aboutsummaryrefslogtreecommitdiff
path: root/doc
diff options
context:
space:
mode:
authorAnthony G. Basile <blueness@gentoo.org>2014-07-30 17:17:25 -0400
committerAnthony G. Basile <blueness@gentoo.org>2014-07-30 17:17:25 -0400
commit774ce372e0a21e58541d34035ed15903b4b5b34a (patch)
treeb9afd5764c222ffff052e7ce8b8e5e5ecf766fac /doc
parentSplit misc/ into misc/ for production and poc/ for experimental stuff. (diff)
downloadelfix-774ce372e0a21e58541d34035ed15903b4b5b34a.tar.gz
elfix-774ce372e0a21e58541d34035ed15903b4b5b34a.tar.bz2
elfix-774ce372e0a21e58541d34035ed15903b4b5b34a.zip
Refactor source tree: separate out fix-gnustack
Diffstat (limited to 'doc')
-rw-r--r--doc/Makefile.am8
-rw-r--r--doc/fix-gnustack.1172
-rw-r--r--doc/fix-gnustack.pod54
-rwxr-xr-xdoc/make.sh22
-rw-r--r--doc/paxctl-ng.14
-rw-r--r--doc/revdep-pax.14
6 files changed, 11 insertions, 253 deletions
diff --git a/doc/Makefile.am b/doc/Makefile.am
index 836014b..4ce1847 100644
--- a/doc/Makefile.am
+++ b/doc/Makefile.am
@@ -1,11 +1,3 @@
ACLOCAL_AMFLAGS = -I m4
dist_man_MANS = paxctl-ng.1 revdep-pax.1
-if BUILD_ELF
-dist_man_MANS += fix-gnustack.1
-endif
-
-# I don't know why I need this, but without it, I don't get fix-gnustack.1 distributed.
-# This is since commit 414cfa1770a8cfc46308149deecf9c0eef60a5bb. It will be fixed once
-# fix-gnustack is broken out.
-EXTRA_DIST = fix-gnustack.1
diff --git a/doc/fix-gnustack.1 b/doc/fix-gnustack.1
deleted file mode 100644
index 3ef26eb..0000000
--- a/doc/fix-gnustack.1
+++ /dev/null
@@ -1,172 +0,0 @@
-.\" Automatically generated by Pod::Man 2.23 (Pod::Simple 3.14)
-.\"
-.\" Standard preamble:
-.\" ========================================================================
-.de Sp \" Vertical space (when we can't use .PP)
-.if t .sp .5v
-.if n .sp
-..
-.de Vb \" Begin verbatim text
-.ft CW
-.nf
-.ne \\$1
-..
-.de Ve \" End verbatim text
-.ft R
-.fi
-..
-.\" Set up some character translations and predefined strings. \*(-- will
-.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left
-.\" double quote, and \*(R" will give a right double quote. \*(C+ will
-.\" give a nicer C++. Capital omega is used to do unbreakable dashes and
-.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff,
-.\" nothing in troff, for use with C<>.
-.tr \(*W-
-.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p'
-.ie n \{\
-. ds -- \(*W-
-. ds PI pi
-. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch
-. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch
-. ds L" ""
-. ds R" ""
-. ds C` ""
-. ds C' ""
-'br\}
-.el\{\
-. ds -- \|\(em\|
-. ds PI \(*p
-. ds L" ``
-. ds R" ''
-'br\}
-.\"
-.\" Escape single quotes in literal strings from groff's Unicode transform.
-.ie \n(.g .ds Aq \(aq
-.el .ds Aq '
-.\"
-.\" If the F register is turned on, we'll generate index entries on stderr for
-.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index
-.\" entries marked with X<> in POD. Of course, you'll have to process the
-.\" output yourself in some meaningful fashion.
-.ie \nF \{\
-. de IX
-. tm Index:\\$1\t\\n%\t"\\$2"
-..
-. nr % 0
-. rr F
-.\}
-.el \{\
-. de IX
-..
-.\}
-.\"
-.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2).
-.\" Fear. Run. Save yourself. No user-serviceable parts.
