1 |
måndag 17 maj 2010 22.28.05 skrev Ed W: |
2 |
> On 16/05/2010 21:20, Magnus Granberg wrote: |
3 |
> > Hi |
4 |
> > |
5 |
> > Here is the summary of the meeting 2010-05-16 |
6 |
> > |
7 |
> > 1,0 Toolchain |
8 |
> > We have an open bug #318171 for the merge of SSP and GCC>=4.4.3 |
9 |
> > support. http://bugs.gentoo.org/show_bug.cgi?id=318171 |
10 |
> > We are waiting for toolchain to approve the changes to toolchain.eclass |
11 |
> > and glibc that we need. Then we will have GCC 4.4.3 and 4.5.0 with full |
12 |
> > hardened (PIE/SSP) support in the tree. Grub need to be bumped to the new |
13 |
> > patchset. |
14 |
> > We have no time line on it for we are waiting on toolchain. |
15 |
> |
16 |
> I see a comment in there: "Cleaned some code and removed SSP support for |
17 |
> gcc 4.3.X " - I think this might need some watching and perhaps a |
18 |
> warning here? Sounds like if you now update say a "stable" hardened |
19 |
> amd64 machine pulling in stable gcc 4.3.X then you might be suddenly |
20 |
> loosing your hardened compiler? |
21 |
> |
22 |
> I understand this is avoided if using your overlay, but it seems like a |
23 |
> potential pitfall for anyone using the "stable" hardened tree? |
24 |
> |
25 |
> Can anyone comment if this is the case or I'm worrying over nothing? |
26 |
> |
27 |
> Ta |
28 |
> |
29 |
> Ed W |
30 |
> |
31 |
I only removed the code for default enable option for SSP. GCC 4.3.X still |
32 |
support SSP if you add -fstack-protector. The GCC 4.4.3 is on the way to get |
33 |
stable in 1-4 weeks i hope. Is up to the archs teams now to mark it stablel. |
34 |
|
35 |
Hardened at gentoo.org |
36 |
Magnus Granberg (Zorry) |