--- grsecurity-2.1.13-2.6.28.10-omap1.patch	2010-03-07 00:28:29.000000000 +0100
+++ grsecurity-2.1.13-2.6.28.8-200903191958.patch	2009-03-20 00:59:23.000000000 +0100
@@ -34707,6 +34707,15 @@
  		if (locked > limit && !capable(CAP_IPC_LOCK))
  			return -ENOMEM;
  	}
+@@ -1580,7 +1789,7 @@ static int acct_stack_growth(struct vm_a
+ 	 * Overcommit..  This must be the final test, as it will
+ 	 * update security statistics.
+ 	 */
+-	if (security_vm_enough_memory(grow))
++	if (security_vm_enough_memory_mm(mm, grow))
+ 		return -ENOMEM;
+ 
+ 	/* Ok, everything looks good - let it rip */
 @@ -1601,35 +1810,40 @@ static
  #endif
  int expand_upwards(struct vm_area_struct *vma, unsigned long address)
@@ -36145,12 +36154,11 @@
 diff -urNp linux-2.6.28.8/net/ipv4/netfilter/Makefile linux-2.6.28.8/net/ipv4/netfilter/Makefile
 --- linux-2.6.28.8/net/ipv4/netfilter/Makefile	2009-02-06 16:47:45.000000000 -0500
 +++ linux-2.6.28.8/net/ipv4/netfilter/Makefile	2009-02-21 09:37:50.000000000 -0500
-@@ -61,7 +61,8 @@ obj-$(CONFIG_IP_NF_TARGET_MASQUERADE) +=
+@@ -61,6 +61,7 @@ obj-$(CONFIG_IP_NF_TARGET_MASQUERADE) +=
  obj-$(CONFIG_IP_NF_TARGET_NETMAP) += ipt_NETMAP.o
  obj-$(CONFIG_IP_NF_TARGET_REDIRECT) += ipt_REDIRECT.o
  obj-$(CONFIG_IP_NF_TARGET_REJECT) += ipt_REJECT.o
 +obj-$(CONFIG_IP_NF_MATCH_STEALTH) += ipt_stealth.o
- obj-$(CONFIG_IP_NF_TARGET_IDLETIMER) += ipt_IDLETIMER.o
  obj-$(CONFIG_IP_NF_TARGET_TTL) += ipt_TTL.o
  obj-$(CONFIG_IP_NF_TARGET_ULOG) += ipt_ULOG.o
  
