Gentoo Archives: gentoo-hardened

From: Stefan SF <stefan@××××××.com>
To: Brandon Hale <tseng@g.o>
Cc: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Hardened (PIE/SSP) 2004.2 Beta - Get it while its hot!
Date: Wed, 09 Jun 2004 06:44:17
Message-Id: 20040609063835.GA17475@crux.sternplastic
In Reply to: [gentoo-hardened] Hardened (PIE/SSP) 2004.2 Beta - Get it while its hot! by Brandon Hale
1 Hi,
2
3 > DO NOT add -fstack-protector, -fPIC, etc to CFLAGS. These are provided
4 > by the gcc specfiles. DO NOT add USE=nptl or use 2.6 headers. Otherwise,
5 > go freakin nuts and test the hell out of these things.
6
7 I've still installed the "normal" gentoo system. But now I want to upgrade to hardened gentoo. The only thing I have to do putting "hardened" to the USE-flag. Is this right? You have wrote that the specfiles already include the -fstack-protector. Do I have to install the specfiles seperately or are they already installed by the normal installation of gcc etc?
8
9 cu, Stefan

Replies