On 7/15/11 3:51 AM, Anthony G. Basile wrote:
> So, here's the glitch.  For example, in dev-lang/mono, following the
> above plan, we would drop the "hardened" flag, remove
> 
>    DEPEND=" ... hardened? ( sys-apps/paxctl )"

In the cited scenario, if you're not inheriting the pax-utils eclass,
you can keep paxctl undonditionally in DEPEND. It's a rather lightweight
dependency I think.

> But this assumes that paxctl is on the user's system which is not
> guaranteed unless the users has emerged hardened-sources (which will
> depend on paxctl).   scanelf would have to be the replacement in such
> cases because it is guaranteed to be there by the profiles.

Yeah, I think the pax-utils eclass handles that fallback, it's just not
used by the ebuild (it seems a bit harder here because of the sed call).

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to