2013-09-03 00:59:47 +00:00
|
|
|
# Copyright 1999-2013 Gentoo Foundation
|
2012-10-02 08:08:41 +00:00
|
|
|
# Distributed under the terms of the GNU General Public License v2
|
2013-09-03 00:59:47 +00:00
|
|
|
# $Header: /var/cvsroot/gentoo-x86/sys-kernel/hardened-sources/hardened-sources-3.9.9.ebuild,v 1.2 2013/07/28 19:34:15 blueness Exp $
|
2012-10-02 08:08:41 +00:00
|
|
|
|
2013-09-03 00:59:47 +00:00
|
|
|
EAPI="5"
|
2012-10-02 08:08:41 +00:00
|
|
|
|
|
|
|
ETYPE="sources"
|
2013-09-03 00:59:47 +00:00
|
|
|
K_WANT_GENPATCHES="base"
|
|
|
|
K_GENPATCHES_VER="14"
|
2012-10-02 08:08:41 +00:00
|
|
|
K_DEBLOB_AVAILABLE="1"
|
|
|
|
|
|
|
|
inherit kernel-2
|
|
|
|
detect_version
|
|
|
|
|
2013-09-03 00:59:47 +00:00
|
|
|
HGPV="${KV_MAJOR}.${KV_MINOR}.${KV_PATCH}-1"
|
2012-10-02 08:08:41 +00:00
|
|
|
HGPV_URI="http://dev.gentoo.org/~blueness/hardened-sources/hardened-patches/hardened-patches-${HGPV}.extras.tar.bz2"
|
|
|
|
SRC_URI="${KERNEL_URI} ${HGPV_URI} ${GENPATCHES_URI} ${ARCH_URI}"
|
|
|
|
|
|
|
|
UNIPATCH_LIST="${DISTDIR}/hardened-patches-${HGPV}.extras.tar.bz2"
|
2013-09-03 00:59:47 +00:00
|
|
|
UNIPATCH_EXCLUDE="
|
|
|
|
1500_XATTR_USER_PREFIX.patch
|
|
|
|
1510_af_key-fix-info-leaks-in-notify-messages.patch
|
|
|
|
1511_ipv6-ip6_sk_dst_check-must-not-assume-ipv6-dst.patch
|
|
|
|
2900_dev-root-proc-mount-fix.patch"
|
2012-10-02 08:08:41 +00:00
|
|
|
|
|
|
|
DESCRIPTION="Hardened kernel sources (kernel series ${KV_MAJOR}.${KV_MINOR})"
|
|
|
|
HOMEPAGE="http://www.gentoo.org/proj/en/hardened/"
|
|
|
|
IUSE="deblob -injection"
|
|
|
|
|
|
|
|
KEYWORDS="~alpha amd64 ~arm ~hppa ~ia64 ~ppc ~ppc64 ~sparc x86"
|
|
|
|
|
|
|
|
RDEPEND=">=sys-devel/gcc-4.5"
|
|
|
|
|
|
|
|
pkg_setup() {
|
|
|
|
if use injection; then
|
|
|
|
UNIPATCH_LIST+=" ${FILESDIR}/wireless_injection.patch"
|
|
|
|
fi
|
|
|
|
}
|
|
|
|
|
|
|
|
pkg_postinst() {
|
|
|
|
kernel-2_pkg_postinst
|
|
|
|
|
|
|
|
local GRADM_COMPAT="sys-apps/gradm-2.9.1*"
|
|
|
|
|
|
|
|
ewarn
|
|
|
|
ewarn "Users of grsecurity's RBAC system must ensure they are using"
|
|
|
|
ewarn "${GRADM_COMPAT}, which is compatible with ${PF}."
|
|
|
|
ewarn "It is strongly recommended that the following command is issued"
|
|
|
|
ewarn "prior to booting a ${PF} kernel for the first time:"
|
|
|
|
ewarn
|
|
|
|
ewarn "emerge -na =${GRADM_COMPAT}"
|
|
|
|
ewarn
|
|
|
|
}
|