Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 315667 - Pax kills chromium 5.0.375.3
Summary: Pax kills chromium 5.0.375.3
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Hardened (show other bugs)
Hardware: All Linux
: High normal
Assignee: The Gentoo Linux Hardened Team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-04-16 21:29 UTC by Joel
Modified: 2010-05-11 11:26 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
dmesg output (dmesg,3.12 KB, text/plain)
2010-04-16 21:30 UTC, Joel
Details
emerge --info (info,3.92 KB, text/plain)
2010-04-16 21:30 UTC, Joel
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Joel 2010-04-16 21:29:57 UTC
I'm on a Gentoo amd64 testing with hardened profile. I've tried chromium 5.0.342.9 and 5.0.375.3 and both get killed by pax when launched. I attach demesg relevant output and emerge --info

Reproducible: Always
Comment 1 Joel 2010-04-16 21:30:30 UTC
Created attachment 228065 [details]
dmesg output
Comment 2 Joel 2010-04-16 21:30:43 UTC
Created attachment 228067 [details]
emerge --info
Comment 3 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2010-04-19 11:51:50 UTC
Joel, could you provide a paxctl or equivalent command that would make Chromium work on PaX-enabled system?
Comment 4 Xake 2010-04-19 12:00:12 UTC
@Joel please provide build log in future bugreports.

Here is what probably creates the fail.

^G
 * QA Notice: The following files contain runtime text relocations
 *  Text relocations force the dynamic linker to perform extra
 *  work at startup, waste system resources, and may pose a security
 *  risk.  On some architectures, the code may not even function
 *  properly, if at all.
 *  For more information, see http://hardened.gentoo.org/pic-fix-guide.xml
 *  Please include the following list of files in your report:
 * TEXTREL usr/lib64/chromium-browser/chrome
^G
^G
 * QA Notice: The following files contain writable and executable sections
 *  Files with such sections will not work properly (or at all!) on some
 *  architectures/operating systems.  A bug should be filed at
 *  http://bugs.gentoo.org/ to make sure the issue is fixed.
 *  For more information, see http://hardened.gentoo.org/gnu-stack.xml
 *  Please include the following list of files in your report:
 *  Note: Bugs should be filed for the respective maintainers
 *  of the package in question and not hardened@g.o.
 * RWX --- --- usr/lib64/chromium-browser/chrome
Comment 5 Constantine Kardaris 2010-05-10 16:49:08 UTC
#paxctl -c /opt/chromium.org/chrome-linux/chrome
#paxctl -m /opt/chromium.org/chrome-linux/chrome

that is for chromium-bin
fyi seems to also work ok with just the javascript disabled
Comment 6 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2010-05-11 11:26:33 UTC
This should be fixed with a recent bump. Thanks Constantine for the paxctl commands. Please re-open (preferably with an ebuild patch), if there are still some problems with it.