Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more

2014-12-24 Thread PaX Team
On 18 Dec 2014 at 19:58, Anthony G. Basile wrote: > > So it works on ext4, but not ext3, even though both have the ext_attr flag > > on > > disk. Any difference in kernel support? > > > > Because on ext3 you need to add user_xattr to the mount options. Either > `mount -o user_xattr` or in fsta

Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more

2014-12-24 Thread PaX Team
On 14 Dec 2014 at 4:18, "Tóth Attila" wrote: > I've made an observation long before, that although PT_PAX flags are > properly handled on my systems, the installed binaries and libraries lack > XATTR_PAX markings. first, PaX flags don't matter on libraries at all as only the executable is used to

Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more

2014-12-24 Thread Tóth Attila
2014.December 24.(Sze) 11:38 időpontban PaX Team ezt írta: >> I have both PT and XT present in my make.conf for markings. I was told >> before, that I should rather opt for only one of the two possibilities - >> kernel-option wise and make.conf-marking-selection wise. Kinda both PT >> and >> XT are