Gentoo Archives: gentoo-hardened

From: Matthew Thode <prometheanfire@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] missing the meeting
Date: Fri, 19 Dec 2014 06:54:57
Message-Id: 5493CC1D.7060906@gentoo.org
In Reply to: Re: [gentoo-hardened] missing the meeting by Sven Vermeulen
1 On 12/19/2014 12:02 AM, Sven Vermeulen wrote:
2 >
3 > On Dec 19, 2014 2:38 AM, "Matthew Thode" <prometheanfire@g.o
4 > <mailto:prometheanfire@g.o>> wrote:
5 >>
6 >> On 12/18/2014 07:09 PM, Anthony G. Basile wrote:
7 >> > 2) what to do about tar and POSIX capabilities in the context of
8 >> > building stage3's. Utilities like ping that used to be setuid to root
9 >> > are now just using posix caps. But preserving xattrs with tar is
10 >> > tricky. Since we dealt with this for the user.pax.* xattr namespace
11 >> > jmbsvicetto asked us to look at security.capability. However, the issue
12 >> > may now be mute because I just got a message from him that
13 >> >
14 >> > tar --xattrs --xattrs-include=security.capability
15 >> > --xattrs-include=user.* --acls -xjpvf
16 >> >
17 >> > works to get us all the xattr goodies we need for hardened and gentoo in
18 >> > general.
19 >> regarding 2: The thing we need to ask is if we want to ask users to run
20 >> that to extract stage3 tarballs, instead
21 >
22 > What xattrs are there in the tarball that we don't want our users to
23 > install?
24 >
25 > Wkr,
26 > Sven Vermeulen
27 >
28 not a question about trust, but one of added complexity :D
29
30 --
31 -- Matthew Thode (prometheanfire)