On Sat, Mar 22, 2008 at 03:16:31AM -0700, Nicholas Miell wrote:Actually it is a relatively weak argument assuming the standard 4k xattrs, but still an issue. The other stronger argument against it is that larger xattrs tend to be outside the inode so you would have another seek again. Good joke. What signed binaries? Anyways there are two ways to deal with this: - Run the executable through a little filter that zeroes the bitmap before computing the checksum. That is how rpm -V deals with prelinked binaries which have a similar issue. You can probably reuse the scripts from rpm. - Disable the pbitmap header before you sign, either by never adding one or disabling it by turning the phdr type into a nop (should be very simple) -Andi --
| Ryan Hope | reiser4 for 2.6.27-rc1 |
| Ingo Molnar | Re: 2.6.24-rc6-mm1 |
| Tejun Heo | [PATCHSET] CUSE: implement CUSE |
| Peter Zijlstra | Re: 2.6.24-rc8-mm1 (BUG: sched_rt) |
git: | |
| Shawn O. Pearce | Re: [PATCH/POLL] git-format-patch: the default suffix is now .patch, not .txt |
| Jakub Narebski | Re: What's cooking in git.git (topics) |
| Junio C Hamano | Maintaining "needswork" section of "What's (not) cooking" |
| Matthias Lederhofer | [PATCH] prune-packed: new option --min-age=N |
| Theo de Raadt | That whole "Linux stealing our code" thing |
| Karthik Kumar | Re: Real men don't attack straw men |
| Khalid Schofield | Configuring sendmail openbsd 4.2 |
| Ray Percival | Re: Real men don't attack straw men |
| RW | Re: forcefsck on booting stage |
| Vladimir Terziev | Video memory as swap under FreeBSD |
| Ivan Voras | Progress for 7.0 - the "what's cooking" page |
| Pietro Cerutti | Re: [patch] enhance powerd(8) to handle max temperature |
