[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-users] Xen+Grsec for 2.6.11.12


  • To: xen-users@xxxxxxxxxxxxxxxxxxx
  • From: Turi Peter <turip@xxxxxxx>
  • Date: Tue, 18 Oct 2005 08:50:07 +0200
  • Delivery-date: Tue, 18 Oct 2005 06:47:36 +0000
  • List-id: Xen user discussion <xen-users.lists.xensource.com>

Hi!

What do you mean under being "restricted"? Grsecurity works with 2.6 kernels. However it seems difficult (for me) to port all the i386 specific stuff to the xen arch (I've checked it this weekend)
The grsecurity patch modifies the internal working of memory management, 
initialization, and the xenolinux source contains a few modified parts 
of these files, so the grsec modifications should be merged ... but it's 
not straightforward.
The ACL subsystem could be ported easily, but I suppose when xen enters 
the official kernel tree a grsec patch will be released. So I don't want 
to create a half-working solution.
Peter


Dirk H. Schulz wrote:

Sebastian,

grsecurity seems to be restricted to 2.4 kernels. At least that is what http://www.grsecurity.net/ says.
Dirk

Sebastian Hyrwall schrieb:

Hello. This is my first post so please let me know if I'm doing something wrong.
Anyway. Does anyone have a homemade-patch or anything to make 
grsecurity work for 2.0.7 (2.6.11.12) in a domU (dom0 would be nice 
too).
It's right now the only thing stopping me from taking the step to 
using Xen in a "live enviroment".
Sincerely, Sebastian H

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users



_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.