Created attachment 359308 [details] emerge output emerge --info Portage 2.2.6 (hardened/linux/amd64, gcc-4.8.1, glibc-2.17, 3.11.1-hardened x86_64) ================================================================= System uname: Linux-3.11.1-hardened-x86_64-Intel-R-_Core-TM-_i5-2320_CPU_@_3.00GHz-with-gentoo-2.2 KiB Mem: 8159528 total, 700248 free KiB Swap: 16777212 total, 16742324 free Timestamp of tree: Mon, 23 Sep 2013 17:30:01 +0000 ld GNU ld (GNU Binutils) 2.23.2 app-shells/bash: 4.2_p45 dev-java/java-config: 2.2.0 dev-lang/python: 2.7.5-r2, 3.3.2-r2 dev-util/cmake: 2.8.11.2 dev-util/pkgconfig: 0.28 sys-apps/baselayout: 2.2 sys-apps/openrc: 0.12 sys-apps/sandbox: 2.6-r1 sys-devel/autoconf: 2.13, 2.69 sys-devel/automake: 1.9.6-r3, 1.11.6, 1.12.6, 1.14 sys-devel/binutils: 2.23.2 sys-devel/gcc: 4.6.4, 4.7.3, 4.8.1 sys-devel/gcc-config: 1.8 sys-devel/libtool: 2.4.2 sys-devel/make: 3.82-r4 sys-kernel/linux-headers: 3.11 (virtual/os-headers) sys-libs/glibc: 2.17 Repositories: gentoo x11 fidonet Graham-s-Local-Portage ACCEPT_KEYWORDS="amd64 ~amd64" ACCEPT_LICENSE="*" CBUILD="x86_64-pc-linux-gnu" CFLAGS="-march=native -mtune=native -O2 -pipe" CHOST="x86_64-pc-linux-gnu" CONFIG_PROTECT="/etc /usr/share/config /usr/share/gnupg/qualified.txt /var/bind /var/spool/munin-async/.ssh" CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/dconf /etc/env.d /etc/fonts/fonts.conf /etc/games/angband/edit/ /etc/gconf /etc/gentoo-release /etc/php/apache2-php5.4/ext-active/ /etc/php/apache2-php5.5/ext-active/ /etc/php/cgi-php5.4/ext-active/ /etc/php/cgi-php5.5/ext-active/ /etc/php/cli-php5.4/ext-active/ /etc/php/cli-php5.5/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo /etc/texmf/language.dat.d /etc/texmf/language.def.d /etc/texmf/updmap.d /etc/texmf/web2c" CXXFLAGS="-march=native -mtune=native -O2 -pipe" DISTDIR="/usr/portage/distfiles" EMERGE_DEFAULT_OPTS="--with-bdeps y" FCFLAGS="-O2 -pipe" FEATURES="assume-digests binpkg-logs buildpkg config-protect-if-modified distlocks ebuild-locks fixlafiles merge-sync news parallel-fetch preserve-libs protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync xattr" FFLAGS="-march=native -mtune=native -O2 -pipe" GENTOO_MIRRORS="http://www.mirrorservice.org/sites/www.ibiblio.org/gentoo/ http://mirror.qubenet.net/mirror/gentoo/ http://mirrors.linuxant.fr/distfiles.gentoo.org/ ftp://mirror.qubenet.net/mirror/gentoo/ ftp://ftp.mirrorservice.org/sites/www.ibiblio.org/gentoo/" LANG="en_GB.UTF-8" LDFLAGS="-Wl,-O1 -Wl,--as-needed" MAKEOPTS="-j5" PKGDIR="/usr/portage/packages" PORTAGE_CONFIGROOT="/" PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages" PORTAGE_TMPDIR="/var/tmp" PORTDIR="/usr/portage" PORTDIR_OVERLAY="/var/lib/layman/x11 /var/lib/layman/fidonet /usr/local/portage" SYNC="rsync://rsync.gentoo.org/gentoo-portage" USE="X a52 aac acl alsa amd64 apache2 berkdb branding bzip2 cairo caps cdda cddb cli cracklib crypt cups cxx dbus directfb doc dri dts dvd emacs encode examples exif fam ffmpeg flac fontconfig fortran gd gdbm geoip gif gmp gnome