Gentoo Archives: gentoo-dev

From: Steven J Long <slong@××××××××××××××××××.uk>
To: gentoo-dev@l.g.o
Subject: [gentoo-dev] Re: Moving more hardening features to default?
Date: Sun, 23 Oct 2011 03:53:29
Message-Id: j8031i$846$1@dough.gmane.org
In Reply to: Re: [gentoo-dev] Moving more hardening features to default? by Magnus Granberg
1 Magnus Granberg wrote:
2
3 > It's hard to keep the patches up to date when they
4 > are not maintained upstream.
5 >
6 > There are about 30 packages which have problems with PIE. We either add
7 > patch to these or else use filter-flags on them.
8
9 Sounds perfectly reasonable just to filter those, and not give yourself the
10 maintenance burden.
11
12 Will we be able to switch off SSP via config, or will we have to setup our
13 own profile?
14
15 (Since PIE has minimal performance burden on AMD64, and won't be default
16 elsewhere it doesn't seem like a concern.)
17 --
18 #friendly-coders -- We're friendly, but we're not /that/ friendly ;-)

Replies

Subject Author
Re: [gentoo-dev] Re: Moving more hardening features to default? "Paweł Hajdan
Re: [gentoo-dev] Re: Moving more hardening features to default? "Francisco Blas Izquierdo Riera (klondike)" <klondike@g.o>