1 |
On 12/19/2014 12:02 AM, Sven Vermeulen wrote: |
2 |
> |
3 |
> On Dec 19, 2014 2:38 AM, "Matthew Thode" <prometheanfire@g.o |
4 |
> <mailto:prometheanfire@g.o>> wrote: |
5 |
>> |
6 |
>> On 12/18/2014 07:09 PM, Anthony G. Basile wrote: |
7 |
>> > 2) what to do about tar and POSIX capabilities in the context of |
8 |
>> > building stage3's. Utilities like ping that used to be setuid to root |
9 |
>> > are now just using posix caps. But preserving xattrs with tar is |
10 |
>> > tricky. Since we dealt with this for the user.pax.* xattr namespace |
11 |
>> > jmbsvicetto asked us to look at security.capability. However, the issue |
12 |
>> > may now be mute because I just got a message from him that |
13 |
>> > |
14 |
>> > tar --xattrs --xattrs-include=security.capability |
15 |
>> > --xattrs-include=user.* --acls -xjpvf |
16 |
>> > |
17 |
>> > works to get us all the xattr goodies we need for hardened and gentoo in |
18 |
>> > general. |
19 |
>> regarding 2: The thing we need to ask is if we want to ask users to run |
20 |
>> that to extract stage3 tarballs, instead |
21 |
> |
22 |
> What xattrs are there in the tarball that we don't want our users to |
23 |
> install? |
24 |
> |
25 |
> Wkr, |
26 |
> Sven Vermeulen |
27 |
> |
28 |
not a question about trust, but one of added complexity :D |
29 |
|
30 |
-- |
31 |
-- Matthew Thode (prometheanfire) |