[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: grsecurity-1.99cvs with parisc-linux-2.4.20pa22 patch



On Sat, Jan 25, 2003 at 07:43:41PM +0100, Alexander Gabert wrote:
> hello debian-hppa,
> 
> finally Brad and i got the grsecurity thing on my parisc box going...
> my test machine, a nice little 712 gecko, called "mickey" is currently
> running a freshly compiled 2.4.20-pa22-grsec...

Very cool! Very timely!
I just finished reading "@Large", the story about "infomaster/phantomd".
And todays news with the mysql worm wreaking havoc...


> here is the patch:
> 
> https://nikita.ath.cx/users/pappy/grsec/199_cvs_pappy/linux2420pa22-grsec199cvs-patch.txt

Issues with the patch:
o it's 1.8MB - at this size, gzipping would yeild good benefits.

o most of this patch is arch independent and touches nearly every
  part of the kernel.  Given the number of arches the patch has support
  for, there must be some reason why upstream hasn't accepted this yet.
  Anyone know why not?

o And lastly, someone needs to remove extraneous things that shouldn't
  go in the parisc CVS:
  - linux/Makefile, 
  - linux/*.orig (several of these)
  - linux/arch/i386 ia64 cris m68k etc

thanks,
grant



Reply to: