Bug#605090: [RFC] Proposal for a new linux-grsec source package

2015-12-20 Thread Jacob Appelbaum
It may make sense for us to have a package of paxrat with common configurations for Debian users: https://github.com/subgraph/paxrat This would ensure that everyone can use this kernel and have xorg work as expected, for example. Otherwise, I think we will see a lot of people who just run:

Bug#605090: [RFC] Proposal for a new linux-grsec source package

2015-12-19 Thread Ben Hutchings
On Sat, 2015-12-19 at 17:03 +, Jacob Appelbaum wrote: > On 12/19/15, Jacob Appelbaum wrote: [...] > > To boot Debian Jessie (with some testing pacakes too) to X - I had to set: > > > > kernel.grsecurity.disable_priv_io=0 > > kernel.pax.softmode=1 > > kernel.grsecirity.grsec_lock=0 > > > > W

Bug#605090: [RFC] Proposal for a new linux-grsec source package

2015-12-19 Thread Jacob Appelbaum
On 12/19/15, Jacob Appelbaum wrote: > On 12/19/15, Yves-Alexis Perez wrote: >> On jeu., 2015-11-05 at 22:08 +0100, Yves-Alexis Perez wrote: >>> On sam., 2015-10-10 at 21:55 +0200, Yves-Alexis Perez wrote: >>> > This is really a work in progress and this mail a request for comment. >>> > Especiall

Bug#605090: [RFC] Proposal for a new linux-grsec source package

2015-12-19 Thread Jacob Appelbaum
On 12/19/15, Yves-Alexis Perez wrote: > On jeu., 2015-11-05 at 22:08 +0100, Yves-Alexis Perez wrote: >> On sam., 2015-10-10 at 21:55 +0200, Yves-Alexis Perez wrote: >> > This is really a work in progress and this mail a request for comment. >> > Especially missing is: >> >> So, did any of you have

Bug#605090: [RFC] Proposal for a new linux-grsec source package

2015-12-19 Thread Yves-Alexis Perez
On jeu., 2015-11-05 at 22:08 +0100, Yves-Alexis Perez wrote: > On sam., 2015-10-10 at 21:55 +0200, Yves-Alexis Perez wrote: > > This is really a work in progress and this mail a request for comment. > > Especially missing is: > > So, did any of you have the chance to test it? I'm currently running

Bug#605090: [RFC] Proposal for a new linux-grsec source package

2015-11-12 Thread Yves-Alexis Perez
On sam., 2015-11-07 at 14:54 +, Ben Hutchings wrote: > 1. linux-grsec-{source,support} are included in debian/control but not > built by debian/rules.real.  I think these should be built; the latter > will be needed to build metapackages as in linux-latest. > > > 3. The changes to gencontrol.

Bug#605090: [RFC] Proposal for a new linux-grsec source package

2015-11-10 Thread Ben Hutchings
On Tue, 2015-11-10 at 10:42 +0100, Yves-Alexis Perez wrote: > On sam., 2015-11-07 at 14:54 +, Ben Hutchings wrote: > > I've given this a quick review and found a few issues: > > Thanks! > > > > 1. linux-grsec-{source,support} are included in debian/control but not > > built by debian/rules.re

Bug#605090: [RFC] Proposal for a new linux-grsec source package

2015-11-10 Thread Yves-Alexis Perez
On sam., 2015-11-07 at 14:54 +, Ben Hutchings wrote: > I've given this a quick review and found a few issues: Thanks! > > 1. linux-grsec-{source,support} are included in debian/control but not > built by debian/rules.real.  I think these should be built; the latter > will be needed to build m

Bug#605090: [RFC] Proposal for a new linux-grsec source package

2015-11-07 Thread Ben Hutchings
On Thu, 2015-11-05 at 22:08 +0100, Yves-Alexis Perez wrote: > On sam., 2015-10-10 at 21:55 +0200, Yves-Alexis Perez wrote: > > This is really a work in progress and this mail a request for comment. > > Especially missing is: > > So, did any of you have the chance to test it? I'm currently running

Bug#605090: [RFC] Proposal for a new linux-grsec source package

2015-11-05 Thread Yves-Alexis Perez
On sam., 2015-10-10 at 21:55 +0200, Yves-Alexis Perez wrote: > This is really a work in progress and this mail a request for comment. > Especially missing is: So, did any of you have the chance to test it? I'm currently running the 4.2.5 kernel with grsecurity-3.1-4.2.5-201511021814 (just uploaded