gnome-keyring gnutls gpm gstreamer gtk hardened iconv icu imagemagick introspection ipv6 java jpeg jpeg2k justify kde lcms libnotify lua lzma mad matroska milter mmx mng modules mp3 mpeg mudflap multilib mysql ncurses nls nptl nsplugin ogg opengl openmp pam pax_kernel pcre perl pfd png policykit postgres ppds pulseaudio python qt4 raw readline sdl semantic-desktop session speex spell sqlite sqlite3 sse sse2 sse3 ssl ssse3 startup-notification svg systemd tcpd theora threads tiff tk truetype udev unicode urandom usb v4l vdpau vim-syntax vorbis x264 xattr xcb xml xmp xv xvid zlib" ABI_X86="64 32" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" APACHE2_MODULES="authn_core authz_core socache_shmcb unixd actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CALLIGRA_FEATURES="braindump flow karbon kexi krita sheets words" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ubx" INPUT_DEVICES="keyboard mouse evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" LINGUAS="en_GB en fr" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php5-5 php5-4" PYTHON_SINGLE_TARGET="python2_7" PYTHON_TARGETS="python2_7 python3_3" RUBY_TARGETS="ruby18 ruby19 ruby20" USERLAND="GNU" VIDEO_CARDS="nouveau" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account" Unset: CPPFLAGS, CTARGET, INSTALL_MASK, LC_ALL, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, USE_PYTHON
I found a difference between profile "default/linux/amd64/13.0/x32" and "hardened/linux/amd64/x32". <code> (gentoo-x32) txtsurface / # eselect profile set default/linux/amd64/13.0/x32 (gentoo-x32) txtsurface / # emerge --info | grep ^ABI ABI="x32" ABI_X86="x32 64" (gentoo-x32) txtsurface / # eselect profile set hardened/linux/amd64/x32 (gentoo-x32) txtsurface / # emerge --info | grep ^ABI ABI="amd64" ABI_X86="64" (gentoo-x32) txtsurface / # </code> In my humble opinion the hardened profile for x32 should have x32 as ABI.
I suppose that's some profile inheritance order problem.
$ cat ~/git/gentoo/profiles/hardened/linux/amd64/x32/parent ../../../../features/multilib ../../../../arch/amd64/x32 .. $ ./profile-dumper ~/git/gentoo/profiles/hardened/linux/amd64/x32 /tmp/1 /home/mgorny/git/gentoo/profiles/features/multilib /home/mgorny/git/gentoo/profiles/arch/base /home/mgorny/git/gentoo/profiles/features/multilib /home/mgorny/git/gentoo/profiles/arch/amd64 /home/mgorny/git/gentoo/profiles/arch/amd64/x32 /home/mgorny/git/gentoo/profiles/base /home/mgorny/git/gentoo/profiles/default/linux /home/mgorny/git/gentoo/profiles/arch/base /home/mgorny/git/gentoo/profiles/features/multilib /home/mgorny/git/gentoo/profiles/arch/amd64 /home/mgorny/git/gentoo/profiles/releases /home/mgorny/git/gentoo/profiles/releases/13.0 /home/mgorny/git/gentoo/profiles/hardened/linux /home/mgorny/git/gentoo/profiles/hardened/linux/amd64 /home/mgorny/git/gentoo/profiles/hardened/linux/amd64/x32 $ grep ABI /tmp/1/make.defaults | head -4 ABI="amd64" ABI_X86="64" DEFAULT_ABI="amd64" MULTILIB_ABIS="amd64 x86" If I shift the order: $ cat ~/git/gentoo/profiles/hardened/linux/amd64/x32/parent ../../../../features/multilib .. ../../../../arch/amd64/x32 $ ./profile-dumper ~/git/gentoo/profiles/hardened/linux/amd64/x32 /tmp/2 /home/mgorny/git/gentoo/profiles/features/multilib /home/mgorny/git/gentoo/profiles/base /home/mgorny/git/gentoo/profiles/default/linux /home/mgorny/git/gentoo/profiles/arch/base /home/mgorny/git/gentoo/profiles/features/multilib /home/mgorny/git/gentoo/profiles/arch/amd64 /home/mgorny/git/gentoo/profiles/releases /home/mgorny/git/gentoo/profiles/releases/13.0 /home/mgorny/git/gentoo/profiles/hardened/linux /home/mgorny/git/gentoo/profiles/hardened/linux/amd64 /home/mgorny/git/gentoo/profiles/arch/base /home/mgorny/git/gentoo/profiles/features/multilib /home/mgorny/git/gentoo/profiles/arch/amd64 /home/mgorny/git/gentoo/profiles/arch/amd64/x32 /home/mgorny/git/gentoo/profiles/hardened/linux/amd64/x32 $ diff -dupr /tmp/1 /tmp/2 diff -dupr /tmp/1/make.defaults /tmp/2/make.defaults --- /tmp/1/make.defaults 2017-08-22 09:34:13.169910125 +0200 +++ /tmp/2/make.defaults 2017-08-22 09:35:10.734663700 +0200 @@ -1,10 +1,10 @@ -ABI="amd64" -ABI_X86="64" +ABI="x32" +ABI_X86="x32" ACCEPT_KEYWORDS="amd64" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" APACHE2_MODULES="authn_core authz_core socache_shmcb unixd actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" ARCH="amd64" -BOOTSTRAP_USE="cxx unicode internal-glib python_targets_python3_4 python_targets_python2_7 multilib hardened pax_kernel pic xtpax -jit -orc" +BOOTSTRAP_USE="cxx unicode internal-glib python_targets_python3_4 python_targets_python2_7 multilib hardened pax_kernel pic xtpax -jit -orc multilib" CALLIGRA_FEATURES="kexi words flow plan sheets stage tables krita karbon braindump author" CFLAGS="-O2 -pipe" CFLAGS_amd64="-m64" @@ -20,14 +20,14 @@ CONFIG_PROTECT="/etc" CONFIG_PROTECT_MASK="/etc/env.d /etc/gconf" CPU_FLAGS_X86="mmx mmxext sse sse2" CXXFLAGS="-O2 -pipe" -DEFAULT_ABI="amd64" +DEFAULT_ABI="x32" ELIBC="glibc" FCFLAGS="-O2 -pipe" FFLAGS="-O2 -pipe" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock isync itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf skytraq superstar2 timing tsip tripmate tnt ublox ubx" GRUB_PLATFORMS="" INPUT_DEVICES="libinput" -IUSE_IMPLICIT="abi_x86_64 abi_x86_x32 prefix prefix-chain prefix-guest" +IUSE_IMPLICIT="-abi_x86_64 abi_x86_x32 prefix prefix-chain prefix-guest" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LC_MESSAGES="C" @@ -37,9 +37,9 @@ LDFLAGS_x32="-m elf32_x86_64" LDFLAGS_x86="-m elf_i386" LIBDIR_amd64="lib64" LIBDIR_x32="libx32" -LIBDIR_x86="lib32" +LIBDIR_x86="lib" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" -MULTILIB_ABIS="amd64 x86" +MULTILIB_ABIS="amd64 x86 x32" MULTILIB_STRICT_DENY="64-bit.