ALT Linux Team development discussions
 help / color / mirror / Atom feed
* [devel] [Linux 2.4.21-ow1, msulogin, Owl updates]
@ 2003-06-17  8:38 Dmitry V. Levin
    0 siblings, 1 reply; 3+ messages in thread
From: Dmitry V. Levin @ 2003-06-17  8:38 UTC (permalink / raw)
  To: ALT Devel discussion list

[-- Attachment #1: Type: text/plain, Size: 3336 bytes --]

FYI

----- Forwarded message from Solar Designer <solar@> -----

Date: Tue, 17 Jun 2003 07:40:29 +0400
From: Solar Designer <solar@>
To: announce@lists.openwall.com
Cc: lwn@lwn.net
Subject: Linux 2.4.21-ow1, msulogin, Owl updates

Hi,

This is a cumulative announcement for several updates which have
occurred in the last three months.  I'll start with the latest.

Linux 2.4.21-ow1 is out and available for download at the usual
location:

	http://www.openwall.com/linux/

Linux 2.4.21 (and thus 2.4.21-ow1) adds numerous security fixes,
including to the kmod/ptrace race previously fixed in 2.2.25 and many
2.4.x-specific vulnerabilities (ioperm(2) allowing unauthorized direct
access to certain I/O ports, O_DIRECT information leaks, excessive CPU
consumption with networking, and more).

Linux 2.4.21-ow1, compared to previous versions of the patch for Linux
2.4.x, corrects the RLIMIT_NPROC enforcement to not apply to
privileged processes and to work also for 32-bit syscall emulation on
sparc64, ppc64, mips64, s390x, and 64-bit parisc, thanks to the report
from Brad Spengler.  It also has a harmless user-triggerable Oops
(kernel mode fault) in the GPF handler on x86/SMP fixed, thanks to the
PaX team.

Owl-current now fully supports Linux 2.4.x as well as 2.2.x, although
only 2.2.x is included and it's still the preferred choice.  This
means that not only will Owl run with a 2.4.x kernel (Owl 1.0 release
supported that already), but its userland may be fully rebuilt from
source ("make buildworld") with Linux 2.4.x kernel headers.

Another recent release is msulogin, a single user mode login program
which adds support for having multiple root accounts on a system.
It's a part of Owl-current but is also made available separately:

	http://www.openwall.com/msulogin/

More importantly, Owl-current now defaults to tcb, our alternative and
better password shadowing scheme.  This was already supported in Owl
1.0, but not made the default until recently.  Updating existing Owl
installs to Owl-current or the upcoming release results in automatic
conversion from /etc/shadow to tcb.  It is still possible to maintain
an Owl system with /etc/shadow should you require this level of
backwards compatibility, -- automatic conversion to tcb won't be
performed on updates if a system has been explicitly unconverted from
tcb.  Just to remind, our tcb suite is also available separately from
Owl primarily for re-use by other distributions:

	http://www.openwall.com/tcb/

Other recent changes to Owl-current include the addition of CVS and
Nmap packages (both with our modifications), replacing console-tools
with kbd, updates to Mutt 1.4.1i, mktemp 1.5, OpenSSH 3.6.1p2, OpenSSL
0.9.6j, util-linux 2.11z, xinetd 2.3.11, SysVinit 2.85, GnuPG 1.2.2,
lftp 2.6.6, and stmpclean 0.3.  We've imported many improvements from
ALT Linux, including libpam_userpass, much better command line parsing
in su(1), and various fixes and improvements to start-stop-daemon and
wall(1).  pam_tcb now implements proper fake salt creation for
non-existent or password-less accounts to reduce timing leaks, and our
login services know to make use of that functionality.

For a more complete and verbose list of Owl-current changes, please
refer to:

	http://www.openwall.com/Owl/CHANGES-current.shtml

----- End forwarded message -----


--
ldv

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [devel] [Linux 2.4.21-ow1, msulogin, Owl updates]
  @ 2003-06-17 10:10   ` aen
  2003-06-17 13:58     ` Albert R. Valiev
  0 siblings, 1 reply; 3+ messages in thread
From: aen @ 2003-06-17 10:10 UTC (permalink / raw)
  To: ALT Devel discussion list

Albert R. Valiev пишет:

>В сообщении от 17 Июнь 2003 08:38 Dmitry V. Levin написал:
>
>Ух ты )) собираю этот патч в сизиф безоговорочног.
>2 Nidd:
>Залью сегодня исправленные варианты. Одновременно попробую сразу 
>прикрутить этот патч
>  
>
>  
>
Только проверьте, будет ли с ним работать Wine и Win4Lin.

Rgrds, Алексей


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [devel] [Linux 2.4.21-ow1, msulogin, Owl updates]
  2003-06-17 10:10   ` aen
@ 2003-06-17 13:58     ` Albert R. Valiev
  0 siblings, 0 replies; 3+ messages in thread
From: Albert R. Valiev @ 2003-06-17 13:58 UTC (permalink / raw)
  To: ALT Devel discussion list

[-- Attachment #1: signed data --]
[-- Type: text/plain, Size: 562 bytes --]

В сообщении от 17 Июнь 2003 10:10 aen написал:
> Albert R. Valiev пишет:
> >В сообщении от 17 Июнь 2003 08:38 Dmitry V. Levin написал:
> >
> >Ух ты )) собираю этот патч в сизиф безоговорочног.
> >2 Nidd:
> >Залью сегодня исправленные варианты. Одновременно попробую
> > сразу прикрутить этот патч
>
> Только проверьте, будет ли с ним работать Wine и Win4Lin.

ok

P.S.

еще залью патч для поддержкт ntfs (новую версию).


-- 

With Best Regards, Albert R. Valiev
------------------------------------
ALT Linux Team [www.altlinux.ru]
ARV-DARKSTAR-RIPN, ARV2-RIPE

[-- Attachment #2: signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2003-06-17 13:58 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2003-06-17  8:38 [devel] [Linux 2.4.21-ow1, msulogin, Owl updates] Dmitry V. Levin
2003-06-17 10:10   ` aen
2003-06-17 13:58     ` Albert R. Valiev

ALT Linux Team development discussions

This inbox may be cloned and mirrored by anyone:

	git clone --mirror http://lore.altlinux.org/devel/0 devel/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 devel devel/ http://lore.altlinux.org/devel \
		devel@altlinux.org devel@altlinux.ru devel@lists.altlinux.org devel@lists.altlinux.ru devel@linux.iplabs.ru mandrake-russian@linuxteam.iplabs.ru sisyphus@linuxteam.iplabs.ru
	public-inbox-index devel

Example config snippet for mirrors.
Newsgroup available over NNTP:
	nntp://lore.altlinux.org/org.altlinux.lists.devel


AGPL code for this site: git clone https://public-inbox.org/public-inbox.git