-
Notifications
You must be signed in to change notification settings - Fork 46
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Test experimental securedrop-workstation (w/ grsec) template on Buster #308
Test experimental securedrop-workstation (w/ grsec) template on Buster #308
Comments
Attempted a quick-and-dirty evaluation by running a |
This bug has already been reported/tracked upstream in QubesOS/qubes-issues#5212 (comment) |
Update: The default debian-provided kernel now works in HVM mode on Debian 10, both on a dist-upgraded debian-9 template, but also the qubes-hosted template [1]
Unfortunately, installing the currently hosted 4.14.128 debs for linux-headers and linux-image, and setting those as default kernel in grub2 config via Now trying to build a newer kernel, if that fails will look more closely at the upstream kernel configs. |
Thanks for the update @emkll ! Our remaining sprint commitment for 10/23-11/6 is still accurately described in the top-level comment, but just noting for the record that we've also agreed to:
Our goal here is to allow developers to create new Buster VMs using a grsec kernel, not to immediately override the default for all existing SDW VMs. |
Lifting proc restrictions for GID1000 (user group) instead of 900 (qubes group), which was introduced in freedomofpress/ansible-role-grsecurity-build@55998eb resolves the issue. Because 4.14 < 4.19 (the default Buster kernel series), we must set the following option in Building an HVM qube with the modifications described above will result in a functional HVM Qube running a grsecurity kernel.
|
In preparation of the transition to Debian Buster for all Debian-based templates used by the workstation (#306), we want to create an experimental version of the securedrop-workstation template based on Debian Buster, w/ grsec enabled, in order to:
This can be done in an experimental branch or otherwise in such a manner as to not impact the ordinary course of development.
The text was updated successfully, but these errors were encountered: