Gentoo Archives: gentoo-hardened

From: Grant <emailgrant@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Firefox won't compile on hardened profile
Date: Sun, 19 Feb 2012 18:33:30
Message-Id: CAN0CFw3t9-cRegSG5t6VHtaO0sAn_E6i3-5_k=GevUkEWGcp-w@mail.gmail.com
In Reply to: Re: [gentoo-hardened] Firefox won't compile on hardened profile by "Tóth Attila"
1 > There's a snippet in your ebuild:
2 > "append-flags -mno-avx"
3 >
4 > What is the problem with avx? Is it an option counteracting with security?
5
6 I'm sorry but I'm not sure what you mean. I should change the firefox ebuild?
7
8 - Grant
9
10
11 >>>>>>> Firefox won't compile on my system due to the issue
12 >>>>>>> described here:
13 >>>>>>>
14 >>>>>>> http://www.gossamer-threads.com/lists/gentoo/hardened/245060
15 >>>>>>
16 >>>>>>
17 >>>>>>>
18 >> FWIW: I had no trouble compiling Firefox 9.0 on my amd64 system
19 >>>>>> using the current stable 3.2.2-r1 kernel, gcc 4.5.3,
20 >>>>>> grsec/pax enabled.
21 >>>>>
22 >>>>> To confirm, you aren't on a hardened profile?
23 >>>>
24 >>>> I am on a hardened profile, currently using
25 >>>> hardened/linux/amd64/no-multilib/selinux profile, only running
26 >>>> stable software.
27 >>>
28 >>> I don't get it then.  Does anyone know why I can't compile Firefox
29 >>> as described in the link above?  This sums it up:
30 >>>
31 >>> "firefox-9.0 ebuild stalls at the install phase while xpcshell
32 >>> command tops CPU usage for hours."
33 >>>
34 >>> Although xpcshell doesn't use any CPU for me.  It just sits there
35 >>> and the install phase doesn't proceed.
36 >>>
37 >>> - Grant
38 >>>
39 >>
40 >> I can compile Icecat with a customized ebuild. since it's basically
41 >> the same as Firefox, maybe that helps. Basically it disables jit.

Replies

Subject Author
Re: [gentoo-hardened] Firefox won't compile on hardened profile "Tóth Attila" <atoth@××××××××××.hu>