Gentoo Archives: gentoo-dev

From: Donnie Berkholz <spyderous@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: Modular X and hardened
Date: Sun, 14 May 2006 06:09:45
Message-Id: 4466C85A.8020109@gentoo.org
In Reply to: Re: [gentoo-dev] Re: Modular X and hardened by "Kevin F. Quinn (Gentoo)"
1 Kevin F. Quinn (Gentoo) wrote:
2 > The current solution (bail if -z,now is set in the compiler specs) is
3 > not one suggested by the hardened team, just need to make that clear,
4 > and it's not something we would encourage elsewhere. However until we
5 > can provide a solution for such a high-profile package we are not going
6 > to make a fuss.
7 >
8 > Our suggestion was to 'append-flags -nonow' on the server and video
9 > driver builds, but when a helpful user tried it, it wasn't enough -
10 > we simply haven't had the resource to work it out properly yet.
11
12 Oh, OK, let's argue semantics. It's suggested by a hardened user on a
13 bug the hardened team is CC'd on, but the team didn't say anything was
14 wrong with the change.
15
16 > With regards to Duncan's (non-hardened) problem, adding:
17 >
18 > filter-ldflags -Wl,-z,now
19 >
20 > to x-modular.eclass as he suggests should be fine; his issue is
21 > different to that with the hardened compiler in as much as he has added
22 > the '-Wl,-z,now' to LDFLAGS as advised by the QA message and the above
23 > filter will just remove it again; whereas to deal with the hardened
24 > compiler we need to reliably add a flag to all the relevant link
25 > commands (the bit that takes the effort is working out which are
26 > relevant).
27
28 Now I'm confused. Do you want this filter instead of the current
29 situation, in addition to, or what? This is exactly why I asked for a patch.
30
31 Thanks,
32 Donnie

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
[gentoo-dev] Re: Re: Modular X and hardened Duncan <1i5t5.duncan@×××.net>
Re: [gentoo-dev] Re: Modular X and hardened "Kevin F. Quinn (Gentoo)" <kevquinn@g.o>