Gentoo Archives: gentoo-dev

From: "Tomáš Chvátal" <scarabeus@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Moving more hardening features to default?
Date: Thu, 20 Oct 2011 10:47:30
Message-Id: CA+NrkpdPq0cPxBwLoDzL=z==oyVy5aLdQiZH2Wfa2dyPQqwpjA@mail.gmail.com
In Reply to: Re: [gentoo-dev] Moving more hardening features to default? by "Anthony G. Basile"
1 2011/10/20 Anthony G. Basile <blueness@g.o>:
2
3 > USE=hardened refers to only toolchain hardening.  The problems there are
4 > mostly packages which break with PIE because they (ab)use assembly.
5 > Things like virtualbox and some codecs.  This can become a thorny mess.
6 >
7 > It would probably be nearly painless to bring in -D_FORTIFY_SOURCES=2
8 > and ssp into mainstream though.  Packages which break because of either
9 > of those two features are broken and should be fixed anyhow.
10 >
11
12 This sounds like good idea to do so,
13 I would say that most hardened features should be merged to to main
14 profile as soon as they won't cause major PITA for the regular users.
15
16 Cheers
17
18 Tom

Replies

Subject Author
Re: [gentoo-dev] Moving more hardening features to default? Rich Freeman <rich0@g.o>