-. \" fudge factors for nroff and troff
-.if n \{\
-. ds #H 0
-. ds #V .8m
-. ds #F .3m
-. ds #[ \f1
-. ds #] \fP
-.\}
-.if t \{\
-. ds #H ((1u-(\\\\n(.fu%2u))*.13m)
-. ds #V .6m
-. ds #F 0
-. ds #[ \&
-. ds #] \&
-.\}
-. \" simple accents for nroff and troff
-.if n \{\
-. ds ' \&
-. ds ` \&
-. ds ^ \&
-. ds , \&
-. ds ~ ~
-. ds /
-.\}
-.if t \{\
-. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u"
-. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u'
-. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u'
-. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u'
-. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u'
-. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u'
-.\}
-. \" troff and (daisy-wheel) nroff accents
-.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V'
-.ds 8 \h'\*(#H'\(*b\h'-\*(#H'
-.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#]
-.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H'
-.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u'
-.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#]
-.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#]
-.ds ae a\h'-(\w'a'u*4/10)'e
-.ds Ae A\h'-(\w'A'u*4/10)'E
-. \" corrections for vroff
-.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u'
-.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u'
-. \" for low resolution devices (crt and lpr)
-.if \n(.H>23 .if \n(.V>19 \
-\{\
-. ds : e
-. ds 8 ss
-. ds o a
-. ds d- d\h'-1'\(ga
-. ds D- D\h'-1'\(hy
-. ds th \o'bp'
-. ds Th \o'LP'
-. ds ae ae
-. ds Ae AE
-.\}
-.rm #[ #] #H #V #F C
-.\" ========================================================================
-.\"
-.IX Title "FIX-GNUSTACK 1"
-.TH FIX-GNUSTACK 1 "2011-04-14" "elfix 0.3" "Documentation for elfix"
-.\" For nroff, turn off justification. Always turn off hyphenation; it makes
-.\" way too many mistakes in technical documents.
-.if n .ad l
-.nh
-.SH "NAME"
-fix\-gnustack \- query or clear any ELF GNU_STACK executable flag
-.SH "SYNOPSIS"
-.IX Header "SYNOPSIS"
-\&\fBfix-gnustack\fR \-h
-.PP
-\&\fBfix-gnustack\fR [\-f] \s-1ELF\s0
-.SH "DESCRIPTION"
-.IX Header "DESCRIPTION"
-\&\fBfix-gnustack\fR scans the program headers of an \s-1ELF\s0 binary or shared
-object library, reports if it has a \s-1GNU_STACK\s0 entry and if it is
-marked both writeable and executable. On PaX hardened kernels where
-memory protection (\s-1MPROTECT\s0) is enforced, execution of binaries with
-\&\s-1GNU_STACKS\s0 marked \s-1WX\s0, or execution of binaries linking against libraries
-with \s-1GNU_STACKS\s0 marked \s-1WX\s0, is terminated by the kernel. When \fBfix-gnustack\fR
-is called without the \fB\-f\fR option on an \s-1ELF\s0, it simply reports the
-\&\s-1RWX\s0 (read/write/execute) flags on any \s-1GNU_STACK\s0 entry found. When called
-with \fB\-f\fR, it clears the X flag if a \s-1GNU_STACK\s0 entry is found and it
-has both W and X flags.
-.SH "OPTIONS"
-.IX Header "OPTIONS"
-.IP "\fB\-h\fR" 4
-.IX Item "-h"
-Print out a short help message and exit.
-.IP "[\fB\-f\fR] \s-1ELF\s0" 4
-.IX Item "[-f] ELF"
-\&\*(L"Fix\*(R" the \s-1ELF\s0, ie, remove the X flag from any \s-1GNU_STACK\s0 entry found
-if it has both W and X flags. When called without, it simply reports
-what flags it found.
-.SH "HOMEPAGE"
-.IX Header "HOMEPAGE"
-http://www.gentoo.org/proj/en/hardened/pax\-quickstart.xml
-.SH "REPORTING BUGS"
-.IX Header "REPORTING BUGS"
-Please report bugs at http://bugs.gentoo.org.
-.SH "SEE ALSO"
-.IX Header "SEE ALSO"
-\&\fBscanelf\fR(1), \fBdumpelf\fR(1), \fBpaxctl\fR(1), \fBpaxctl-ng\fR(1), \fBpspax\fR(1).
-.SH "AUTHORS"
-.IX Header "AUTHORS"
-\&\fBAnthony G. Basile\fR <blueness@gentoo.org>
diff --git a/doc/fix-gnustack.pod b/doc/fix-gnustack.pod
deleted file mode 100644
index d94b8b4..0000000
--- a/doc/fix-gnustack.pod
+++ /dev/null
@@ -1,54 +0,0 @@
-=head1 NAME
-
-B<fix-gnustack> - query or clear any ELF GNU_STACK executable flag
-
-=head1 SYNOPSIS
-
-B<fix-gnustack> -h
-
-B<fix-gnustack> [-f] ELF
-
-=head1 DESCRIPTION
-
-B<fix-gnustack> scans the program headers of an ELF binary or shared
-object library, reports if it has a GNU_STACK entry and if it is
-marked both writeable and executable. On PaX hardened kernels where
-memory protection (MPROTECT) is enforced, execution of binaries with
-GNU_STACKS marked WX, or execution of binaries linking against libraries
-with GNU_STACKS marked WX, is terminated by the kernel. When B<fix-gnustack>
-is called without the B<-f> option on an ELF, it simply reports the
-RWX (read/write/execute) flags on any GNU_STACK entry found. When called
-with B<-f>, it clears the X flag if a GNU_STACK entry is found and it
-has both W and X flags.
