[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-users] Xen+Grsec for 2.6.11.12


  • To: xen-users@xxxxxxxxxxxxxxxxxxx
  • From: Turi Peter <turip@xxxxxxx>
  • Date: Tue, 18 Oct 2005 08:50:07 +0200
  • Delivery-date: Tue, 18 Oct 2005 06:47:36 +0000
  • List-id: Xen user discussion <xen-users.lists.xensource.com>

Hi!

What do you mean under being "restricted"? Grsecurity works with 2.6 kernels. However it seems difficult (for me) to port all the i386 specific stuff to the xen arch (I've checked it this weekend)

The grsecurity patch modifies the internal working of memory management, initialization, and the xenolinux source contains a few modified parts of these files, so the grsec modifications should be merged ... but it's not straightforward.

The ACL subsystem could be ported easily, but I suppose when xen enters the official kernel tree a grsec patch will be released. So I don't want to create a half-working solution.

Peter


Dirk H. Schulz wrote:

Sebastian,

grsecurity seems to be restricted to 2.4 kernels. At least that is what http://www.grsecurity.net/ says.

Dirk

Sebastian Hyrwall schrieb:

Hello. This is my first post so please let me know if I'm doing something wrong.

Anyway. Does anyone have a homemade-patch or anything to make grsecurity work for 2.0.7 (2.6.11.12) in a domU (dom0 would be nice too). It's right now the only thing stopping me from taking the step to using Xen in a "live enviroment".

Sincerely, Sebastian H

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users




_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users



_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.