Gentoo Archives: gentoo-hardened

From: Matthew Summers <msummers42@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] mprotect question
Date: Thu, 14 Jul 2011 22:08:50
Message-Id: CADhbkgn_udR5aJfQauDk8-g0VnLfNVxFemSUURJrx=r9EXnuDw@mail.gmail.com
In Reply to: Re: [gentoo-hardened] mprotect question by "Anthony G. Basile"
1 On Thu, Jul 14, 2011 at 8:41 AM, Anthony G. Basile <blueness@g.o> wrote:
2 > Hi Markus,
3 >
4 > It looks like you missed something in the process.  The steps to
5 > converting are (skipping details):
6 >
7 > 1) switch profile
8 > 2) recompile the toolchain: emerge glibc gcc binutils
9 > 3) recompile system: emerge -e system
10 > 4) recompile world: emerge -e world
11 >
12 > If you didn't do these, its possible you have some  binaries left that
13 > will trigger pax violations.
14
15 <snip>
16
17 > --
18 > Anthony G. Basile, Ph.D.
19 > Gentoo Linux Developer [Hardened]
20 > E-Mail    : blueness@g.o
21 > GnuPG FP  : 8040 5A4D 8709 21B1 1A88  33CE 979C AF40 D045 5535
22 > GnuPG ID  : D0455535
23
24 I might add a step in there after #2, lets call it step "2+to-be-sure"
25 check the output of gcc-config -l and select the hardened gcc if its
26 not been selected already. Its been a long time since I did a non- to
27 a hardened system conversion, so I am uncertain whether this is in
28 fact necessary. In any case it cannot hurt anything to simply check
29 the situation out.
30
31 --
32 M. Summers
33
34 "...there are no rules here -- we're trying to accomplish something."
35   - Thomas A. Edison