<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Gentoo/Hardened on BAFM</title><link>https://christian.blog.pakiheim.de/tags/gentoo/hardened/</link><description>Recent content in Gentoo/Hardened on BAFM</description><generator>Hugo -- 0.160.1</generator><language>en</language><lastBuildDate>Sat, 16 Aug 2014 10:12:01 +0000</lastBuildDate><atom:link href="https://christian.blog.pakiheim.de/tags/gentoo/hardened/index.xml" rel="self" type="application/rss+xml"/><item><title>stages</title><link>https://christian.blog.pakiheim.de/posts/2014-08-16_stages/</link><pubDate>Sat, 16 Aug 2014 10:12:01 +0000</pubDate><guid isPermaLink="false">http://blog.barfoo.org/2008/01/08/stages</guid><description>&lt;p&gt;For what it&amp;rsquo;s worth, I&amp;rsquo;ve been trying to get some stages together the last few days. Thanks to &lt;a href="http://blogs.gentoo.org/solar"&gt;solar&lt;/a&gt; and &lt;a href="http://blogs.gentoo.org/ferdy"&gt;Brent&lt;/a&gt;, the ppc-stages are now coming along quite fast.&lt;/p&gt;
&lt;p&gt;I haven&amp;rsquo;t really tested them yet, but for what it&amp;rsquo;s worth, you&amp;rsquo;ll find stages based on Saturday&amp;rsquo;s snapshot (that is 200780105 for those not smart enough to take a look at the calendar) here for the following profiles:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;uclibc/ppc (normal/-softfloat)&lt;/li&gt;
&lt;li&gt;uclibc/ppc/hardened&lt;/li&gt;
&lt;li&gt;uclibc/x86&lt;/li&gt;
&lt;li&gt;uclibc/x86/hardened&lt;/li&gt;
&lt;li&gt;hardened/amd64&lt;/li&gt;
&lt;li&gt;hardened/amd64/nomultilib&lt;/li&gt;
&lt;li&gt;hardened/x86/2.6 (x86/i686)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Now remember, this isn&amp;rsquo;t &lt;em&gt;&lt;strong&gt;official&lt;/strong&gt;&lt;/em&gt; release material. This is just &lt;em&gt;&lt;strong&gt;MY&lt;/strong&gt;&lt;/em&gt; effort ( &lt;em&gt;for now&lt;/em&gt;) to provide current stages.&lt;/p&gt;</description></item><item><title>packages-barfoo-org is going away</title><link>https://christian.blog.pakiheim.de/posts/2014-08-08_packages-barfoo-org-is-going-away/</link><pubDate>Fri, 08 Aug 2014 09:09:37 +0000</pubDate><guid isPermaLink="false">http://blog.barfoo.org/?p=1550</guid><description>&lt;p&gt;For those of you, still using my binary packages. It&amp;rsquo;s just a waste of disk space for me (6.8G to be exact), so I decided to remove them. I&amp;rsquo;m gonna give people one week to grab yourself a copy. I&amp;rsquo;m gonna keep the bashrc and all the other stuff I wrote back when I was &lt;a href="https://christian.blog.pakiheim.de/posts/2014-08-16_turning-a-simple-chroot-into-a-binpkg-repository" title="Advanced bashrc ('Turning a simple chroot into a binpkg repository' continued)"&gt;still interested&lt;/a&gt; in binary packages, but the binary packages &lt;strong&gt;are gonna vanish&lt;/strong&gt;!&lt;/p&gt;</description></item><item><title>EPIA fun</title><link>https://christian.blog.pakiheim.de/posts/2008-03-04_epia-fun/</link><pubDate>Tue, 04 Mar 2008 19:39:07 +0000</pubDate><guid isPermaLink="false">http://blog.barfoo.org/?p=181</guid><description>&lt;p&gt;Well, as for replacing my current fileserver (which I seriously need to consider replacing), I&amp;rsquo;ll just pick up these things:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;3WARE 9550SXU-8LP (that&amp;rsquo;s 399,00€) plus riser card&lt;/li&gt;
