Move handling of PaX marking JVM executables to eclass.
authorRalph Sennhauser <sera@gentoo.org>
Mon, 21 Nov 2011 10:15:46 +0000 (10:15 +0000)
committerRalph Sennhauser <sera@gentoo.org>
Mon, 21 Nov 2011 10:15:46 +0000 (10:15 +0000)
eclass/ChangeLog
eclass/java-vm-2.eclass

index bd412d605a5959220685fd90d0ae80eadecacc40..3394c06f04c3ea7e2513114eef582f1d094a746b 100644 (file)
@@ -1,6 +1,9 @@
 # ChangeLog for eclass directory
 # Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/eclass/ChangeLog,v 1.21 2011/11/21 01:43:44 dirtyepic Exp $
+# $Header: /var/cvsroot/gentoo-x86/eclass/ChangeLog,v 1.22 2011/11/21 10:15:46 sera Exp $
+
+  21 Nov 2011; Ralph Sennhauser <sera@gentoo.org> java-vm-2.eclass:
+  Move handling of PaX marking JVM executables to eclass.
 
   21 Nov 2011; Ryan Hill <dirtyepic@gentoo.org> toolchain.eclass:
   Fix live ebuilds.
index c66ef8431d471b51d014f670978636b7a3b21fff..0f993874b23a458c43485a9ef047db55f93fa3ec 100644 (file)
@@ -1,6 +1,6 @@
 # Copyright 1999-2011 Gentoo Foundation
 # Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/eclass/java-vm-2.eclass,v 1.38 2011/11/15 09:02:15 caster Exp $
+# $Header: /var/cvsroot/gentoo-x86/eclass/java-vm-2.eclass,v 1.39 2011/11/21 10:15:46 sera Exp $
 
 # -----------------------------------------------------------------------------
 # @eclass-begin
@@ -12,7 +12,7 @@
 #
 # -----------------------------------------------------------------------------
 
-inherit eutils fdo-mime multilib prefix
+inherit eutils fdo-mime multilib pax-utils prefix
 
 DEPEND="=dev-java/java-config-2*"
 has "${EAPI}" 0 1 && DEPEND="${DEPEND} >=sys-apps/portage-2.1"
@@ -174,6 +174,40 @@ set_java_env() {
                || die "Failed to make VM symlink at ${JAVA_VM_DIR}/${VMHANDLE}"
 }
 
+# -----------------------------------------------------------------------------
+# @ebuild-function java-vm_set-pax-markings
+#
+# Set PaX markings on all JDK/JRE executables to allow code-generation on
+# the heap by the JIT compiler.
+# 
+# The markings need to be set prior to the first invocation of the the freshly
+# built / installed VM. Be it before creating the Class Data Sharing archive or
+# generating cacerts. Otherwise a PaX enabled kernel will kill the VM.
+# Bug #215225 #389751
+#
+# @example
+#   java-vm_set-pax-markings "${S}"
+#   java-vm_set-pax-markings "${ED}"/opt/${P}
+#
+# @param $1 - JDK/JRE base directory.
+# -----------------------------------------------------------------------------
+java-vm_set-pax-markings() {
+       debug-print-function ${FUNCNAME} "$*"
+       [[ $# -ne 1 ]] && die "${FUNCNAME}: takes exactly one argument"
+       [[ ! -f "${1}"/bin/java ]] \
+               && die "${FUNCNAME}: argument needs to be JDK/JRE base directory"
+
+       local executables=( "${1}"/bin/* )
+       [[ -d "${1}"/jre ]] && executables+=( "${1}"/jre/bin/* )
+
+       # Usally disabeling MPROTECT is sufficent
+       local pax_markings="m"
+       # On x86 for heap sizes over 700MB disable SEGMEXEC and PAGEEXEC as well.
+       use x86 && pax_markings="msp"
+
+       pax-mark ${pax_markings} $(list-paxables "${executables[@]}")
+}
+
 # -----------------------------------------------------------------------------
 # @ebuild-function java-vm_revdep-mask
 #