Gentoo Archives: gentoo-dev

From: Mike Frysinger <vapier@g.o>
To: gentoo-dev@l.g.o
Cc: Matthew Thode <prometheanfire@g.o>
Subject: Re: [gentoo-dev] New global use-flag [pax_kernel]
Date: Tue, 27 Nov 2012 23:26:00
Message-Id: 201211271826.14011.vapier@gentoo.org
In Reply to: [gentoo-dev] New global use-flag [pax_kernel] by Matthew Thode
1 On Sunday 25 November 2012 18:57:12 Matthew Thode wrote:
2 > pax_kernel is used by 21 packages. The description would generally be
3 > 'make changes to the package so it works under a pax enabled kernel'.
4 > Currently it is used to either patch or (inclusive) to pax mark.
5 >
6 > What think you?
7
8 `paxctl` should be run if it exists, and a hardened profile should list that in
9 its @system imo. that cuts out quite a number of users.
10
11 as for patches applied to the source, i can't say w/out reading the actual
12 patches if there's a better way (keying off defines, or runtime detection based
13 on errno which we've done in glibc).
14 -mike

Attachments

File name MIME type
signature.asc application/pgp-signature