1 |
Hi fellow hardened devs: |
2 |
|
3 |
I'm sorry for missing the meeting but things came up and the day got |
4 |
hectic. It is an important meeting because we were to discuss: |
5 |
|
6 |
1) what we want with toolchain.eclass - There is a move to get rid of |
7 |
the eclas because it is "messy". This is probably a bad thing in |
8 |
general and especially for hardened so we should discuss the pros and |
9 |
cons and what we want. |
10 |
|
11 |
2) what to do about tar and POSIX capabilities in the context of |
12 |
building stage3's. Utilities like ping that used to be setuid to root |
13 |
are now just using posix caps. But preserving xattrs with tar is |
14 |
tricky. Since we dealt with this for the user.pax.* xattr namespace |
15 |
jmbsvicetto asked us to look at security.capability. However, the issue |
16 |
may now be mute because I just got a message from him that |
17 |
|
18 |
tar --xattrs --xattrs-include=security.capability |
19 |
--xattrs-include=user.* --acls -xjpvf |
20 |
|
21 |
works to get us all the xattr goodies we need for hardened and gentoo in |
22 |
general. |
23 |
|
24 |
|
25 |
We should try to discuss 1 soon-ish before Cthulu awakens and madness |
26 |
reigns in gentoo. |
27 |
|
28 |
-- |
29 |
Anthony G. Basile, Ph. D. |
30 |
Chair of Information Technology |
31 |
D'Youville College |
32 |
Buffalo, NY 14201 |
33 |
(716) 829-8197 |