Page 1 of 1

grsec and xfs

PostPosted: Wed Sep 03, 2003 11:31 am
by msi
Hello i'm trying to patch my linux 2.4.22 with grsecurity and xfs.
firstly i applied the xfs patch and after that the grsecurity patch.
in sysctl.c i have a problem: this is the .rej file:
Code: Select all
*** 272,280 ****
        {KERN_EXCEPTION_TRACE,"exception-trace",
         &exception_trace,sizeof(int),0644,NULL,&proc_dointvec},
  #endif
        {0}
  };

  static ctl_table vm_table[] = {
        {VM_BDFLUSH, "bdflush", &bdf_prm, 9*sizeof(int), 0644, NULL,
         &proc_dointvec_minmax, &sysctl_intvec, NULL,
--- 283,477 ----
        {KERN_EXCEPTION_TRACE,"exception-trace",
         &exception_trace,sizeof(int),0644,NULL,&proc_dointvec},
  #endif
+ #ifdef CONFIG_GRKERNSEC
+       {KERN_GRSECURITY, "grsecurity", NULL, 0, 0500, grsecurity_table},
+ #endif
        {0}
  };
....
but my sysctl.c file:
Code: Select all
        {KERN_EXCEPTION_TRACE,"exception-trace",
         &exception_trace,sizeof(int),0644,NULL,&proc_dointvec},
#endif
#ifdef  CONFIG_KDB
        {KERN_KDB, "kdb", &kdb_on, sizeof(int),
         0644, NULL, &proc_dointvec},
#endif  /* CONFIG_KDB */

        {0}
...


shall i put the grsecurity stuff after CONFIG_KDB or before it??
i heared that sysctl.c is hard coded, so do i need to adjust some assembly code too after the possition of the grsecurity stuff changed? (when i put the code after CONFIG_KDB)

PostPosted: Wed Sep 03, 2003 3:05 pm
by bse
sorry, cant help you on that one, but if you don't need the KDB skip it. Download the -split patch files. You only need

split-only (only adds new files)
split-kernel (only patches existing files)

The other files are optional. I patched my kernel with split-misc, split-acl and split-quota32, that works fine with grsec - no failed hunks.

Usually you don't need KDB and DMAPI.

[OT]
found that one looking for xfs features on sgi website, *lol*
http://verein.lst.de/~hch/talks/ukuug2003/mgp00005.html
[/OT]

PostPosted: Wed Sep 03, 2003 6:27 pm
by msi
ok thanks i'll try this.

PostPosted: Thu Sep 04, 2003 5:57 am
by Sleight of Mind
i'll post a -xfs-grsec patch for 2.4.22 later today or tomorrow. Check other thread for the URL.

PostPosted: Fri Sep 05, 2003 7:04 pm
by msi
fine, then i can compare my one with yours.
thank you!!