From e6f4e9171c5dc7d567e1fd3cbfd6514d0b069d65 Mon Sep 17 00:00:00 2001 From: Ralph Sennhauser Date: Mon, 21 Nov 2011 10:15:46 +0000 Subject: [PATCH] Move handling of PaX marking JVM executables to eclass. --- eclass/ChangeLog | 5 ++++- eclass/java-vm-2.eclass | 38 ++++++++++++++++++++++++++++++++++++-- 2 files changed, 40 insertions(+), 3 deletions(-) diff --git a/eclass/ChangeLog b/eclass/ChangeLog index bd412d605a59..3394c06f04c3 100644 --- a/eclass/ChangeLog +++ b/eclass/ChangeLog @@ -1,6 +1,9 @@ # ChangeLog for eclass directory # Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2 -# $Header: /var/cvsroot/gentoo-x86/eclass/ChangeLog,v 1.21 2011/11/21 01:43:44 dirtyepic Exp $ +# $Header: /var/cvsroot/gentoo-x86/eclass/ChangeLog,v 1.22 2011/11/21 10:15:46 sera Exp $ + + 21 Nov 2011; Ralph Sennhauser java-vm-2.eclass: + Move handling of PaX marking JVM executables to eclass. 21 Nov 2011; Ryan Hill toolchain.eclass: Fix live ebuilds. diff --git a/eclass/java-vm-2.eclass b/eclass/java-vm-2.eclass index c66ef8431d47..0f993874b23a 100644 --- a/eclass/java-vm-2.eclass +++ b/eclass/java-vm-2.eclass @@ -1,6 +1,6 @@ # Copyright 1999-2011 Gentoo Foundation # Distributed under the terms of the GNU General Public License v2 -# $Header: /var/cvsroot/gentoo-x86/eclass/java-vm-2.eclass,v 1.38 2011/11/15 09:02:15 caster Exp $ +# $Header: /var/cvsroot/gentoo-x86/eclass/java-vm-2.eclass,v 1.39 2011/11/21 10:15:46 sera Exp $ # ----------------------------------------------------------------------------- # @eclass-begin @@ -12,7 +12,7 @@ # # ----------------------------------------------------------------------------- -inherit eutils fdo-mime multilib prefix +inherit eutils fdo-mime multilib pax-utils prefix DEPEND="=dev-java/java-config-2*" has "${EAPI}" 0 1 && DEPEND="${DEPEND} >=sys-apps/portage-2.1" @@ -174,6 +174,40 @@ set_java_env() { || die "Failed to make VM symlink at ${JAVA_VM_DIR}/${VMHANDLE}" } +# ----------------------------------------------------------------------------- +# @ebuild-function java-vm_set-pax-markings +# +# Set PaX markings on all JDK/JRE executables to allow code-generation on +# the heap by the JIT compiler. +# +# The markings need to be set prior to the first invocation of the the freshly +# built / installed VM. Be it before creating the Class Data Sharing archive or +# generating cacerts. Otherwise a PaX enabled kernel will kill the VM. +# Bug #215225 #389751 +# +# @example +# java-vm_set-pax-markings "${S}" +# java-vm_set-pax-markings "${ED}"/opt/${P} +# +# @param $1 - JDK/JRE base directory. +# ----------------------------------------------------------------------------- +java-vm_set-pax-markings() { + debug-print-function ${FUNCNAME} "$*" + [[ $# -ne 1 ]] && die "${FUNCNAME}: takes exactly one argument" + [[ ! -f "${1}"/bin/java ]] \ + && die "${FUNCNAME}: argument needs to be JDK/JRE base directory" + + local executables=( "${1}"/bin/* ) + [[ -d "${1}"/jre ]] && executables+=( "${1}"/jre/bin/* ) + + # Usally disabeling MPROTECT is sufficent + local pax_markings="m" + # On x86 for heap sizes over 700MB disable SEGMEXEC and PAGEEXEC as well. + use x86 && pax_markings="msp" + + pax-mark ${pax_markings} $(list-paxables "${executables[@]}") +} + # ----------------------------------------------------------------------------- # @ebuild-function java-vm_revdep-mask # -- 2.26.2