3 ms·
Could they not have done something like how paxctl works on Linux? Such as globally enabling it but allowing for application specific control if you have to di
by ryuuchin 10y ago
Could they not have done something like how paxctl works on Linux? Such as globally enabling it but allowing for application specific control if you have to disable it (either through paxctl/xattr's or some policy file (rbac))?
To me that seems to make more sense than a global mount flag but I admit I'm not that knowledgeable about OpenBSD stuff. I suppose it's better late than never considering we've had this stuff in PaX since 2000[1].
[1] https://pax.grsecurity.net/docs/mprotect.txt https://pax.grsecurity.net/docs/mprotect.txt
- ben_bai 10y agoSince /usr/local is where all the packages are installed and by default it is a separate mount point, this is a acceptable first step. A ELF-header-flag to allow W|X on a per binary basis is in the works.