&lt;li&gt;VIA EPIA EK 8000EG (that&amp;rsquo;s 201,69€)&lt;/li&gt;
&lt;li&gt;Kingston ValueRAM DIMM 1 GB DDR-400 (that&amp;rsquo;s 57,00€)&lt;/li&gt;
&lt;li&gt;4x Seagate ST31000340NS (that&amp;rsquo;s 279,00€ each - making a subtotal of 1.116,00€)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;So after browsing some more for a replacement for my current fileserver, I&amp;rsquo;d like to share the latest &lt;a href="https://christian.blog.pakiheim.de/posts/2014-08-16_stages"&gt;stages&lt;/a&gt; with you people. Thanks to Mike (who mentioned that binutils-2.18* already does the &lt;strong&gt;&lt;em&gt;LDFLAGS=&amp;quot;-Wl,-z,relro&amp;quot;&lt;/em&gt;&lt;/strong&gt; part) I replaced it with &lt;strong&gt;&lt;em&gt;&amp;quot;-Wl,-O1&amp;quot;&lt;/em&gt;&lt;/strong&gt;. Same old place, there&amp;rsquo;s fresh stages &amp;hellip; (and thanks again to Mike, with working &lt;a href="https://bugs.gentoo.org/show_bug.cgi?id=203711"&gt;util-linux-2.13-r2&lt;/a&gt;).&lt;/p&gt;</description></item><item><title>Saying thank you</title><link>https://christian.blog.pakiheim.de/posts/2007-04-19_saying-thank-you/</link><pubDate>Thu, 19 Apr 2007 21:28:14 +0000</pubDate><guid isPermaLink="false">http://blogs.barfoo.org/phreak/2007/04/08/saying-thank-you/</guid><description>&lt;p&gt;As I&amp;rsquo;m way better writing stuff than saying it with my own words, here a short &lt;em&gt;&amp;quot;&lt;/em&gt; &lt;strong&gt;Thank you!&lt;/strong&gt; &lt;em&gt;&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Christel, you have been a gracious and honest person, thanks for all the advice and help in the last year&lt;/li&gt;
&lt;li&gt;Chrissy, thanks for the inspiring words, you really made/make me feel better&lt;/li&gt;
&lt;li&gt;Alec (antarus), you&amp;rsquo;ve been a real friend and to say it with your own words &lt;em&gt;&amp;ldquo;It sucks to be you&amp;rdquo;&lt;/em&gt;; to phrase it differently, I&amp;rsquo;m really going to miss you&lt;/li&gt;
&lt;li&gt;Bryan, thanks for all the help, thanks for all the fun at FOSDEM (and after FOSDEM, hah)&lt;/li&gt;
&lt;li&gt;Ned, Alexander (pappy); you&amp;rsquo;ve both been an inspiration, thanks for letting me work on hardened foo; it has been real fun&lt;/li&gt;
&lt;li&gt;Mike (vapier), thanks for being a smart ass and inspiration at the same time&lt;/li&gt;
&lt;li&gt;Chris, thanks for the inspiration and for being a sarcastic person &amp;#x1f609;&lt;/li&gt;
&lt;li&gt;Andrew, thanks for trying to make a fun out of me &amp;#x1f61b; and thanks for warning me of Chris&amp;rsquo;s sarcasm&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Gentoo/hardened and the new toolchain</title><link>https://christian.blog.pakiheim.de/posts/2007-02-26_gentoo-hardened-and-the-new-toolchain/</link><pubDate>Mon, 26 Feb 2007 09:28:44 +0000</pubDate><guid isPermaLink="false">http://blogs.barfoo.org/phreak/2007/02/26/gentoohardened-and-the-new-toolchain/</guid><description>&lt;p&gt;OK, as some of you have noticed; I prepared my box for the new toolchain, recompiled the stuff Kevin mentioned in the exact same order wrote down in his README, and it looks like it actually works with all my stuff I have on my box; except &lt;em&gt;sys-libs/grub&lt;/em&gt;! &lt;em&gt;&lt;strong&gt;sigh&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Apparently, grub segfaults at boot and/or while running it from the chroot in the exact same spot, the new QA warnings complain about ..&lt;/p&gt;</description></item><item><title>hardened-sources-2-6-18</title><link>https://christian.blog.pakiheim.de/posts/2006-11-10_hardened-sources-2-6-18/</link><pubDate>Fri, 10 Nov 2006 23:56:45 +0000</pubDate><guid isPermaLink="false">http://blogs.barfoo.org/phreak/?p=91</guid><description>&lt;p&gt;Today (OK, it&amp;rsquo;s yesterday now, it&amp;rsquo;s again after 12:00) I had a little fun with pappy (Alexander Gabert) preparing 2.6.18 for prime time &amp;#x1f600;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt" id="hl-0-1"&gt;&lt;a class="lnlinks" href="#hl-0-1"&gt; 1&lt;/a&gt;
&lt;/span&gt;&lt;span class="lnt" id="hl-0-2"&gt;&lt;a class="lnlinks" href="#hl-0-2"&gt; 2&lt;/a&gt;
&lt;/span&gt;&lt;span class="lnt" id="hl-0-3"&gt;&lt;a class="lnlinks" href="#hl-0-3"&gt; 3&lt;/a&gt;
&lt;/span&gt;&lt;span class="lnt" id="hl-0-4"&gt;&lt;a class="lnlinks" href="#hl-0-4"&gt; 4&lt;/a&gt;
&lt;/span&gt;&lt;span class="lnt" id="hl-0-5"&gt;&lt;a class="lnlinks" href="#hl-0-5"&gt; 5&lt;/a&gt;
&lt;/span&gt;&lt;span class="lnt" id="hl-0-6"&gt;&lt;a class="lnlinks" href="#hl-0-6"&gt; 6&lt;/a&gt;
&lt;/span&gt;&lt;span class="lnt" id="hl-0-7"&gt;&lt;a class="lnlinks" href="#hl-0-7"&gt; 7&lt;/a&gt;
&lt;/span&gt;&lt;span class="lnt" id="hl-0-8"&gt;&lt;a class="lnlinks" href="#hl-0-8"&gt; 8&lt;/a&gt;
&lt;/span&gt;&lt;span class="lnt" id="hl-0-9"&gt;&lt;a class="lnlinks" href="#hl-0-9"&gt; 9&lt;/a&gt;
&lt;/span&gt;&lt;span class="lnt" id="hl-0-10"&gt;&lt;a class="lnlinks" href="#hl-0-10"&gt;10&lt;/a&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ ls -AGg 2.6.18
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;-rw-r--r-- 1 1593 Jan 25 23:25 1500_cvs-2007-1000.patch
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;-rw-r--r-- 1 797 Jan 25 23:25 4000_deprecate-sk98lin.patch
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;-rw-r--r-- 1 32192 Jan 25 23:25 4105_dm-bbr.patch
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;-rw-r--r-- 1 125781 Jan 25 23:25 4300_squashfs-3.1.patch
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;-rw-r--r-- 1 5710 Jan 25 23:25 4405_alpha-sysctl-uac.patch
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;-rw-r--r-- 1 864955 Jan 25 23:25 4450_grsec-2.1.9-2.6.18.6-200611100917.patch
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;-rw-r--r-- 1 910 Jan 25 23:25 4451_grsec-2.1.9-2.6.18.2-mute-warnings.patch
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;-rw-r--r-- 1 1034 Jan 25 23:25 4452_selinux-avc_audit-log-curr_ip-grsec.patch
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;-rw-r--r-- 1 2097 Jan 25 23:25 4453_pax_curr_ip-fixes.patch
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;So far all patches are applying fine and according to Alexander it even works on his workstation. But I&amp;rsquo;ll wait for Steve/Ned to get back to me telling me if this release works for them or not (as they had serious issues with their hardened desktops - something about the cursor being stuck in the corners).&lt;/p&gt;</description></item></channel></rss>