1 |
Excerpts from Tóth Attila's message of Sat Dec 31 19:22:11 -0700 2011: |
2 |
> |
3 |
> Handling the firefox situation at the ebuild level is pretty simple, since |
4 |
> we have pax-marking available now for use. The real solution would be to |
5 |
> teach upstream about security and proper memory handling. As it was |
6 |
> mentioned by paxteam and others as well. Like it is not just erroneous |
7 |
> from the security point of view, but the whole concept of fixed address |
8 |
> mmap is not correct. |
9 |
|
10 |
The bug [1] referenced earlier contains a patch which allows again the |
11 |
use of RANDMMAP (paxctl -R) with FF9. (At least it works for me and the |
12 |
for the filer of the bug.) As mentioned earlier, this is a better |
13 |
solution than pax-mark r. |
14 |
|
15 |
Many thanks to zakalwe and pageexec for making this patch available so |
16 |
quickly. |
17 |
|
18 |
(I'm getting a very full /etc/portage/patches lately. Only this one is |
19 |
related to hardened; the others are instead for silly things that |
20 |
probably shouldn't be installed anyway.) At least this "wake up call" |
21 |
had me test out some alternate browsers. |
22 |
|
23 |
[1] https://bugs.gentoo.org/show_bug.cgi?id=396275 |
24 |
|
25 |
-- |
26 |
Regards, |
27 |
|
28 |
wmw |