Gentoo Archives: gentoo-hardened

From: Michael Orlitzky <michael@××××××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] XATTR_PAX migration
Date: Mon, 09 Sep 2013 17:56:52
Message-Id: 522E0BDF.2050000@orlitzky.com
In Reply to: Re: [gentoo-hardened] XATTR_PAX migration by "Anthony G. Basile"
1 On 09/09/2013 01:47 PM, Anthony G. Basile wrote:
2 >
3 > That was my mistake. When I dropped XT I forgot to update the comment.
4 > We tried XT right off the bat, but discovered a couple of problems: 1)
5 > install doesn't preserve xattr. we have a solution but it isn't working
6 > that well, and 2) there were lots of warning thrown for non hardened
7 > users which annoyed them. So we dropped to just PT.
8 >
9
10 What do you recommend then? Stick with PT_PAX until the install thing is
11 fixed, and then add PAX_MARKINGS=XT to make.conf?

Replies

Subject Author
Re: [gentoo-hardened] XATTR_PAX migration "Anthony G. Basile" <basile@××××××××××××××.edu>