Re: [gentoo-hardened] gcc 4.5.3 doesn't build on x86 hardened profile

2012-02-06 Thread Alexander Tsoy
ortage/sys-devel/gcc-4.5.3-r1/work/build/gcc-build-logs.tar.bz2 in > your bug report > * > * The complete build log is located at > '/var/tmp/portage/sys-devel/gcc-4.5.3-r1/temp/build.log'. > * The ebuild environment file is located at > '/var/tmp/portage/sys-devel/gcc-4.5.3-r1/temp/environment'. > * S: '/var/tmp/portage/sys-devel/gcc-4.5.3-r1/work/build' From the gcc ebuild change log: 30 Dec 2011; Magnus Granberg gcc-4.5.3-r2.ebuild: Bump the piepatchset to 0.4.7 to fix 394821 -- With best regards, Alexander Tsoy

Re: [gentoo-hardened] udev do not generate 70-persistent-net.rules

2012-07-02 Thread Alexander Tsoy
stent-net-generator.rules There are exceptions for KVM, Xen, etc. Maybe you hit one of them? -- With best regards, Alexander Tsoy

Re: [gentoo-hardened] mptsas support with hardened

2012-10-25 Thread Alexander Tsoy
> http://forums.gentoo.org/viewtopic-t-940502.html > Hello, this is not a hardened-specific question. But the answer is simple: you have to enable "Device Drivers" -> "Fusion MPT device support" -> "Fusion MPT ScsiHost drivers for SAS" in nconfig/menuconfig/etc. -- With best regards, Alexander Tsoy

Re: [gentoo-hardened] erlang fails to install on kvm guest (illegal instruction)

2012-11-20 Thread Alexander Tsoy
etes > successfully. The only thing I can think of is that something is wrong > with my CFLAGS(but this is just an assumption). > > Any help would be appreciated > > Regards, > > Yannis > It seems that KVM host is and AMD-based system. I suggest you to drop "-march=core2" from CFLAGS. Or if you do not plan to migrate this VM you can also try to replace it with something like "-march=amdfam10 -mno-3dnow". :) -- With best regards, Alexander Tsoy

Re: [gentoo-hardened] erlang fails to install on kvm guest (illegal instruction)

2012-11-20 Thread Alexander Tsoy
В Tue, 20 Nov 2012 17:50:36 +0200 Yannis Kontekakis пишет: > On 11/20/2012 05:34 PM, Alexander Tsoy wrote: > > В Tue, 20 Nov 2012 16:54:39 +0200 > > Yannis Kontekakis пишет: > > > >> Hello, > >> > >> I am trying to install erlang on a hardened

Re: [gentoo-hardened] gentoo hardened archive broken

2012-11-22 Thread Alexander Tsoy
On чт 22 ноя 2012 22:21:05 MSK, Javier Juan Martínez Cabezón wrote: > > > Hi, just to say we have the mailing list archive broken: > > http://archives.gentoo.org/gentoo-hardened/ > Look at this bug report: https://bugs.gentoo.org/show_bug.cgi?id=424647 -- with best

Re: [gentoo-hardened] Cleaning up the hardened profiles

2013-01-27 Thread Alexander Tsoy
links. > > If no one is using them, I'll mark them deprecated, and dump them in a > month or two. > > Comments? I've never used these subprofiles. -- Alexander Tsoy

Re: [gentoo-hardened] Can't build 3.8.3: kernel/user_namespace.c In function 'userns_install'

2013-04-17 Thread Alexander Tsoy
stall': > kernel/user_namespace.c:808:25: error: invalid operands to binary != (have > 'atomic_t' and 'int') > make[1]: *** [kernel/user_namespace.o] Error 1 > make: *** [kernel] Error 2 > > Hello This is a known issue http://forums.grsecurity.net/viewtopic.php?t=3358&p=12707 -- Alexander Tsoy

