Re: [gentoo-dev] RFC: Disambiguation of "hardened" use flag and proposal for a new global flag "pax_kernel"

2011-07-18 Thread Mike Frysinger
On Friday, July 15, 2011 06:51:42 Anthony G. Basile wrote: > ewarn "We are disabling MPROTECT on the mono binary." > sed '/exec/ i\paxctl -mr "$r/@mono_runtime@"' -i > "${S}"/runtime/mono-wrapper.in use: sed -i \ '/exec/ itype -p paxctl >/dev/null && paxctl -mr "$r

Re: [gentoo-dev] RFC: Disambiguation of "hardened" use flag and proposal for a new global flag "pax_kernel"

2011-07-18 Thread Mike Frysinger
On Friday, July 15, 2011 02:44:45 Michał Górny wrote: > On Thu, 14 Jul 2011 19:19:11 -0400 Mike Frysinger wrote: > > > 3) Since a hardened kernel can be configure with various flavors of > > > "pax" or "grsec" or "selinux", there should be useflags to reflect > > > userland needs to conform. There

Re: [gentoo-dev] RFC: optinal run time dependencies

2011-07-18 Thread Markos Chandras
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 18/07/2011 05:45 μμ, Ciaran McCreesh wrote: > On Mon, 18 Jul 2011 17:25:08 +0300 > Markos Chandras wrote: >>> If you have suggested dependencies, you don't need to use >>> pkg_postinst, since suggested dependencies are better. >>> >> You may need

Re: [gentoo-dev] RFC: Disambiguation of "hardened" use flag and proposal for a new global flag "pax_kernel"

2011-07-18 Thread Anthony G. Basile
On 07/16/2011 12:55 PM, "Paweł Hajdan, Jr." wrote: > On 7/15/11 3:51 AM, Anthony G. Basile wrote: >> So, here's the glitch. For example, in dev-lang/mono, following the >> above plan, we would drop the "hardened" flag, remove >> >>DEPEND=" ... hardened? ( sys-apps/paxctl )" > In the cited scen

Re: [gentoo-dev] RFC: optinal run time dependencies

2011-07-18 Thread Ciaran McCreesh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Mon, 18 Jul 2011 17:25:08 +0300 Markos Chandras wrote: > > If you have suggested dependencies, you don't need to use > > pkg_postinst, since suggested dependencies are better. > > > You may need some extra text to explain why these dependencies ar

Re: [gentoo-dev] RFC: optinal run time dependencies

2011-07-18 Thread Markos Chandras
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 18/07/2011 05:02 ??, Ciaran McCreesh wrote: > On Mon, 18 Jul 2011 13:44:27 +0300 > Markos Chandras wrote: >> Whilst I like the new variable approach, I think this adds too much >> overhead to the already bloated ebuild writing. >> pkg_postinst me

Re: [gentoo-dev] RFC: optinal run time dependencies

2011-07-18 Thread Ciaran McCreesh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Mon, 18 Jul 2011 13:44:27 +0300 Markos Chandras wrote: > Whilst I like the new variable approach, I think this adds too much > overhead to the already bloated ebuild writing. > pkg_postinst messages include not only the optional dependencies but >

Re: [gentoo-dev] RFC: optinal run time dependencies

2011-07-18 Thread Markos Chandras
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 29/06/2011 05:27 ??, Donnie Berkholz wrote: > On 14:38 Tue 28 Jun , Peter Volkov wrote: >> 1. add a use flag to control runtime dependency >> 2. add elog message into pkg_postinst to notify users that some >> features depend on installing pac

Re: [gentoo-dev] Last rites: net-misc/dhcpv6

2011-07-18 Thread Markos Chandras
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 16/07/2011 02:41 πμ, Joshua Saddler wrote: > >> I can keep this package in the tree long enough until there is an >> alternative documentation available. My point is not to frustrate >> users but to "force" them migrate to better alternatives. Mo