Update of /cvsroot/devil-linux/build/scripts
In directory sc8-pr-cvs12.sourceforge.net:/tmp/cvs-serv6924/scripts
Modified Files:
finalize openssl
Added Files:
pax-utils
Log Message:
- updated gmp to 4.2.2
- build system now fails if GNU_EXEC_STACK is turned on for files and PAX
or GRSecurity are enabled (the specific binaries/libraries will error out)
the install/finalize script will log the specific files in the output
- install/finalize script logs all files with TEXTREL so we can fix them
- added pax-utils 0.1.15 to build system (thanks Hardened Gentoo folks!)
--- NEW FILE: pax-utils ---
#!/bin/bash
# $Source: /cvsroot/devil-linux/build/scripts/pax-utils,v $
# $Revision: 1.1 $
# $Date: 2007/12/25 18:18:58 $
#
# http://www.devil-linux.org
# you need the next line, otherwise script won't be executed !!!
# DL-build-system v3
### BEGIN INIT INFO
# Provides: pax-utils
# Required-Start: $basebuildtools
# Required-Stop:
# Default-Start: 1
# Default-Stop:
# Description: description
### END INIT INFO
# get the directoryname of the script
MYDIR=${0%/*}
# source functions and config
source $MYDIR/settings
case $1 in
build )
make $PMAKE || exit 1
make install || exit 1
strip_debug
;;
* )
echo "ERROR ($0)"
echo "please add parameter so I know what to do"
exit 1
;;
esac
Index: openssl
===================================================================
RCS file: /cvsroot/devil-linux/build/scripts/openssl,v
retrieving revision 1.28
retrieving revision 1.29
diff -u -d -r1.28 -r1.29
--- openssl 24 Dec 2007 20:24:02 -0000 1.28
+++ openssl 25 Dec 2007 18:18:58 -0000 1.29
@@ -33,7 +33,9 @@
touch .patches_done
fi
- replace_str crypto/Makefile "^ASFLAGS=" "&-Wa,--noexecstack "
+ for FILE in $(find crypto/ -name Makefile) ; do
+ replace_str $FILE "^ASFLAGS=" "&-Wa,--noexecstack "
+ done
./Configure linux-elf shared threads zlib-dynamic --prefix=/usr --openssldir=/etc/ssl || exit 1
make depend || exit 1
Index: finalize
===================================================================
RCS file: /cvsroot/devil-linux/build/scripts/finalize,v
retrieving revision 1.8
retrieving revision 1.9
diff -u -d -r1.8 -r1.9
--- finalize 1 Apr 2007 20:20:29 -0000 1.8
+++ finalize 25 Dec 2007 18:18:58 -0000 1.9
@@ -30,11 +30,39 @@
pwconv || exit 1
cp /etc/passwd $ETCDIR/etc/ || exit 1
cp /etc/group $ETCDIR/etc/ || exit 1
- #cp /etc/group $INITRDDIR/ || exit 1
cp /etc/shadow $ETCDIR/etc/ || exit 1
cp /etc/gshadow $ETCDIR/etc/ || exit 1
chown -R 0.0 $ETCDIR/etc || exit 1
+
+ TEXT_REL=$(scanelf -qtyR $CDDIR)
+ if [ -n "$TEXT_REL" ]; then
+ echo "************ WARNING ************"
+ echo "The following files contain text relocations, please try to get those files to PIC"
+ echo "$TEXT_REL"
+ fi
+
+ # now let's search for libraries which have the executable stack flag set
+ # and error out if we find any (only if PAX or GRSecurity are on)
+ GNU_EXEC_STACK=$(scanelf $CDDIR -eRq)
+ if [ -n "$GNU_EXEC_STACK" ]; then
+ if [ "$CONFIG_GRSECURITY" = "y" ] || [ "$CONFIG_PAX" == "y" ]; then
+ echo "************ ERROR ************"
+ else
+ echo "************ WARNING ************"
+ fi
+ echo "The following files have the GNU_EXEC_STACK turned on:"
+ echo "$GNU_EXEC_STACK"
+ echo "fix this by adding either:"
+ echo "-Wa,--noexecstack to CC"
+ echo "or"
+ echo "-Wl,-z,noexecstack to LD"
+ echo "worst case just disable it with scanelf"
+ echo "see http://www.gentoo.org/proj/en/hardened/pax-utils.xml for details"
+ if [ "$CONFIG_GRSECURITY" = "y" ] || [ "$CONFIG_PAX" == "y" ]; then
+ exit 1
+ fi
+ fi
;;
* )
|