Re: request commit for 6.1 too // scsi: megaraid_sas: Add flexible array member for SGLs

2023-06-10 Thread Kees Cook
part from this call trace showing up - I don't see any weird things. >The /dev/disk/by-uuid/ thingie I wrote about in > >https://lkml.org/lkml/2023/6/9/1384 > >is nonsense ofcourse - because upon further thinking about what I wrote >it came apparent that the command I'm using does change/nullify the UUID >I am talking about. > >Thankyou! >Frank Reppin > > -- Kees Cook

Re: Debian 8/jessie - SECCOMP_FILTER_FLAG_TSYNC [PATH]

2015-03-09 Thread Kees Cook
-- Kees Cook@debian.org -- To UNSUBSCRIBE, email to debian-kernel-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org Archive: https://lists.debian.org/20150309182548.gb5...@outflux.net

Bug#712740: the default is fine

2013-06-19 Thread Kees Cook
owners don't want it enabled, they can choose to turn it off in /etc/sysctl.d/, just like other things. -Kees -- Kees Cook@debian.org -- To UNSUBSCRIBE, email to debian-kernel-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#679436: add drop_capabilities=... support, like kinit

2012-06-28 Thread Kees Cook
the system init starts. Thanks, -Kees -- Kees Cook@debian.org diff -Nru initramfs-tools-0.106/debian/changelog initramfs-tools-0.107~0kees1/debian/changelog --- initramfs-tools-0.106/debian/changelog 2012-06-07 05:40:53.0 -0700 +++ initramfs

Bug#676515: linux-2.6: AppArmor totally broken

2012-06-26 Thread Kees Cook
-not-mediate-kernel-bas.patch My preference would be to apply the networking patch, along with 0003 and 0004 posted here. -Kees -- Kees Cook -- To UNSUBSCRIBE, email to debian-kernel-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org Archive: http

Re: Linux kernel hardening - link restrictions

2012-03-01 Thread Kees Cook
did for the Lucid LTS release that was getting backported kernels (with link restrictions) built for it. -Kees [1] http://anonscm.debian.org/gitweb/?p=collab-maint/at.git;a=commitdiff;h=f4114656c3a6c6f6070e315ffdf940a49eda3279 -- Kees Cook@debian.org

Bug#605090: Updated patch

2011-02-09 Thread Kees Cook
(people are turning more to Debian as other distros move their minimum instruction set requirements higher and higher). -Kees -- Kees Cook@debian.org -- To UNSUBSCRIBE, email to debian-kernel-requ...@lists.debian.org with a subject of unsubscribe

Bug#605090: Updated patch

2011-01-26 Thread Kees Cook
of heavy-duty kernel hardening is with KERNEXEC and UDEREF. If someone is interested in speed, they can choose i386. But if someone wants a hardened kernel and amd64, they should have the option. I'd leave those on for both. -Kees -- Kees Cook@debian.org

Re: Minutes of the Debian linux-2.6 Group Meeting

2010-11-18 Thread Kees Cook
-emulation http://git.kernel.org/?p=linux/kernel/git/frob/linux-2.6-roland.git;a=shortlog;h=refs/heads/fedora/32bit-mmap-exec-randomization (this one is still missing one additional patch from me...) [2] https://wiki.ubuntu.com/SecurityTeam/Roadmap/KernelHardening#Upstream%20Hardening -- Kees

Re: Minutes of the Debian linux-2.6 Group Meeting

2010-11-18 Thread Kees Cook
Hi, On Thu, Nov 18, 2010 at 08:37:44PM +0100, Julien Cristau wrote: On Thu, Nov 18, 2010 at 11:23:39 -0800, Kees Cook wrote: On Thu, Nov 11, 2010 at 13:52:12 +, maximilian attems wrote: LSM: Enable AppArmor? as well as/instead of Tomoyo

Re: Minutes of the Debian linux-2.6 Group Meeting

2010-11-18 Thread Kees Cook
On Thu, Nov 18, 2010 at 08:06:50PM +, Ben Hutchings wrote: On Thu, Nov 18, 2010 at 12:03:33PM -0800, Kees Cook wrote: Now, don't get me wrong, I'd hugely prefer there be an __init-like way to handle this, and it actually touches on the constification work too. Still, blocking until

Re: Minutes of the Debian linux-2.6 Group Meeting

2010-11-18 Thread Kees Cook
On Thu, Nov 18, 2010 at 08:05:55PM +, Ben Hutchings wrote: On Thu, Nov 18, 2010 at 11:23:39AM -0800, Kees Cook wrote: Why? These patches are well maintained, and touch areas of the kernel that do not change much (making them very easy to merge). Why leave non-PAE x86 users out

Re: Paris MiniDebConf Minutes

2010-11-08 Thread Kees Cook
discardable. :) The agenda item wasn't asking for it to be the default LSM, just to be available at all. Thanks, -Kees -- Kees Cook@debian.org -- To UNSUBSCRIBE, email to debian-kernel-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Re: Paris MiniDebConf Minutes

2010-11-08 Thread Kees Cook
they made it non-modular, unfortunately. :( If a distro wants to make multiple LSMs available to their users, they have to compile them all in. Which is rather annoying. -Kees -- Kees Cook@debian.org -- To UNSUBSCRIBE, email to debian-kernel-requ

Re: item for kernel meeting -- NX emulation

2010-11-02 Thread Kees Cook
On Tue, Nov 02, 2010 at 04:04:13PM +0100, maximilian attems wrote: hello Kees, On Fri, 29 Oct 2010, Kees Cook wrote: Thanks for adding this to the agenda! I've added details about both AppArmor and the nx-emulation bits to the wiki page. Let me know if you've got any questions. Do

Re: item for kernel meeting -- NX emulation

2010-10-29 Thread Kees Cook
the userspace tools to experimental soon, since 2.6.36 is landing there now. Thanks, -Kees -- Kees Cook -- To UNSUBSCRIBE, email to debian-kernel-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/20101029155057.gb5

Bug#514938: alternatively...

2009-02-12 Thread Kees Cook
to forward once Ubuntu 9.04 releases. I have CC'd Luke Yelavich, who did the 0.92b merge. Luke, anything to forward to Debian for initramfs-tools that isn't Ubuntu-specific? Thanks! -Kees -- Kees Cook@debian.org -- To UNSUBSCRIBE, email to debian

Bug#514938: find/cpio exit codes ignored while building initramfs

2009-02-11 Thread Kees Cook
--dereference -o -H newc | gzip /tmp/archive.gz find: `/fail': No such file or directory $ echo $? 1 Also, I would recommend adding -e to the shell to catch single-command failures during execution, though that's out of scope for this particular bug. Thanks! -Kees -- Kees Cook

Bug#514938: alternatively...

2009-02-11 Thread Kees Cook
Attached is a gross alternative to depending on bash... -- Kees Cook@debian.org --- mkinitramfs~ 2009-02-11 17:18:41.0 -0800 +++ mkinitramfs 2009-02-11 20:13:16.0 -0800 @@ -296,7 +296,24 @@ fi [ ${verbose} = y ] echo Building cpio