Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] apache ssl problems: PAX terminates execution attempt
Date: Mon, 18 Apr 2011 05:02:50
Message-Id: c31e05984ede12ff75c62c019f988cf7.squirrel@atoth.sote.hu
In Reply to: Re: [gentoo-hardened] apache ssl problems: PAX terminates execution attempt by Magnus Granberg
1 2011.Április 17.(V) 13:20 időpontban Magnus Granberg ezt írta:
2 > söndag 17 april 2011 12.27.19 skrev Tóth Attila:
3 >> 2011.Április 17.(V) 03:49 időpontban Alex Efros ezt írta:
4 >> > Hi!
5 >> >
6 >> > On Sun, Apr 17, 2011 at 02:17:21AM +0200, "Tóth Attila" wrote:
7 >> >> Reverting to the old binary makes the problem go away.
8 >> >
9 >> > Any chance it's as trivial as somehow modified old binary - like with
10 >> > paxctl?
11 >>
12 >> paxctl -m haven't solved the problem.
13 >>
14 >> > Also, you can try to use non-hardened gcc to build apache, just in
15 >> case.
16 >>
17 >> I would rather not use a non-hardened apache on the server. But I can
18 >> give
19 >> a try to compile it using a vanilla gcc profile.
20 >> Any of you successfully recompiled apache with a recent toolchain and
21 >> see
22 >> the ssl connections are working correctly?
23 >>
24 >> Thx:
25 >> Dw.
26 >>
27 >> > --
28 >> >
29 >> > WBR, Alex.
30 > Look at bug http://bugs.gentoo.org/show_bug.cgi?id=363443
31 > /Magnus
32
33 Compiling using gcc-4.5.2 with -O1 or switching to gcc-4.4.5 solves the
34 issue. Obviously it's not a solution.
35 I can provide binaries, but gcc cannot compile using -g ggdb in my case.
36
37 Thx for the tip. I add my comment to this bug.
38
39 Dw.
40 --
41 dr Tóth Attila, Radiológus, 06-20-825-8057
42 Attila Toth MD, Radiologist, +36-20-825-8057