Gentoo Archives: gentoo-hardened

From: James Taylor <james@××××××××××.au>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more
Date: Fri, 19 Dec 2014 06:52:12
Message-Id: 5493CB0F.1080303@jtaylor.id.au
In Reply to: Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more by Karl-Johan Karlsson
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4
5 On 2014/12/19 17:08, Karl-Johan Karlsson wrote:
6 > On Thu 18 Dec 2014 19.58.11 Anthony G. Basile wrote:
7 >> On 12/13/14 18:52, Karl-Johan Karlsson wrote:
8 >>> So it works on ext4, but not ext3, even though both have the
9 ext_attr flag
10 >>> on disk. Any difference in kernel support?
11 >>
12 >> Because on ext3 you need to add user_xattr to the mount options. Either
13 >> `mount -o user_xattr` or in fstab in column 4 like this
14 >>
15 >> /dev/sdb5 /tmp ext3 user_xattr 0 1
16 >>
17 >> Its automatic on ext4. `man mount` for more info. Please let me know
18 >> if this works for you.
19 >
20 > Aha! I was unaware of that mount option. mount(8) documents it, but is
21 unclear
22 > on what the default value is. attr(5) says it's needed on ext2, ext3 and
23 > reiserfs, but says nothing about ext4.
24 >
25 > Unfortunately, the machine is in production, and since it works
26 without that
27 > option when using the ext4 code to read ext3, I would prefer to leave
28 it alone
29 > for now.
30 >
31 Would mount -oremount,user_xattr be an option? Or am I missing the point :)
32 -----BEGIN PGP SIGNATURE-----
33 Version: GnuPG v2
34
35 iQEcBAEBAgAGBQJUk8sJAAoJEHLy9B54fW4wGi8H/2eifOOUy8kkJAiUMALvOcUH
36 aPloeW0ck52Zh0ZZ9qiuXYHJm30E1tNR6ymIihNYY1P8Uiimghv5IbvroMiraTzo
37 bfjQEMXV/hcwNMsSTFLLNZWs2KDpIn36m/uJNjyUszZ5yUnrJVi4XrC7sMoiCcQb
38 DrK24IFLrSmgM5+w0IPe35olHFXlJwQrJT/F+IjrMZkfHuWfl/eWVBPPqYsohv48
39 OaxWWYO33S5M3Vqr1rtCTeWQ2A/+saThewX5aZTtjaA4n8ZIW2khQuidXeUz/2kU
40 /b8C9BN3ExtwUGHzmWV4W3dQVMdyGkfS/M0doF1TNo8IamfX2QPtKWc02siQ52k=
41 =7vr7
42 -----END PGP SIGNATURE-----

Replies

Subject Author
Re: [gentoo-hardened] XATTR_PAX, paxmark.sh, elog, icedtea, and maybe more "Anthony G. Basile" <basile@××××××××××××××.edu>