Re: [gentoo-hardened] gnome-shell segfault

2013-05-13 Thread Alexander Tsoy
ssage, 2 > matched rules; type="method_call", sender=":1.230" (uid=500 pid=15358 > comm="/usr/bin/gnome-shell ") > interface="org.freedesktop.DBus.Properties" member="GetAll" error > name="(unset)" requested_reply="0" destination=":1.0" (uid=0 pid=1912 > comm="/usr/sbin/console-kit-daemon ") > May 12 20:35:11 siren gnome-session[15161]: WARNING: Application > 'gnome-shell.desktop' killed by signal 11 > May 12 20:35:11 siren gnome-session[15161]: WARNING: App > 'gnome-shell.desktop' respawning too quickly > Hello! Do you have errors like 'grsec: denied RWX mprotect of ...' in dmesg or journal? Also see this bug report: https://bugs.gentoo.org/show_bug.cgi?id=455938 -- Alexander Tsoy

Re: [gentoo-hardened] RELRO and Xorg

2013-10-25 Thread Alexander Tsoy
> So radeon still needs lazy. But Xorg and other drivers are RELRO now. > I have to say the first load of X takes a bit longer than usuall - makes > sense because of the BIND_NOW... > > How I can define the load order of the modules? > I may play around with it. A bit more false sense of security! :-) > > Thx: Dw. Same problem with glamor. See comment 1 for an example of how to define the load order of modules. https://bugs.gentoo.org/show_bug.cgi?id=488906 -- Alexander Tsoy

Re: [gentoo-hardened] New messages in log with hs-3.11.9-r1

2013-11-27 Thread Alexander Tsoy
Bonding is supported by net-misc/netctl. Also, this functionality will be in systemd itself in the future (systemd-networkd). http://lists.freedesktop.org/archives/systemd-devel/2013-November/014115.html -- Alexander Tsoy

Re: [gentoo-hardened] systemd transition stalled

2013-12-17 Thread Alexander Tsoy
h libsystemd-login.so which need access to "/proc/1") > > I'm trying real hard to be a shepherd. But this time I feel the urge - > again - to purge the remnants of the once so shiny GNOME from my systems. > > Any thoughts on this? Or rather a grsec proc config workaround? > > Thx: > Dw. -- Alexander Tsoy

Re: [gentoo-hardened] hardened-sources wrt CVE-2014-3153 and CVE-2014-0196

2014-06-08 Thread Alexander Tsoy
letion-Wait loop timed out" and experience slowdowns; - KVM VMs with virtio network interface completely crashes without any error messages -- Alexander Tsoy

Re: [gentoo-hardened] Read this before installing sys-apps/gradm-3.0.201407162022

2014-07-24 Thread Alexander Tsoy
fix broken password authentication caused by recent commit 4b923540573b90c0b2274d510e4948aa9c962775 It was not possible to authenticate to the RBAC system as I misread the code and didn't notice it was stripping the trailing newline -- Alexander Tsoy

Re: [gentoo-hardened] "grsec: denied RWX mprotect" doesn't kill app anymore

2014-11-01 Thread Alexander Tsoy
ering if they can't mmap > executable memory. Alex uses nvidia blob, so fdo bug is unrelated here: > > # eselect opengl list > > Available OpenGL implementations: > > [1] nvidia * > > [2] xorg-x11 -- Alexander Tsoy

Re: [gentoo-hardened] hardened sources 4.1.7 vs 4.3.3

2016-02-19 Thread Alexander Tsoy
; What should I do? > > /Gandalf > I also noticed this. Probably an accidental removal of stable 4.3.3-r4: https://gitweb.gentoo.org/repo/gentoo.git/commit/sys-kernel/hardened-sources?id=788c313e6bf3a35010837b5089b89cc48fcd6c31 -- Alexander Tsoy

Re: [gentoo-hardened] What does the pic USE flag do these days?

2018-09-27 Thread Alexander Tsoy
В Чт, 27/09/2018 в 15:45 +0200, Hanno Böck пишет: > On Fri, 21 Sep 2018 00:16:48 +0100 > Luis Ressel wrote: > > > On Wed, 19 Sep 2018 09:24:27 +0200 > > Hanno Böck wrote: > > > > > If the flag just disables assembly optimizations then I wonder if > > > it > > > should be renamed (or if we need