Gentoo Archives: gentoo-hardened

From: "Javier Juan Martínez Cabezón" <tazok.id0@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Hardened meeting summary 2010-05-16
Date: Mon, 17 May 2010 08:35:34
Message-Id: AANLkTimLEZkvTq8QdcEtnphXv7LU5c4DOomdr0v6OBiS@mail.gmail.com
In Reply to: [gentoo-hardened] Hardened meeting summary 2010-05-16 by Magnus Granberg
1 I get realized of this question at the bad way, after seeing that the
2 binaries didn't have the canary inside. After that I compiled the system
3 with ssp in the unclean way, -fstack-protector-all in CFLAGS and CXXFLAGS in
4 make.conf with the exception of glibc that works only with
5 -fstack-protector. If someone need ssp with this versions it could be the
6 way to have it working until it gets solved.
7
8 ¿Do you recommend this "workaround" until solution?
9
10 1,0 Toolchain
11 > We have an open bug #318171 for the merge of SSP and GCC >=4.4.3 support.
12 > http://bugs.gentoo.org/show_bug.cgi?id=318171
13 > We are waiting for toolchain to approve the changes to toolchain.eclass
14 > and glibc that we need.
15 > Then we will have GCC 4.4.3 and 4.5.0 with full hardened (PIE/SSP) support
16 > in the tree.
17 > Grub need to be bumped to the new patchset.
18 > We have no time line on it for we are waiting on toolchain.
19 >
20 >

Replies

Subject Author
Re: [gentoo-hardened] Hardened meeting summary 2010-05-16 Magnus Granberg <zorry@g.o>