Ok thanks for these infos i will check it out When saying automatic i was referring to kernel updates in package repositories (with apt or dnf) where auto download and install can be configured for security updates...i was thinking about applying config options but i guess they are already compiled? Isnt there a tool that would download new kernel based on repository security updates and that would compile it with a provided config file? I can use a bash script or ansible role but i dont see how to keep close to the official kernel distribution updates automatically... Thanks 25 janv. 2023 23:21:15 Siddh Raman Pant <code@siddh.me>:
On Thu, 26 Jan 2023 at 03:25:08 +0530, A.Péré wrote:
Is there a distribution with automated tools to compile a kernel with custom config settings
Yes, it is your favourite distro, whichever that may be. You just need the tools to build, which you may already have, but can be seen in docs: https://www.kernel.org/doc/html/latest/process/changes.html
that ils easier and more accessible
If you want a GUI, use `make xconfig`.
un particular for automated updates with automatic custom compiling config?
Have your custom config options in a separate file somewhere, and use scripts/kconfig/merge_config.sh to merge. Example in a script:
make defconfig ./scripts/kconfig/merge_config.sh .config common.config
The script will take care of requisite stuff, which additional options to enable, etc.
Or you can have your entire config saved in .config, and just run merge_config.sh everytime you pull newer kernel code.
Thanks, Siddh
Please use plain text email and top-posting. Quoting Greg KH: A: http://en.wikipedia.org/wiki/Top_post Q: Were do I find info about this thing called top-posting? A: Because it messes up the order in which people normally read text. Q: Why is top-posting such a bad thing? A: Top-posting. Q: What is the most annoying thing in e-mail? A: No. Q: Should I include quotations after my reply? http://daringfireball.net/2007/07/on_top --------------------------------------------------------------------- On Thu, 26 Jan 2023 at 05:43:42 +0530, Aurel Pere wrote:
Ok thanks for these infos i will check it out
When saying automatic i was referring to kernel updates in package repositories (with apt or dnf) where auto download and install can be configured for security updates...i was thinking about applying config options but i guess they are already compiled?
Yes, those are already compiled. That's why the process is so quick!
Isnt there a tool that would download new kernel based on repository security updates and that would compile it with a provided config file?
I can use a bash script or ansible role but i dont see how to keep close to the official kernel distribution updates automatically...
Make a cron job to pull from the kernel repo automatically, either the stable kernel.org or Fedora's official repo. Then you can run the merge_config script, and then build the kernel. Then, you can run `update-grub` or whatever is the process. Unless for learning, why do this? Fedora maintainers do know their stuff, so you can trust them. You are not going to audit changes anyways, so this exercise is futile as you are basically doing the same thing as `sudo dnf update` (or whatever the dnf command is), but without the testing from maintainers and other people. Not to mention the Fedora specific quirks which won't be there upstream. Better to have your stuff up-to-date using dnf-automatic. https://docs.fedoraproject.org/en-US/quick-docs/securing-the-system-by-keepi... Thanks, Siddh
'Make a cron job to pull from the kernel repo automatically, either the stable kernel.org[http://kernel.org] or Fedora's official repo. Then you can run the merge_config script, and then build the kernel. Then, you can run `update-grub` or whatever is the process.'
I was hoping a security tool existed for that purpose. I will do with make then
'Unless for learning, why do this? Fedora maintainers do know their stuff, so you can trust them. You are not going to audit changes anyways, so this exercise is futile as you are basically doing the same thing as `sudo dnf update` (or whatever the dnf command is), but without the testing from maintainers and other people. Not to mention the Fedora specific quirks which won't be there upstream.'
I have chosen fedora for the relative pre built security guarantee it brings but i have reasons to believe the default quirks dont provide enough hardening for my situation. So I am now trying my best to follow and apply an official hardening guide and the kernel compiling is a part of it. For me this is a philosophical stake as much as a technical issue and an experiment: in 2023, can someone targeted who is only a geek be sovereign on a relatively trusted computer (ie relative free hardware from purism and free software)
participants (2)
-
aurel.pere@gmail.com -
Siddh Raman Pant