[gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more

2014-12-13 Thread Karl-Johan Karlsson
Hi list, I seem to have at least three problems related to PaX markings simultaneously, and since it's after midnight here and I need to write down some notes anyway so I know how to continue tomorrow, I might as well send them out to the world and see if someone else solves my problems for me

Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more

2014-12-13 Thread Rick "Zero_Chaos" Farina
On 12/13/2014 06:52 PM, Karl-Johan Karlsson wrote: > So it works on ext4, but not ext3, even though both have the ext_attr flag on > disk. Any difference in kernel support? > > > # uname -r > 3.16.5-hardened > > # gunzip -c /proc/config.gz | grep XATTR > CONFIG_EXT3_FS_XATTR=y > CONFIG_TMPFS_XA

Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more

2014-12-13 Thread Tóth Attila
I've made an observation long before, that although PT_PAX flags are properly handled on my systems, the installed binaries and libraries lack XATTR_PAX markings. This has been the situation for a long time now. I've made a script scanning the system for inconsistent markings and issuing paxctl-ng

Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more

2014-12-13 Thread Tóth Attila
+1 for omitting EXT3. Karl-Johan: you can safely remove that, IMHO. -- dr Tóth Attila, Radiológus, 06-20-825-8057 Attila Toth MD, Radiologist, +36-20-825-8057 2014.December 14.(V) 03:34 időpontban Rick \"Zero_Chaos\" Farina ezt írta: > On 12/13/2014 06:52 PM, Karl-Johan Karlsson wrote: >> So it w