1 |
On Dec 19, 2014 2:38 AM, "Matthew Thode" <prometheanfire@g.o> wrote: |
2 |
> |
3 |
> On 12/18/2014 07:09 PM, Anthony G. Basile wrote: |
4 |
> > 2) what to do about tar and POSIX capabilities in the context of |
5 |
> > building stage3's. Utilities like ping that used to be setuid to root |
6 |
> > are now just using posix caps. But preserving xattrs with tar is |
7 |
> > tricky. Since we dealt with this for the user.pax.* xattr namespace |
8 |
> > jmbsvicetto asked us to look at security.capability. However, the issue |
9 |
> > may now be mute because I just got a message from him that |
10 |
> > |
11 |
> > tar --xattrs --xattrs-include=security.capability |
12 |
> > --xattrs-include=user.* --acls -xjpvf |
13 |
> > |
14 |
> > works to get us all the xattr goodies we need for hardened and gentoo in |
15 |
> > general. |
16 |
> regarding 2: The thing we need to ask is if we want to ask users to run |
17 |
> that to extract stage3 tarballs, instead |
18 |
|
19 |
What xattrs are there in the tarball that we don't want our users to |
20 |
install? |
21 |
|
22 |
Wkr, |
23 |
Sven Vermeulen |