Gentoo Archives: gentoo-hardened

From: gentoo-hardened-ml-01@××××××.org
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Hardened Gentoo + Quake3?
Date: Sun, 28 Jan 2007 02:22:42
Message-Id: 200701271820.46350.gentoo-hardened-ml-01@bumpin.org
1 I've had a "partially-hardened" workstation for awhile now. I use
2 hardened-sources and enable many of the PaX/grsecurity options including
3 stack smashing protection. This works great as I can disable SEGMEXEC,
4 PAGEEXEC and mprotect for Quake3 (ioquake3) and get it to run. My question
5 is if I take my workstation to a full hardened system with SSP+PIE toolchain,
6 etc. will I still be able to run Quake3 and other programs like it? If I
7 went to a full Hardened Gentoo system, even if I disabled PaX's SEGMEXEC,
8 PAGEXEC and mprotect, which is sufficient to run Quake3 now, the toolchains'
9 own SSP would then kick in and stop me, right?
10
11 I'm normally a test and do-it-myself kind of person, but I really don't want
12 to have to recompile the system to find out and then recompile again if gcc's
13 SSP/ProPolice does stop me.
14
15 Side note: I masked gcc-4* and >=glibc-2.4 when they were stabled in x86. I
16 still run gcc-3.4.6-r2 and glibc-2.3.6-r5 so switching to the hardened
17 profile will not present any of those types of problems for me.
18
19 Thank you for your help.
20 --
21 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Hardened Gentoo + Quake3? John Schember <j5483@×××××.com>