Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] firefox and thunderbird uses compile-time python2.7 without -E
Date: Thu, 11 Aug 2016 16:01:55
Message-Id: 27953337550eb7282b8cb15d33399aef.squirrel@atoth.sote.hu
1 I was busy trying to figure out how it happens the system ends up
2 generating binaries without GNU_STACK header in case pax marking suppose
3 to happen during the ebuild (1-3), I also noticed current firefox and
4 thunderbird ebuilds uses a compile-time python2.7 instance without -E
5 marking, therefore throwing a bunch of "denied RWX mmap of <anonymous
6 mapping>" messages in the log.
7 The two binaries are:
8 /var/tmp/portage/mail-client/thunderbird-45.2.0/work/thunderbird-45.2.0/tbird/_virtualenv/bin/python2.7
9 and
10 /var/tmp/portage/www-client/firefox-48.0/work/firefox-48.0/ff/_virtualenv/bin/python2.7
11 I'm not sure what would be the proper treatment here...
12
13 1. https://bugs.gentoo.org/show_bug.cgi?id=590422
14 2. https://bugs.gentoo.org/show_bug.cgi?id=590334
15 3. https://bugs.gentoo.org/show_bug.cgi?id=589828
16 --
17 dr Tóth Attila, Radiológus, 06-20-825-8057
18 Attila Toth MD, Radiologist, +36-20-825-8057