Gentoo Archives: gentoo-hardened

From: "Javier Juan Martínez Cabezón" <tazok.id0@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] rsbac-sources and PaX
Date: Sun, 02 Dec 2012 09:03:08
Message-Id: 50BB14A5.2020308@gmail.com
In Reply to: Re: [gentoo-hardened] rsbac-sources and PaX by "Anthony G. Basile"
1 On 01/12/12 21:37, Anthony G. Basile wrote:
2 > On 11/22/2012 12:49 PM, Javier Juan Martínez Cabezón wrote:
3 >>
4 >>
5 >> Hi all, I saw that in the last ebuild (3.4.1), PaX is in
6 >> UNIPATCH_EXCLUDE. What have you Planned about this?.
7 >>
8 >> I also knew the existence of a base rsbac_policy based hardened gentoo
9 >> subproject? is there anything written about it?
10 >>
11 >> Thanks for all.
12 >>
13 >
14 > When last I tried to apply the pax patches on top of rsbac, they did not
15 > go. People kept saying the did, but they did not without hacking. If
16 > you want to provide me with an rsbac patchset and pax patchset that are
17 > compat I will try again.
18 >
19 >
20
21 Hi Anthony, thanks for your reply. I think that there are no one PaX
22 version compatible with rsbac patch by default without patching at hand.
23 They are always rejections in mm.c and some others, and always in the
24 same places and it seems it will not change in the future.
25
26 This is really tricky because to solve it I don't always know if I'm
27 doing things in a correct way.