1 |
On Tue, 11 Jul 2006 18:42:53 +0200 |
2 |
kang <kang@g.o> wrote: |
3 |
|
4 |
> Kevin F. Quinn wrote: |
5 |
> > On Tue, 04 Jul 2006 18:34:25 +0200 |
6 |
> > pageexec@××××××××.hu wrote: |
7 |
> > |
8 |
> > |
9 |
> >> On 4 Jul 2006 at 16:19, Michael Decker wrote: |
10 |
> >> |
11 |
> >>> But I've detect that RSBAC and PAX manual are different, could be |
12 |
> >>> here an error? (showing only the differences here): |
13 |
> >>> http://www.gentoo.org/proj/en/hardened/rsbac/quickstart.xml |
14 |
> >>> |
15 |
> >>> --- SNIP --- |
16 |
> >>> PaX Control ---> |
17 |
> >>> [*] Support soft mode (Turn that option off on a production |
18 |
> >>> kernel) [ ] Use legacy ELF header marking |
19 |
> >>> [ ] Use ELF program header marking |
20 |
> >>> Use ELF program header marking MAC system integration |
21 |
> >>> (direct) ---> (X) direct |
22 |
> >>> |
23 |
> >> the problem is the MAC integration setting, for RSBAC you need |
24 |
> >> the 'hook' type (i added it explicitly per Amon's request ;-), |
25 |
> >> and the gentoo guide is wrong on this. the PaX guide suggests |
26 |
> >> 'none' because it's, well, a PaX-only guide hence there's no |
27 |
> >> MAC integration. |
28 |
> >> |
29 |
> > |
30 |
> > Documentation fixed :) |
31 |
> > |
32 |
> > |
33 |
> Sorry for the late reply, but actually RSBAC works with both direct |
34 |
> and hook. At the time of writting the doc, the author priviligied |
35 |
> "direct" and still does AFAIK. Although both seems to work equally |
36 |
> well. |
37 |
> |
38 |
> See http://www.rsbac.org/pipermail/rsbac/2006-July/001869.html |
39 |
|
40 |
So the issue remains open as to why compilation failed when the |
41 |
reporter chose "direct". |
42 |
|
43 |
-- |
44 |
Kevin F. Quinn |