-
-=head1 OPTIONS
-
-=over
-
-=item B<-h>
-
-Print out a short help message and exit.
-
-=item [B<-f>] ELF
-
-"Fix" the ELF, ie, remove the X flag from any GNU_STACK entry found
-if it has both W and X flags. When called without, it simply reports
-what flags it found.
-
-=back
-
-=head1 HOMEPAGE
-
-http://www.gentoo.org/proj/en/hardened/pax-quickstart.xml
-
-=head1 REPORTING BUGS
-
-Please report bugs at http://bugs.gentoo.org.
-
-=head1 SEE ALSO
-
-B<scanelf>(1), B<dumpelf>(1), B<paxctl>(1), B<paxctl-ng>(1), B<pspax>(1).
-
-=head1 AUTHORS
-
-B<Anthony G. Basile> <blueness@gentoo.org>
diff --git a/doc/make.sh b/doc/make.sh
index bf29d22..a330f17 100755
--- a/doc/make.sh
+++ b/doc/make.sh
@@ -17,31 +17,23 @@
# along with this program. If not, see <http://www.gnu.org/licenses/>.
#
-#Run this on developer side, and distribute troff
-#in case the end user doesn't have pod2man
+# This is run on the developer side with autogen.sh
-rm -f fix-gnustack.1
+PKG=$(cat ../configure.ac | grep ^AC_INIT | sed -e 's/^.*(\[//' -e 's/\].*$//')
+VERSION=$(cat ../configure.ac | grep ^AC_INIT | sed -e "s/^.*$PKG\], \[//" -e 's/\].*$//')
pod2man \
--official \
--section="1" \
- --release="elfix 0.3" \
+ --release="$PKG $VERSION" \
--center="Documentation for elfix" \
- --date="2011-04-14" \
- fix-gnustack.pod > fix-gnustack.1
-
-pod2man \
- --official \
- --section="1" \
- --release="elfix 0.3" \
- --center="Documentation for elfix" \
- --date="2011-08-18" \
+ --date=$(date +%Y-%m-%d) \
paxctl-ng.pod > paxctl-ng.1
pod2man \
--official \
--section="1" \
- --release="elfix 0.3" \
+ --release="$PKG $VERSION" \
--center="Documentation for elfix" \
- --date="2011-10-19" \
+ --date=$(date +%Y-%m-%d) \
revdep-pax.pod > revdep-pax.1
diff --git a/doc/paxctl-ng.1 b/doc/paxctl-ng.1
index 744184b..5cb923a 100644
--- a/doc/paxctl-ng.1
+++ b/doc/paxctl-ng.1
@@ -1,4 +1,4 @@
-.\" Automatically generated by Pod::Man 2.23 (Pod::Simple 3.14)
+.\" Automatically generated by Pod::Man 2.25 (Pod::Simple 3.23)
.\"
.\" Standard preamble:
.\" ========================================================================
@@ -124,7 +124,7 @@
.\" ========================================================================
.\"
.IX Title "PAXCTL-NG 1"
-.TH PAXCTL-NG 1 "2011-08-18" "elfix 0.3" "Documentation for elfix"
+.TH PAXCTL-NG 1 "2014-07-30" "elfix 0.9" "Documentation for elfix"
.\" For nroff, turn off justification. Always turn off hyphenation; it makes
.\" way too many mistakes in technical documents.
.if n .ad l
diff --git a/doc/revdep-pax.1 b/doc/revdep-pax.1
index 58568fa..ee7cfd5 100644
--- a/doc/revdep-pax.1
+++ b/doc/revdep-pax.1
@@ -1,4 +1,4 @@
-.\" Automatically generated by Pod::Man 2.23 (Pod::Simple 3.14)
+.\" Automatically generated by Pod::Man 2.25 (Pod::Simple 3.23)
.\"
.\" Standard preamble:
.\" ========================================================================
@@ -124,7 +124,7 @@
.\" ========================================================================
.\"
.IX Title "REVDEP-PAX 1"
-.TH REVDEP-PAX 1 "2011-10-19" "elfix 0.3" "Documentation for elfix"
+.TH REVDEP-PAX 1 "2014-07-30" "elfix 0.9" "Documentation for elfix"
.\" For nroff, turn off justification. Always turn off hyphenation; it makes
.\" way too many mistakes in technical documents.
.if n .ad l