Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 469776 - profiles/hardened/linux/uclibc/amd64: please unmask jit
Summary: profiles/hardened/linux/uclibc/amd64: please unmask jit
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Hardened (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: The Gentoo Linux Hardened Team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-05-14 02:33 UTC by pmn
Modified: 2013-05-28 14:48 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description pmn 2013-05-14 02:33:15 UTC
jit builds just fine here (for webkit-gtk and friends). no test for runtime though.

Reproducible: Always
Comment 1 Anthony Basile gentoo-dev 2013-05-14 14:28:03 UTC
It does, but the problem with jit is pax.  It requires RWX mmap-ings which are killed by the hardened kernel.  So in all hardened profiles, not just the uclibc ones, we've masked jit.

This issue comes back every once in a while, so I'll let the rest of the hardened team pipe in.
Comment 2 Anthony Basile gentoo-dev 2013-05-28 14:48:54 UTC
Okay I'll follow the main hardened profiles here and just turn jit and orc off by default but not mask them.  More than this would be wrong because of the RWX mmap-ings.


+  28 May 2013; Anthony G. Basile <blueness@gentoo.org>
+  hardened/linux/uclibc/make.defaults, hardened/linux/uclibc/use.mask:
+  Unmask jit and orc, but turn them off by default on hardened/linux/uclibc
+