Gentoo Archives: gentoo-hardened

From: Alex Efros <powerman@××××××××××××××××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] [Bug 134620] portage does not uninstall files that have been modified by paxctl or chpax
Date: Sat, 17 Jun 2006 22:35:55
Message-Id: 20060617223308.GO20474@home.power
In Reply to: Re: [gentoo-hardened] [Bug 134620] portage does not uninstall files that have been modified by paxctl or chpax by pageexec@freemail.hu
1 Hi!
2
3 On Sun, Jun 18, 2006 at 12:01:36AM +0200, pageexec@××××××××.hu wrote:
4 > imho, this is the only proper solution, any external management is
5 > misplaced for a simple reason: PaX flags are not a matter of policy
6 > (not up to an arbitrary human decision), they simply reflect what
7 > the given application can run with at all. in practice that means
8
9 Agreed!
10
11 Probably best way to view relaxed PaX flags similar to SUID bit.
12 SUID bit also required for some application to run and these binaries now
13 installed with switched on SUID bit anyway. (Yeah, I know, some app doesn't
14 require it but may provide additional features with it and these app can
15 be installed by portage without SUID bit by default. But app which just
16 don't run without SUID bit installed with it!)
17
18 --
19 WBR, Alex.
20 --
21 gentoo-hardened@g.o mailing list