Re: Help testing full end-to-end xattr support in portage

Luis Ressel <[email protected]>
Newsgroups gmane.linux.gentoo.hardened
Message-ID <[email protected]>
On Sat, 28 Jun 2014 07:47:26 -0400
"Anthony G. Basile" <[email protected]> wrote:

> There are two advantages to paxctl over paxctl-ng from elfix: 1) It 
> doesn't depend on elfutils to do its manipulation of elf phdr's.  2)
> It does try to convert or create a PT_PAX_FLAGS phdr by either
> creating (-C) or converting (-c) a PT_GNU_STACK phdr.
> 
> The advantage of paxctl-ng over paxctl is 1) it is designed to do
> both PT_PAX and/or XATTR_PAX markings, 2) it is consciously designed
> to not try to create/convert ELF phdr's.
> 
> If we ever drop the PT_PAX_FLAGS patch from binutils then paxctl
> would no longer be needed and paxctl-ng can be reduced to just doing
> XATTR_PAX markings.
> 
> One step at a time ;)

Okay, that sounds reasonable. And as paxctl is a small program, it
doesn't hurt to have it around on XATTR_PAX-only systems even though
it's not needed.

But there's still an issue. According to [1], 15 packages still depend
on or invoke paxctl directly. One example is dev-lisp/sbcl, which needs
pax markings at one point right in the middle of the build process and
therefore can't use the pax eclass, at least not in a simple way. This
doesn't work on systems like mine which don't respect PT_PAX flags.

I'm currently working on a patch for sbcl (there are selinux-related
issues as well), but please have a look at the other ebuilds.

[1] $ echo /usr/portage/*/*/*.ebuild|xargs -n1000 grep -P 'paxctl(?!-ng)'|cut -d: -f1


Regards,
Luis Ressel
signature.asc (application/pgp-signature, 966 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)

iQJ8BAEBCgBmBQJTtAv/XxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRBMjU3MDBFQTc5QkYzMkY4NEQzMTFGNDlD
NzE4OTFBNkEwRUZCN0U5AAoJEMcYkaag77fp8K0P/1Wb2Dw7YwXNzRKT4UVWCeL8
W9Z4HtIuwagxvmYV27Mm2b2vcFdm7Mf74RaZwHTdw2K4rY9OqeU42ZlLIn2USlFh
ihaWevCgb0SOe3Czrwy72r7Da/WNc1bPePjV3KHGc1DMbmo3Pc54/Smquemo2LdZ
ScNoo3QLyp1WOM3Oiaw/RDQ9gYKUCzvlOFAhq2Ev1VTejfZkVDiNAAXnHF7MGbGJ
djjUmvXuWY1yBG9HKawm8mg4ifaEiaPzq0xe2F6lPEYQEl4u8ZcYZgihaSTuy69K
HC/IyPJROwnBofVeuqrbrRZBPmVpORf54LZPlmB3yMahCIUzJ6i8cFY+9ku5zVoi
gYrRyVZ0jNi4KnvOSmIzKbBy5DrAxttH3e9VEzqvZkXW7Yv9pNTOZ57UI/xDPjYN
kqS6+cO2wub6+JPO2WLOTUqJC+BwzrRff91tTRmEbFEfBeLt70oejNCmgK/dabyn
1YzV8MNvzlbbTJHk0y9O2EK0doo9GcWcU9N0IDAqpBT4D+JdV6f1rEzjECfd2TDf
ivOv6l4bLD2zFWnniGi+JMeda57PCh0+5TiTAhxmysWFd8yQER7OQ25q1Bb1dx2S
9p0UCZ5UUiD66q7R8pddh5GAGo9oJCUN9IgCNk0D7y5EYHiGQJvwRbJg0RbazAUJ
FdwXsjIb9cq0RcjnA4F9
=8tgf
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.