Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] nvidia.ko with Grsecurity & PaX kernel
Date: Sun, 22 Sep 2013 14:19:47
Message-Id: 1d422d427a1e4c380720eec4c5fac427.squirrel@atoth.sote.hu
In Reply to: Re: [gentoo-hardened] nvidia.ko with Grsecurity & PaX kernel by Hinnerk van Bruinehsen
1 2013.Szeptember 21.(Szo) 20:01 időpontban Hinnerk van Bruinehsen ezt írta:
2 > On Sat, Sep 21, 2013 at 07:55:40PM +0300, Balint Szente wrote:
3 >>
4 >> pypaxctl itself works, but I found the way to reproduce the issue:
5 >>
6 >> Step 2. is the trigger for the problem. If I don't delete the XT_ATTR
7 >> PAX flags from the GL library, then the revdep-pax script works well.
8 >>
9 >> So as a conclusion, I think the issue appears when the library has only
10 >> PT marks.
11 >>
12 > Why would you remove XT-pax flags anyways? It's just xattr (shouldn't
13 > cause
14 > much overhead) and since PT-pax is going to be deprecated (iirc soon), you
15 > have
16 > a backup with the XT-pax flags (so you don't have breakage when the
17 > switch
18 > occurs).
19 >
20 >
21 > WKR
22 > Hinnerk
23 >
24
25 Dear Hinnerk,
26
27 I have both PT and XT support compiled into my kernel and I have both PT
28 and XT PAX flags defined in my make.conf. Using the latest hardened
29 overlay, it installs binaries with PT marking only. So the installed
30 binary is just like what Balint produced by erasing the XT attributes.
31 Now if I run revdep-pax, the situation remains the same.
32 Actually I've already put together some commands to look for XT-less
33 binaries and paxctl-ng them properly.
34
35 The issue is probably related to the fact, that previously an install
36 wrapper in portage turned out to slow down things significantly, so it was
37 removed. GNU install won't preserve XT pax markings. It was told on this
38 mailing list, that an updated solution will come, which makes install
39 preserve XT attributes for PAX.
40
41 We can expect more to come regarding XT support in the future and help
42 testing it.
43
44 Regards:
45 Dw.
46 --
47 dr Tóth Attila, Radiológus, 06-20-825-8057
48 Attila Toth MD, Radiologist, +36-20-825-8057