Gentoo Archives: gentoo-hardened

From: Grant <emailgrant@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Hardened laptop: am I nuts?
Date: Wed, 05 Dec 2007 14:22:33
Message-Id: 49bf44f10712050620q1e07a107i81337dce32529cdb@mail.gmail.com
In Reply to: Re: [gentoo-hardened] Hardened laptop: am I nuts? by Alex Howells
1 > > > $ skype
2 > > > /usr/bin/skype: line 10: /opt/skype/skype: No such file or directory
3 > > > /usr/bin/skype: line 10: /opt/skype/skype: Success
4 > > > $ wengophone
5 > > > /opt/bin/wengophone: line 10: /opt/wengophone/qtwengophone: No such
6 > > > file or directory
7 > > > /opt/bin/wengophone: line 10: /opt/wengophone/qtwengophone: Success
8 > > > $ firefox-bin
9 > > > /usr/libexec/mozilla-launcher: line 368:
10 > > > /opt/firefox/mozilla-xremote-client: No such file or directory
11 > > > Unknown error 127 from mozilla-xremote-client
12 > > > /usr/libexec/mozilla-launcher: line 460: /opt/firefox/firefox-bin: No
13 > > > such file or directory
14 > > > firefox-bin exited with non-zero status (127)
15 > > >
16 > > > All of the errors are very similar, and all of the files they say
17 > > > don't exist definitely do.
18 > >
19 > > all of them seem to be in /opt. is that a special mount with noexec
20 > > set perhaps? otherwise you could 'strace -f' one of these and check
21 > > what exactly fails.
22 >
23 > It'd also be very useful to see the output of 'emerge --info' so we
24 > can tell what profile you're using, any awkward CFLAGs which aren't
25 > compatible with hardened which might have been enabled...
26
27 $ emerge --info
28 Portage 2.1.3.19 (hardened/amd64, gcc-3.4.6, glibc-2.6.1-r0,
29 2.6.22-hardened-r8 x86_64)
30 =================================================================
31 System uname: 2.6.22-hardened-r8 x86_64 Intel(R) Pentium(R) Dual CPU
32 T2310 @ 1.46GHz
33 Timestamp of tree: Tue, 04 Dec 2007 15:16:01 +0000
34 app-shells/bash: 3.2_p17
35 dev-java/java-config: 1.3.7, 2.0.33-r1
36 dev-lang/python: 2.4.4-r6
37 dev-python/pycrypto: 2.0.1-r6
38 sys-apps/baselayout: 1.12.9-r2
39 sys-apps/sandbox: 1.2.18.1-r2
40 sys-devel/autoconf: 2.13, 2.61-r1
41 sys-devel/automake: 1.5, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2, 1.10
42 sys-devel/binutils: 2.18-r1
43 sys-devel/gcc-config: 1.3.16
44 sys-devel/libtool: 1.5.24
45 virtual/os-headers: 2.6.22-r2
46 ACCEPT_KEYWORDS="amd64"
47 CBUILD="x86_64-pc-linux-gnu"
48 CFLAGS="-O2 -march=nocona -pipe -fomit-frame-pointer"
49 CHOST="x86_64-pc-linux-gnu"
50 CONFIG_PROTECT="/etc /usr/share/X11/xkb"
51 CONFIG_PROTECT_MASK="/etc/env.d /etc/env.d/java/ /etc/fonts/fonts.conf
52 /etc/gconf /etc/revdep-rebuild /etc/terminfo /etc/udev/rules.d"
53 CXXFLAGS="-O2 -march=nocona -pipe -fomit-frame-pointer"
54 DISTDIR="/usr/portage/distfiles"
55 FEATURES="buildpkg distlocks metadata-transfer sandbox sfperms strict
56 unmerge-orphans userfetch"
57 GENTOO_MIRRORS="http://distfiles.gentoo.org
58 http://distro.ibiblio.org/pub/linux/distributions/gentoo"
59 LINGUAS="en"
60 MAKEOPTS="-j1"
61 PKGDIR="/usr/portage/packages"
62 PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times
63 --compress --force --whole-file --delete --delete-after --stats
64 --timeout=180 --exclude=/distfiles --exclude=/local
65 --exclude=/packages --filter=H_**/files/digest-*"
66 PORTAGE_TMPDIR="/var/tmp"
67 PORTDIR="/usr/portage"
68 PORTDIR_OVERLAY="/usr/local/portage"
69 SYNC="rsync://rsync.us.gentoo.org/gentoo-portage"
70 USE="X acl acpi alsa amd64 bash-completion berkdb bzip2 cairo caps cdr
71 cracklib crypt cups dbus dhcp divx dri dts dvd exif firefox flac gd
72 gif gimp gmedia gmp gnutls gpm grammar gsm gtk gtkhtml hal hardened
73 hpn java jpeg justify lcms mad madwifi md5sum midi mng mono mp3 mpeg
74 ncurses new-login normalize nptl nptlonly nsplugin offensive ogg
75 opengl oss pam pdf perl pic png python qt3support quicktime quotes
76 readline realmedia regex rtc sdl spell sse sse2 ssl tcpd thesaurus
77 tiff truetype unicode urandom vim-with-x wmf wmp wxwindows x264 xml
78 xorg xprint xscreensaver xv zlib" ALSA_CARDS="hda-intel"
79 ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty
80 extplug file hooks iec958 ioplug ladspa lfloat linear meter mulaw
81 multi null plug rate route share shm softvol" APACHE2_MODULES="actions
82 alias auth_basic authn_alias authn_anon authn_dbm authn_default
83 authn_file authz_dbm authz_default authz_groupfile authz_host
84 authz_owner authz_user autoindex cache dav dav_fs dav_lock deflate dir
85 disk_cache env expires ext_filter file_cache filter headers include
86 info log_config logio mem_cache mime mime_magic negotiation rewrite
87 setenvif speling status unique_id userdir usertrack vhost_alias"
88 ELIBC="glibc" INPUT_DEVICES="keyboard synaptics" KERNEL="linux"
89 LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb
90 ncurses text" LINGUAS="en" USERLAND="GNU" VIDEO_CARDS="i810"
91 Unset: CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG,
92 LC_ALL, LDFLAGS, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS,
93 PORTAGE_RSYNC_EXTRA_OPTS
94
95 > My earlier post wasn't really sarcasm, just badly done humour :) You
96 > can blame it on me being Welsh, or whatever.
97
98 I thought you could have been saying a hardened laptop was paranoia,
99 but I just couldn't tell.
100
101 - Grant
102 --
103 gentoo-hardened@g.o mailing list