Gentoo Archives: gentoo-dev

From: Ryan Hill <dirtyepic@g.o>
To: gentoo-dev@l.g.o
Subject: [gentoo-dev] Re: Moving more hardening features to default?
Date: Fri, 21 Oct 2011 05:31:06
Message-Id: 20111020233920.7e022c4f@gentoo.org
In Reply to: Re: [gentoo-dev] Moving more hardening features to default? by "Anthony G. Basile"
1 On Thu, 20 Oct 2011 06:40:43 -0400
2 "Anthony G. Basile" <blueness@g.o> wrote:
3
4 > USE=hardened refers to only toolchain hardening. The problems there are
5 > mostly packages which break with PIE because they (ab)use assembly.
6 > Things like virtualbox and some codecs. This can become a thorny mess.
7 >
8 > It would probably be nearly painless to bring in -D_FORTIFY_SOURCES=2
9 > and ssp into mainstream though. Packages which break because of either
10 > of those two features are broken and should be fixed anyhow.
11
12 If any of these features (other than -D_FORTIFY_SOURCE) relies on spec rule
13 handling of preprocessor flags then I'd like you to try reimplementing them
14 another way. I'm going to hack 4.6 to work properly but I expect it to break
15 again with 4.7.
16
17
18 --
19 fonts, gcc-porting, it makes no sense how it makes no sense
20 toolchain, wxwidgets but i'll take it free anytime
21 @ gentoo.org EFFD 380E 047A 4B51 D2BD C64F 8AA8 8346 F9A4 0662

Attachments

File name MIME type
signature.asc application/pgp-signature