Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <basile@××××××××××××××.edu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] XATTR_PAX migration
Date: Mon, 09 Sep 2013 21:26:48
Message-Id: 522E3D21.2070802@opensource.dyc.edu
In Reply to: Re: [gentoo-hardened] XATTR_PAX migration by Michael Orlitzky
1 On 09/09/2013 01:56 PM, Michael Orlitzky wrote:
2 > On 09/09/2013 01:47 PM, Anthony G. Basile wrote:
3 >>
4 >> That was my mistake. When I dropped XT I forgot to update the comment.
5 >> We tried XT right off the bat, but discovered a couple of problems: 1)
6 >> install doesn't preserve xattr. we have a solution but it isn't working
7 >> that well, and 2) there were lots of warning thrown for non hardened
8 >> users which annoyed them. So we dropped to just PT.
9 >>
10 >
11 > What do you recommend then? Stick with PT_PAX until the install thing is
12 > fixed, and then add PAX_MARKINGS=XT to make.conf?
13 >
14 >
15
16 You can use XT_PAX provided you're not running something like a
17 tinderbox, ie doing massive amounts of ebuilds. The problem is that
18 install is being wrapped by install.py. As a result every instance of
19 install mean invoking the python interpreter. With lots and lots of
20 installs, this adds up to being very slow.
21
22 --
23 Anthony G. Basile, Ph. D.
24 Chair of Information Technology
25 D'Youville College
26 Buffalo, NY 14201
27 (716) 829-8197

Replies

Subject Author
Re: [gentoo-hardened] XATTR_PAX migration Alex Efros <powerman@××××××××.name>
Re: [gentoo-hardened] XATTR_PAX migration Michael Orlitzky <michael@××××××××.com>
Re: [gentoo-hardened] XATTR_PAX migration Alex Efros <powerman@××××××××.name>