|
From: Heiko Z. <smi...@us...> - 2007-12-25 18:19:04
|
Update of /cvsroot/devil-linux/build/scripts In directory sc8-pr-cvs12.sourceforge.net:/tmp/cvs-serv6924/scripts Modified Files: finalize openssl Added Files: pax-utils Log Message: - updated gmp to 4.2.2 - build system now fails if GNU_EXEC_STACK is turned on for files and PAX or GRSecurity are enabled (the specific binaries/libraries will error out) the install/finalize script will log the specific files in the output - install/finalize script logs all files with TEXTREL so we can fix them - added pax-utils 0.1.15 to build system (thanks Hardened Gentoo folks!) --- NEW FILE: pax-utils --- #!/bin/bash # $Source: /cvsroot/devil-linux/build/scripts/pax-utils,v $ # $Revision: 1.1 $ # $Date: 2007/12/25 18:18:58 $ # # http://www.devil-linux.org # you need the next line, otherwise script won't be executed !!! # DL-build-system v3 ### BEGIN INIT INFO # Provides: pax-utils # Required-Start: $basebuildtools # Required-Stop: # Default-Start: 1 # Default-Stop: # Description: description ### END INIT INFO # get the directoryname of the script MYDIR=${0%/*} # source functions and config source $MYDIR/settings case $1 in build ) make $PMAKE || exit 1 make install || exit 1 strip_debug ;; * ) echo "ERROR ($0)" echo "please add parameter so I know what to do" exit 1 ;; esac Index: openssl =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/openssl,v retrieving revision 1.28 retrieving revision 1.29 diff -u -d -r1.28 -r1.29 --- openssl 24 Dec 2007 20:24:02 -0000 1.28 +++ openssl 25 Dec 2007 18:18:58 -0000 1.29 @@ -33,7 +33,9 @@ touch .patches_done fi - replace_str crypto/Makefile "^ASFLAGS=" "&-Wa,--noexecstack " + for FILE in $(find crypto/ -name Makefile) ; do + replace_str $FILE "^ASFLAGS=" "&-Wa,--noexecstack " + done ./Configure linux-elf shared threads zlib-dynamic --prefix=/usr --openssldir=/etc/ssl || exit 1 make depend || exit 1 Index: finalize =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/finalize,v retrieving revision 1.8 retrieving revision 1.9 diff -u -d -r1.8 -r1.9 --- finalize 1 Apr 2007 20:20:29 -0000 1.8 +++ finalize 25 Dec 2007 18:18:58 -0000 1.9 @@ -30,11 +30,39 @@ pwconv || exit 1 cp /etc/passwd $ETCDIR/etc/ || exit 1 cp /etc/group $ETCDIR/etc/ || exit 1 - #cp /etc/group $INITRDDIR/ || exit 1 cp /etc/shadow $ETCDIR/etc/ || exit 1 cp /etc/gshadow $ETCDIR/etc/ || exit 1 chown -R 0.0 $ETCDIR/etc || exit 1 + + TEXT_REL=$(scanelf -qtyR $CDDIR) + if [ -n "$TEXT_REL" ]; then + echo "************ WARNING ************" + echo "The following files contain text relocations, please try to get those files to PIC" + echo "$TEXT_REL" + fi + + # now let's search for libraries which have the executable stack flag set + # and error out if we find any (only if PAX or GRSecurity are on) + GNU_EXEC_STACK=$(scanelf $CDDIR -eRq) + if [ -n "$GNU_EXEC_STACK" ]; then + if [ "$CONFIG_GRSECURITY" = "y" ] || [ "$CONFIG_PAX" == "y" ]; then + echo "************ ERROR ************" + else + echo "************ WARNING ************" + fi + echo "The following files have the GNU_EXEC_STACK turned on:" + echo "$GNU_EXEC_STACK" + echo "fix this by adding either:" + echo "-Wa,--noexecstack to CC" + echo "or" + echo "-Wl,-z,noexecstack to LD" + echo "worst case just disable it with scanelf" + echo "see http://www.gentoo.org/proj/en/hardened/pax-utils.xml for details" + if [ "$CONFIG_GRSECURITY" = "y" ] || [ "$CONFIG_PAX" == "y" ]; then + exit 1 + fi + fi ;; * ) |