looks okay; th

Re: Linux kernel hardening - link restrictions

2012-03-04 Thread Ansgar Burchardt
"Adam D. Barratt" writes: >> sounds like a reasonable plan to me, cc:ing debian-release to get a >> comment on this, and cc:ing the at maintainer too. > > (Predictably enough) I'd like to see a debdiff before a final ack, but > in principle it looks okay; thanks. Attached below. Regards, Ansgar

Re: Linux kernel hardening - link restrictions

2012-03-03 Thread Adam D. Barratt
On 02.03.2012 10:47, Holger Levsen wrote: On Freitag, 2. März 2012, Kees Cook wrote: > + * The new kernel version includes security restrictions on links, > +These restrictions may cause some legitimate programs to fail. > +In particular, if the 'at' package is installed, you should e

Re: Linux kernel hardening - link restrictions

2012-03-02 Thread Holger Levsen
Hi, On Freitag, 2. März 2012, Kees Cook wrote: > > + * The new kernel version includes security restrictions on links, > > +These restrictions may cause some legitimate programs to fail. > > +In particular, if the 'at' package is installed, you should either: > > +- Upgrade it to at l