This bug is here simply to remind me to get the documentationon done: 0) how to configure the kernel for xattr based pax, 1) how to migrate from PT_PAX to xattr pax, 2) how to maintain an xattr pax based pax system. This issue rises to the level of a bug, and a blocker, because the unexpecting user who has a legacy system pulled out from underneath may find herself in trouble. The change over should be accompanied by a news item.
There is now updated documentation at http://www.gentoo.org/proj/en/hardened/pax-quickstart.xml
Please consider adding a line to make.conf(5) -> FEATURES -> xattr about the fact that when this feature is set, pax xattr markings happen, and vice versa. Idea spawned from discussion in bug 464932.
(In reply to comment #2) > Please consider adding a line to make.conf(5) -> FEATURES -> xattr about the > fact that when this feature is set, pax xattr markings happen, and vice > versa. Idea spawned from discussion in bug 464932. OK, this fact turned out not to be a fact. Ignore the above comment, please.