Gentoo Archives: gentoo-hardened

From: "Kevin F. Quinn" <kevquinn@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] RSBAC / PaX -> Compiling error
Date: Tue, 11 Jul 2006 18:06:47
Message-Id: 20060711200311.5d1f2c00@c1358217.kevquinn.com
In Reply to: Re: [gentoo-hardened] RSBAC / PaX -> Compiling error by kang
1 On Tue, 11 Jul 2006 18:42:53 +0200
2 kang <kang@g.o> wrote:
3
4 > Kevin F. Quinn wrote:
5 > > On Tue, 04 Jul 2006 18:34:25 +0200
6 > > pageexec@××××××××.hu wrote:
7 > >
8 > >
9 > >> On 4 Jul 2006 at 16:19, Michael Decker wrote:
10 > >>
11 > >>> But I've detect that RSBAC and PAX manual are different, could be
12 > >>> here an error? (showing only the differences here):
13 > >>> http://www.gentoo.org/proj/en/hardened/rsbac/quickstart.xml
14 > >>>
15 > >>> --- SNIP ---
16 > >>> PaX Control --->
17 > >>> [*] Support soft mode (Turn that option off on a production
18 > >>> kernel) [ ] Use legacy ELF header marking
19 > >>> [ ] Use ELF program header marking
20 > >>> Use ELF program header marking MAC system integration
21 > >>> (direct) ---> (X) direct
22 > >>>
23 > >> the problem is the MAC integration setting, for RSBAC you need
24 > >> the 'hook' type (i added it explicitly per Amon's request ;-),
25 > >> and the gentoo guide is wrong on this. the PaX guide suggests
26 > >> 'none' because it's, well, a PaX-only guide hence there's no
27 > >> MAC integration.
28 > >>
29 > >
30 > > Documentation fixed :)
31 > >
32 > >
33 > Sorry for the late reply, but actually RSBAC works with both direct
34 > and hook. At the time of writting the doc, the author priviligied
35 > "direct" and still does AFAIK. Although both seems to work equally
36 > well.
37 >
38 > See http://www.rsbac.org/pipermail/rsbac/2006-July/001869.html
39
40 So the issue remains open as to why compilation failed when the
41 reporter chose "direct".
42
43 --
44 Kevin F. Quinn

Attachments

File name MIME type
signature.asc application/pgp-signature