summaryrefslogtreecommitdiff
path: root/sys-kernel/librehardened-sources/librehardened-sources-2.6.29.ebuild
blob: 32f924cb6bb4c7cb2201bb7d67535d3d443a470a (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
# Copyright 1999-2009 Gentoo Foundation
# Distributed under the terms of the GNU General Public License v2
# $Header: $

EAPI="2"

K_SECURITY_UNSUPPORTED="1"
ETYPE="sources"
K_WANT_GENPATCHES="base extras"
K_GENPATCHES_VER="6"
LIBRE_VER="1"

inherit kernel-libre
detect_version

HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-1"
HGPV_URI="http://dev.gentoo.org/~gengor/distfiles/${CATEGORY}/${PN}/hardened-patches-${HGPV}.extras.tar.bz2"

UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2"
UNIPATCH_EXCLUDE="4201_fbcondecor-0.9.6.patch"

KEYWORDS="~x86"
IUSE=""
HOMEPAGE="http://www.fsfla.org/svnwiki/selibre/linux-libre/
http://www.gentoo.org/proj/en/hardened/"

DESCRIPTION="Hardened kernel sources (blob-free kernel, series
${KV_MAJOR}.${KV_MINOR})"
SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI} ${DEBLOB_URI}"

pkg_postinst() {
	kernel-2_pkg_postinst

	local GRADM_COMPAT="sys-apps/gradm-2.1.14*"

	ewarn
	ewarn "As of ${CATEGORY}/${PN}-2.6.24 the predefined"
	ewarn "\"Hardened [Gentoo]\" grsecurity level has been removed."
	ewarn "Two improved predefined security levels replace it:"
	ewarn "\"Hardened Gentoo [server]\" and \"Hardened Gentoo [workstation]\""
	ewarn
	ewarn "Those who intend to use one of these predefined grsecurity levels"
	ewarn "should read the help associated with the level. Users importing a"
	ewarn "kernel configuration from a kernel prior to ${PN}-2.6.24,"
	ewarn "should review their selected grsecurity/PaX options carefully."
	ewarn
	ewarn
	ewarn "Users of grsecurity's RBAC system must ensure they are using"
	ewarn "${GRADM_COMPAT}, which is compatible with kernel series ${OKV}."
	ewarn "Therefore, it is strongly recommended that the following command is"
	ewarn "issued prior to booting a ${P} series kernel for"
	ewarn "the first time:"
	ewarn
	ewarn "emerge -na =${GRADM_COMPAT}"
	ewarn
}