It looks like upstream RSBAC is active again. Gentoo used to have
rsbac-sources, so it would be nice to get them back.
I'm not sure right now if I want them to be part of hardened-sources
unconditionally, or switched on and off with a USE="rsbac" flag, or as a
separate package called hardened-rsbac-sources. I'm leaning towards the
third option because it make maintenance easier --- it disconnects
releases of GRSEC from releases of RSBAC.
Currently the ebuild is on my overlay. The package is called:
sys-kernel/hardened-rsbac-sources
I tested but hit a compile time error, but I didn't test very hard. If
you're instrested in RSBAC, please test and we'll start to bug report
and send patches upstream to help them out.
--
Anthony G. Basile, Ph.D.
Gentoo Linux Developer [Hardened]
E-Mail : blueness@gentoo.org
GnuPG FP : 8040 5A4D 8709 21B1 1A88 33CE 979C AF40 D045 5535
GnuPG ID : D0455535
09-04-2011, 11:38 PM
"Francisco Blas Izquierdo Riera (klondike)"
Bringing back RSBAC sources
El 05/09/11 01:07, Anthony G. Basile escribió:
> I tested but hit a compile time error, but I didn't test very hard. If
> you're instrested in RSBAC, please test and we'll start to bug report
> and send patches upstream to help them out
blueness didn't state out but I will, RSBAC docs may be also obsolete
too so if we are going full way (i.e. resurrect the project back from
the stray projects limbo) we'll need a doc writer who is willing to use
RSBAC. So If anybody is interested I won't mind teaching them the
documentation basics so they can start.
09-06-2011, 01:48 PM
Javier Juan Martínez Cabezón
Bringing back RSBAC sources
Well, as rsbac user I would tell you that the gentoo rsbac docs are not as obsoleted as you could suppose, maybe some questions could be more complete but as starting point is right. Global RC learning mode and CAP learning mode has been implemented, other "minor changes" could be for example distinction between video memory and main memory under control by RC with their own SCD.
*
2011/9/5 Francisco Blas Izquierdo Riera (klondike) <klondike@gentoo.org>
El 05/09/11 01:07, Anthony G. Basile escribió:
> I tested but hit a compile time error, but I didn't test very hard. *If
> you're instrested in RSBAC, please test and we'll start to bug report
> and send patches upstream to help them out
blueness didn't state out but I will, RSBAC docs may be also obsolete
too so if we are going full way (i.e. resurrect the project back from
the stray projects limbo) we'll need a doc writer who is willing to use
RSBAC. So If anybody is interested I won't mind teaching them the