<div dir="ltr">Hi jow,<br><div><div class="gmail_extra"><br><div class="gmail_quote">2015-02-10 11:20 GMT+01:00 Jo-Philipp Wich <span dir="ltr"><<a href="mailto:jow@openwrt.org" target="_blank">jow@openwrt.org</a>></span>:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi Etienne,<br>
<br>
so we should keep rpaths below /usr/lib/ or /lib/ and remove everything<br>
else including exactly /usr/lib and /lib (with or without trailing /) ?<br>
<br>
~ Jow<br>
<br></blockquote></div><br></div><div class="gmail_extra">I think so yes, i'm in favor of white list approach here.<br></div><div class="gmail_extra">we may also allow $ORIGIN/* (no package seems to use it but why not)<br><br>According to my extract (rpath.txt)(all ar71xx packages minus ~20),<br>we are not breaking any package for now.<br></div><div class="gmail_extra">(or maybe just kamailo, which use "///usr/lib/kamailio/")<br><br></div><div class="gmail_extra">see also<br><a href="https://wiki.debian.org/RpathIssue#Debian.27s_Stance">https://wiki.debian.org/RpathIssue#Debian.27s_Stance</a><br></div><div class="gmail_extra"><br></div><div class="gmail_extra">Etienne<br></div></div></div>