*shared object" MULTILIB_STRICT_DIRS="/lib32 /lib /usr/lib32 /usr/lib /usr/kde/*/lib32 /usr/kde/*/lib /usr/qt/*/lib32 /usr/qt/*/lib /usr/X11R6/lib32 /usr/X11R6/lib" MULTILIB_STRICT_EXEMPT="(perl5|gcc|gcc-lib|binutils|eclipse-3|debug|portage|udev|systemd|clang|python-exec|llvm)" @@ -48,12 +48,12 @@ OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php5-6" POSTGRES_TARGETS="postgres9_5" PROFILE_IS_HARDENED="1" -PROFILE_ONLY_VARIABLES=" ARCH USE_EXPAND_VALUES_ARCH ELIBC IUSE_IMPLICIT KERNEL USERLAND USE_EXPAND_IMPLICIT USE_EXPAND_UNPREFIXED USE_EXPAND_VALUES_ELIBC USE_EXPAND_VALUES_KERNEL USE_EXPAND_VALUES_USERLAND ARCH USE_EXPAND_VALUES_ARCH" +PROFILE_ONLY_VARIABLES=" ELIBC IUSE_IMPLICIT KERNEL USERLAND USE_EXPAND_IMPLICIT USE_EXPAND_UNPREFIXED USE_EXPAND_VALUES_ELIBC USE_EXPAND_VALUES_KERNEL USE_EXPAND_VALUES_USERLAND ARCH USE_EXPAND_VALUES_ARCH ARCH USE_EXPAND_VALUES_ARCH" PYTHONDONTWRITEBYTECODE="1" PYTHON_SINGLE_TARGET="python3_4" PYTHON_TARGETS="python2_7 python3_4" RUBY_TARGETS="ruby22" -SYMLINK_LIB="yes" +SYMLINK_LIB="no" TWISTED_DISABLE_WRITING_OF_PLUGIN_CACHE="1" UNINSTALL_IGNORE="/lib/modules/* /var/run /var/lock" USE="acl berkdb bzip2 cli cracklib crypt cxx dri -fortran gdbm hardened iconv ipv6 -jit justify modules multilib ncurses nls nptl openmp -orc pam pax_kernel pcre -pic readline seccomp session ssl tcpd unicode urandom xattr xtpax zlib" diff -dupr /tmp/1/package.use.mask /tmp/2/package.use.mask --- /tmp/1/package.use.mask 2017-08-22 09:34:13.172910008 +0200 +++ /tmp/2/package.use.mask 2017-08-22 09:35:10.739663505 +0200 @@ -110,9 +110,9 @@ dev-python/pypy cpu_flags_x86_sse2 sandb dev-python/pypy-bin cpu_flags_x86_sse2 dev-python/pypy3 cpu_flags_x86_sse2 sandbox dev-python/pypy3-bin cpu_flags_x86_sse2 -dev-qt/qtdeclarative -jit -dev-qt/qtscript -jit -dev-qt/qtwebkit -jit +dev-qt/qtdeclarative jit +dev-qt/qtscript jit +dev-qt/qtwebkit jit dev-util/geany-plugins -git dev-util/intel-ocl-sdk system-clang dev-vcs/git -mediawiki -mediawiki-experimental @@ -183,7 +183,7 @@ net-dns/bind seccomp net-dns/pdnsd -isdn -urandom net-fs/openafs modules net-fs/samba system-heimdal -net-im/bitlbee skype +net-im/bitlbee -skype net-im/centerim otr net-im/climm otr net-im/qutim otr @@ -204,7 +204,7 @@ sci-libs/linux-gpib php sci-libs/mathgl octave sci-physics/reduze berkdb sys-apps/flashrom -atahpt -nic3com -nicnatsemi -nicrealtek -rayer_spi -satamv -sys-apps/hwloc gl opencl +sys-apps/hwloc -gl opencl sys-apps/systemd -gnuefi sys-auth/consolekit -acl -cgroups sys-auth/pam_mktemp -prevent-removal diff -dupr /tmp/1/use.force /tmp/2/use.force --- /tmp/1/use.force 2017-08-22 09:34:13.174909930 +0200 +++ /tmp/2/use.force 2017-08-22 09:35:10.740663466 +0200 @@ -1,4 +1,4 @@ -abi_x86_64 +-abi_x86_64 abi_x86_x32 amd64 big-endian diff -dupr /tmp/1/use.mask /tmp/2/use.mask --- /tmp/1/use.mask 2017-08-22 09:34:13.174909930 +0200 +++ /tmp/2/use.mask 2017-08-22 09:35:10.735663661 +0200 @@ -8,7 +8,7 @@ abi_s390_32 abi_s390_64 -abi_x86_32 -abi_x86_64 -abi_x86_x32 +-abi_x86_x32 -ada alpha altivec @@ -181,7 +181,7 @@ video_cards_geode video_cards_i740 video_cards_newport video_cards_nsc -video_cards_nvidia +-video_cards_nvidia video_cards_omap -video_cards_qxl video_cards_sunbw2 I'll leave it for the hardened team to judge if this is acceptable, or if we should look for another solution.