Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <basile@××××××××××××××.edu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] various pax-marking problems
Date: Mon, 08 Jul 2013 14:14:53
Message-Id: 51DAC9C4.8040306@opensource.dyc.edu
In Reply to: Re: [gentoo-hardened] various pax-marking problems by Alex Efros
1 On 07/08/2013 09:09 AM, Alex Efros wrote:
2 > Hi!
3 >
4 > On Mon, Jul 08, 2013 at 09:03:43AM -0400, Anthony G. Basile wrote:
5 >> In your make.conf set PAX_MARKINGS="PT" in the former case or
6 >> PAX_MARKINGS="XT". It is safe to set both: PAX_MARKINGS="PT XT"
7 >
8 > What is default if it's not set? I didn't remember mentioning it in "PT to
9 > XT migration howto"…
10 >
11
12 Currently we had to drop back to PAX_MARKINGS="PT" in the eclass because
13 non-hardened users were complaining about warnings that xattrs were not
14 being set. I'll have to revisit this issue with a totally vanilla
15 system when all the relevant pieces go stable, particularly portage. At
16 that point I'll see if PAX_MARKINGS="PT XT" throws warnings and if it
17 does just silence them.
18
19 --
20 Anthony G. Basile, Ph. D.
21 Chair of Information Technology
22 D'Youville College
23 Buffalo, NY 14201
24 (716) 829-8197