Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update grsecurity kernels for workstation templates #546

Closed
7 tasks done
emkll opened this issue May 6, 2020 · 8 comments
Closed
7 tasks done

Update grsecurity kernels for workstation templates #546

emkll opened this issue May 6, 2020 · 8 comments

Comments

@emkll
Copy link
Contributor

emkll commented May 6, 2020

We are currently 4.14.169 kernels on the workstation (as of today, 4.14.179 has been released), we should consider upgrading these as part of a regular schedule. There have not been any major vulnerabilities and we do we the grsecurity patchset for additional hardening.

Checklist (based on #546 (comment))

@redshiftzero redshiftzero added this to Nominated for next sprint in SecureDrop Team Board May 6, 2020
@zenmonkeykstop
Copy link
Contributor

Plan to move to 4.14.179 or get in sync with core (4.14.175)?

@emkll
Copy link
Contributor Author

emkll commented May 6, 2020

The current build logic does not make it easy to build historical versions, we should target whatever the latest version is at the time we build the kernels (currently 4.14.179)

@eloquence eloquence moved this from Nominated for next sprint to Sprint #50 - 5/6-5/20 in SecureDrop Team Board May 6, 2020
@eloquence
Copy link
Member

For the 5/20-6/3 sprint, we're aiming to build a workstation kernel and get an LFS PR up (not merged), but our priority is a smooth 0.3.0 release including the fedora-30->31 transition (#544).

@zenmonkeykstop
Copy link
Contributor

PRs required to unlock testing have been submitted as follows:

Some preliminary testing has been done against the kernel by manually installing it in securedrop-workstation-buster and reprovisioning the workstation. Outstanding tasks before the LFS PR can be issued include:

  • More testing, including apt upgrade scenarios
  • Uploading the source offer tarball to S3 (I need to verify/acquire credentials or delegate this)

(Have updated docs while going through the process.)

@zenmonkeykstop
Copy link
Contributor

There's been a relevant CVE and grsec patch while these PRs were in the queue, so they will be closed and replaced with a new kernel build soon.

@zenmonkeykstop
Copy link
Contributor

zenmonkeykstop commented Jul 1, 2020

A new set of PRs required to unlock testing for the 4.14.186 kernel have been submitted as follows:

Some preliminary testing has been done against the kernel by manually installing it in securedrop-workstation-buster and reprovisioning the workstation. Outstanding tasks before the LFS PR can be issued include:

  • More testing, including apt upgrade scenarios
  • Uploading the source offer tarball to S3

@eloquence eloquence added this to Ready for Review in SecureDrop Team Board Jul 1, 2020
@eloquence
Copy link
Member

(In light of the number of PRs involved and the need for coordinated review, tracking the issue rather than the individual PRs on the board.)

@eloquence
Copy link
Member

This was completed, and the new kernel has been released to all workstation users, see https://apt.freedom.press/pool/main/s/securedrop-workstation-grsec/

SecureDrop Team Board automation moved this from Under Review to Done Jul 13, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
No open projects
Development

No branches or pull requests

3 participants