From 5898fe769d039856609162036af9444a3b6e00c0 Mon Sep 17 00:00:00 2001 From: Nick White Date: Thu, 18 Jun 2009 09:41:13 +0100 Subject: Added librehardened, and allow for libre versions --- eclass/kernel-libre.eclass | 8 ++-- .../librehardened-sources-2.6.29.ebuild | 50 ++++++++++++++++++++++ 2 files changed, 54 insertions(+), 4 deletions(-) create mode 100644 sys-kernel/librehardened-sources/librehardened-sources-2.6.29.ebuild diff --git a/eclass/kernel-libre.eclass b/eclass/kernel-libre.eclass index 12f50cf..77845ac 100644 --- a/eclass/kernel-libre.eclass +++ b/eclass/kernel-libre.eclass @@ -7,13 +7,13 @@ inherit kernel-2 EXPORT_FUNCTIONS src_unpack DEBLOB_CHECK="deblob-check" -KERNEL_URI="http://www.linux-libre.fsfla.org/pub/linux-libre/releases/${PV}-libre/linux-${PV}-libre.tar.bz2" -DEBLOB_URI="http://www.linux-libre.fsfla.org/pub/linux-libre/releases/${PV}-libre/${DEBLOB_CHECK}" +KERNEL_URI="http://www.linux-libre.fsfla.org/pub/linux-libre/releases/${PV}-libre${LIBRE_VER}/linux-${PV}-libre${LIBRE_VER}.tar.bz2" +DEBLOB_URI="http://www.linux-libre.fsfla.org/pub/linux-libre/releases/${PV}-libre${LIBRE_VER}/${DEBLOB_CHECK}" -# override the kernel-2 function as tarball is named and laid out differently +# override the kernel-2 function as tarball is named differently universal_unpack() { cd ${WORKDIR} - unpack linux-${OKV}-libre.tar.bz2 + unpack linux-${OKV}-libre${LIBRE_VER}.tar.bz2 mv ${WORKDIR}/linux-${OKV} ${WORKDIR}/linux-${KV_FULL} \ || die "Unable to move source tree to ${KV_FULL}." cd ${S} diff --git a/sys-kernel/librehardened-sources/librehardened-sources-2.6.29.ebuild b/sys-kernel/librehardened-sources/librehardened-sources-2.6.29.ebuild new file mode 100644 index 0000000..9ac3093 --- /dev/null +++ b/sys-kernel/librehardened-sources/librehardened-sources-2.6.29.ebuild @@ -0,0 +1,50 @@ +K_SECURITY_UNSUPPORTED="1" +ETYPE="sources" +K_WANT_GENPATCHES="base extras" +K_GENPATCHES_VER="6" +LIBRE_VER="1" + +inherit kernel-libre +detect_version + +HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-1" +HGPV_URI="http://dev.gentoo.org/~gengor/distfiles/${CATEGORY}/${PN}/hardened-patches-${HGPV}.extras.tar.bz2" + +UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2" +UNIPATCH_EXCLUDE="4201_fbcondecor-0.9.6.patch" + +KEYWORDS="~x86" +IUSE="" +HOMEPAGE="http://www.fsfla.org/svnwiki/selibre/linux-libre/ +http://www.gentoo.org/proj/en/hardened/" + +DESCRIPTION="Hardened kernel sources (blob-free kernel, series +${KV_MAJOR}.${KV_MINOR})" +SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI} ${DEBLOB_URI}" + +pkg_postinst() { + kernel-2_pkg_postinst + + local GRADM_COMPAT="sys-apps/gradm-2.1.14*" + + ewarn + ewarn "As of ${CATEGORY}/${PN}-2.6.24 the predefined" + ewarn "\"Hardened [Gentoo]\" grsecurity level has been removed." + ewarn "Two improved predefined security levels replace it:" + ewarn "\"Hardened Gentoo [server]\" and \"Hardened Gentoo [workstation]\"" + ewarn + ewarn "Those who intend to use one of these predefined grsecurity levels" + ewarn "should read the help associated with the level. Users importing a" + ewarn "kernel configuration from a kernel prior to ${PN}-2.6.24," + ewarn "should review their selected grsecurity/PaX options carefully." + ewarn + ewarn + ewarn "Users of grsecurity's RBAC system must ensure they are using" + ewarn "${GRADM_COMPAT}, which is compatible with kernel series ${OKV}." + ewarn "Therefore, it is strongly recommended that the following command is" + ewarn "issued prior to booting a ${P} series kernel for" + ewarn "the first time:" + ewarn + ewarn "emerge -na =${GRADM_COMPAT}" + ewarn +} -- cgit v1.2.3