Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
running mono apps (e.g. tomboy) with SEGMEXEC / PAGEEXEC ?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
kernelOfTruth
Watchman
Watchman


Joined: 20 Dec 2005
Posts: 6111
Location: Vienna, Austria; Germany; hello world :)

PostPosted: Fri Apr 06, 2007 7:10 pm    Post subject: running mono apps (e.g. tomboy) with SEGMEXEC / PAGEEXEC ? Reply with quote

Hi there,

is there a possibility to run mono-apps such as tomboy or f-spot under a kernel with grsecurity / pax

without getting "killed" ?

I know, it's "not a valid ELF executable" :wink:

can there be declared exclusions / exceptions ?

if this works it would also be nice to know if crossover with m$office works that way ...

this would be really nice, since ati-drivers + mprotect & 3d acceleration seem to work fine so far ...

Thanks in advance

Update:

where are pax or chpax in /etc/init.d/ where they are supposed to be ?

I've found a list for lowering mprotect restrictions http://d-sbd.alioth.debian.org/www/pax/pax.conf
but how to apply ?

http://d-sbd.alioth.debian.org/www/?page=pax
_________________
https://github.com/kernelOfTruth/ZFS-for-SystemRescueCD/tree/ZFS-for-SysRescCD-4.9.0
https://github.com/kernelOfTruth/pulseaudio-equalizer-ladspa

Hardcore Gentoo Linux user since 2004 :D
Back to top
View user's profile Send private message
moocha
Watchman
Watchman


Joined: 21 Oct 2003
Posts: 5722

PostPosted: Sat Apr 14, 2007 8:17 am    Post subject: Reply with quote

Code:
paxctl -pemrxs /usr/bin/mono /usr/lib/lib*mono*
No init script necessary. Of course, if the package gets re-emerged you'll need to do it again, but overall it's an acceptable and simple solution.
_________________
Military Commissions Act of 2006: http://tinyurl.com/jrcto

"Those who would give up essential liberty to purchase a little temporary safety deserve neither liberty nor safety."
-- attributed to Benjamin Franklin
Back to top
View user's profile Send private message
kernelOfTruth
Watchman
Watchman


Joined: 20 Dec 2005
Posts: 6111
Location: Vienna, Austria; Germany; hello world :)

PostPosted: Sat Apr 14, 2007 8:48 am    Post subject: Reply with quote

moocha wrote:
Code:
paxctl -pemrxs /usr/bin/mono /usr/lib/lib*mono*
No init script necessary. Of course, if the package gets re-emerged you'll need to do it again, but overall it's an acceptable and simple solution.


Amazing! thanks :D I'll give it a try as soon as possible
_________________
https://github.com/kernelOfTruth/ZFS-for-SystemRescueCD/tree/ZFS-for-SysRescCD-4.9.0
https://github.com/kernelOfTruth/pulseaudio-equalizer-ladspa

Hardcore Gentoo Linux user since 2004 :D
Back to top
View user's profile Send private message
kernelOfTruth
Watchman
Watchman


Joined: 20 Dec 2005
Posts: 6111
Location: Vienna, Austria; Germany; hello world :)

PostPosted: Tue Jun 19, 2007 1:30 pm    Post subject: Reply with quote

it worked :D :!:

one more question :?:

does this also work with crossover (-pemrxs -> applied to /opt/cxoffice/),

I read that paxctl -m suffices for java, (it worked fine without so far),

then everything should be working with pax, if I haven't forgotten anything

will try out a new kernel with pax later ...

many thanks in advance
_________________
https://github.com/kernelOfTruth/ZFS-for-SystemRescueCD/tree/ZFS-for-SysRescCD-4.9.0
https://github.com/kernelOfTruth/pulseaudio-equalizer-ladspa

Hardcore Gentoo Linux user since 2004 :D
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum