Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <sven.vermeulen@××××××.be>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] missing the meeting
Date: Fri, 19 Dec 2014 06:02:18
Message-Id: CAPzO=NyuDvUAW1m72GxFFL+Pj9nTyrhisrvhDUA+ykQDt4HeLQ@mail.gmail.com
In Reply to: Re: [gentoo-hardened] missing the meeting by Matthew Thode
1 On Dec 19, 2014 2:38 AM, "Matthew Thode" <prometheanfire@g.o> wrote:
2 >
3 > On 12/18/2014 07:09 PM, Anthony G. Basile wrote:
4 > > 2) what to do about tar and POSIX capabilities in the context of
5 > > building stage3's. Utilities like ping that used to be setuid to root
6 > > are now just using posix caps. But preserving xattrs with tar is
7 > > tricky. Since we dealt with this for the user.pax.* xattr namespace
8 > > jmbsvicetto asked us to look at security.capability. However, the issue
9 > > may now be mute because I just got a message from him that
10 > >
11 > > tar --xattrs --xattrs-include=security.capability
12 > > --xattrs-include=user.* --acls -xjpvf
13 > >
14 > > works to get us all the xattr goodies we need for hardened and gentoo in
15 > > general.
16 > regarding 2: The thing we need to ask is if we want to ask users to run
17 > that to extract stage3 tarballs, instead
18
19 What xattrs are there in the tarball that we don't want our users to
20 install?
21
22 Wkr,
23 Sven Vermeulen

Replies

Subject Author
Re: [gentoo-hardened] missing the meeting Matthew Thode <prometheanfire@g.o>