Gentoo Archives: gentoo-hardened

From: Christian Apeltauer <c.apeltauer@×××.de>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] hardened-sources & tp_smapi, firefox-9.0 install stucks
Date: Tue, 10 Jan 2012 12:45:24
Message-Id: 20120110133226.603ca67d@gentoo.christian.ich
In Reply to: Re: [gentoo-hardened] hardened-sources & tp_smapi, firefox-9.0 install stucks by "Tóth Attila"
1 Am Sat, 31 Dec 2011 14:43:10 +0100
2 schrieb "Tóth Attila" <atoth@××××××××××.hu>:
3
4 > Isn't it miserable to see, that as time is passing by, more and more
5 > important softwares (java, python, libreoffice, firefox) conflict with
6 > more and more PAX restrictions?
7
8 Hello hardened-list,
9 I would like to point out that I am still able to run icecat-9.0.1
10 without any pax feature disabled by patching the ebuild as shown by the
11 attached patch. Basically I applied the patch from Bug #396275 and
12 disabled both methodjit and tracejit. And now icecat (including
13 addons like noscript) runs without being pax-marked.
14 I am well aware of the warnings that the Javascript engine runs slower
15 without methodjit (by the way, why was that USE flag dropped?). I use
16 Javascript only when absolutely necessary, so I might not be the best
17 judge, but I don't see any noticeable impact on performance. Neither do
18 I use flash plugin or something like that, so neither can I say whether
19 flash will work without pax-marking.
20 May solution may not be workable for everybody. But I don't see a
21 reason why not to give it a try for ones like me who want a browser with
22 reasonable JS management (as provided by the noscript addon) but do not
23 need all the flashy extras. It should be up to the user to decide which
24 features to enable.
25 Best regards
26 Christian Apeltauer

Attachments

File name MIME type
icecat.patch text/x-patch

Replies