Re: Help testing full end-to-end xattr support in portage
Luis Ressel <[email protected]>
| Newsgroups | gmane.linux.gentoo.hardened |
|---|---|
| Message-ID | <[email protected]> |
On Sat, 28 Jun 2014 07:47:26 -0400 "Anthony G. Basile" <[email protected]> wrote: > There are two advantages to paxctl over paxctl-ng from elfix: 1) It > doesn't depend on elfutils to do its manipulation of elf phdr's. 2) > It does try to convert or create a PT_PAX_FLAGS phdr by either > creating (-C) or converting (-c) a PT_GNU_STACK phdr. > > The advantage of paxctl-ng over paxctl is 1) it is designed to do > both PT_PAX and/or XATTR_PAX markings, 2) it is consciously designed > to not try to create/convert ELF phdr's. > > If we ever drop the PT_PAX_FLAGS patch from binutils then paxctl > would no longer be needed and paxctl-ng can be reduced to just doing > XATTR_PAX markings. > > One step at a time ;) Okay, that sounds reasonable. And as paxctl is a small program, it doesn't hurt to have it around on XATTR_PAX-only systems even though it's not needed. But there's still an issue. According to [1], 15 packages still depend on or invoke paxctl directly. One example is dev-lisp/sbcl, which needs pax markings at one point right in the middle of the build process and therefore can't use the pax eclass, at least not in a simple way. This doesn't work on systems like mine which don't respect PT_PAX flags. I'm currently working on a patch for sbcl (there are selinux-related issues as well), but please have a look at the other ebuilds. [1] $ echo /usr/portage/*/*/*.ebuild|xargs -n1000 grep -P 'paxctl(?!-ng)'|cut -d: -f1 Regards, Luis Ressel
signature.asc
(application/pgp-signature, 966 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.22 (GNU/Linux) iQJ8BAEBCgBmBQJTtAv/XxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRBMjU3MDBFQTc5QkYzMkY4NEQzMTFGNDlD NzE4OTFBNkEwRUZCN0U5AAoJEMcYkaag77fp8K0P/1Wb2Dw7YwXNzRKT4UVWCeL8 W9Z4HtIuwagxvmYV27Mm2b2vcFdm7Mf74RaZwHTdw2K4rY9OqeU42ZlLIn2USlFh ihaWevCgb0SOe3Czrwy72r7Da/WNc1bPePjV3KHGc1DMbmo3Pc54/Smquemo2LdZ ScNoo3QLyp1WOM3Oiaw/RDQ9gYKUCzvlOFAhq2Ev1VTejfZkVDiNAAXnHF7MGbGJ djjUmvXuWY1yBG9HKawm8mg4ifaEiaPzq0xe2F6lPEYQEl4u8ZcYZgihaSTuy69K HC/IyPJROwnBofVeuqrbrRZBPmVpORf54LZPlmB3yMahCIUzJ6i8cFY+9ku5zVoi gYrRyVZ0jNi4KnvOSmIzKbBy5DrAxttH3e9VEzqvZkXW7Yv9pNTOZ57UI/xDPjYN kqS6+cO2wub6+JPO2WLOTUqJC+BwzrRff91tTRmEbFEfBeLt70oejNCmgK/dabyn 1YzV8MNvzlbbTJHk0y9O2EK0doo9GcWcU9N0IDAqpBT4D+JdV6f1rEzjECfd2TDf ivOv6l4bLD2zFWnniGi+JMeda57PCh0+5TiTAhxmysWFd8yQER7OQ25q1Bb1dx2S 9p0UCZ5UUiD66q7R8pddh5GAGo9oJCUN9IgCNk0D7y5EYHiGQJvwRbJg0RbazAUJ FdwXsjIb9cq0RcjnA4F9 =8tgf -----END PGP SIGNATURE-----