Mailing List Archive

Clarification on "Cleaning up the hardened profiles"
Just to make things clear (replace $ARCH by your architecture)

1) We are going to create a test version of the 13.0 base profiles with
hardened of the next profiles currently using 10.0. These will also be
replaced by the 13.0 version after a testing period.
hardened/linux/$ARCH
hardened/linux/$ARCH/selinux
hardened/linux/$ARCH/no-multilib
hardened/linux/$ARCH/no-multilib/selinux

2) The following profiles are not oficial and we don't want the burden
of maintaining them so, unless somebody steps out stating they use them
they will be deprecated and removed in two months.
hardened/linux/$ARCH/desktop
hardened/linux/$ARCH/developer
hardened/linux/$ARCH/server
hardened/linux/$ARCH/minimal/

3) Any profile not listed in this e-mail won't be touched for now. This
at least covers:
hardened/linux/amd64/x32/

I hope this helps you understand the things happening here If I made any
mistake I hereby invoke blueness to correct me.
Re: Clarification on "Cleaning up the hardened profiles" [ In reply to ]
hardened/linux/amd64/x32/ ?
http://lwn.net/Articles/500482/ says gcc-4.7 is a requirement.
Anybody using hardened x32? How mature it is? Does it copes well with PaX?
--
dr Tóth Attila, Radiológus, 06-20-825-8057
Attila Toth MD, Radiologist, +36-20-825-8057

2013.Január 28.(H) 22:16 időpontban Francisco Blas Izquierdo Riera
(klondike) ezt írta:
> Just to make things clear (replace $ARCH by your architecture)
>
> 1) We are going to create a test version of the 13.0 base profiles with
> hardened of the next profiles currently using 10.0. These will also be
> replaced by the 13.0 version after a testing period.
> hardened/linux/$ARCH
> hardened/linux/$ARCH/selinux
> hardened/linux/$ARCH/no-multilib
> hardened/linux/$ARCH/no-multilib/selinux
>
> 2) The following profiles are not oficial and we don't want the burden
> of maintaining them so, unless somebody steps out stating they use them
> they will be deprecated and removed in two months.
> hardened/linux/$ARCH/desktop
> hardened/linux/$ARCH/developer
> hardened/linux/$ARCH/server
> hardened/linux/$ARCH/minimal/
>
> 3) Any profile not listed in this e-mail won't be touched for now. This
> at least covers:
> hardened/linux/amd64/x32/
>
> I hope this helps you understand the things happening here If I made any
> mistake I hereby invoke blueness to correct me.
>
>
Re: Clarification on "Cleaning up the hardened profiles" [ In reply to ]
El 28/01/13 22:59, "Tóth Attila" escribió:
> hardened/linux/amd64/x32/ ?
> http://lwn.net/Articles/500482/ says gcc-4.7 is a requirement.
> Anybody using hardened x32? How mature it is? Does it copes well with PaX?
Just don't, IIRC 4.7.1 is still not supported.