Gentoo Archives: gentoo-hardened

From: Michael Decker <MDecker@×××××.de>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Using PaX / Need to recompile whole gentoo?
Date: Wed, 05 Jul 2006 12:12:29
Message-Id: 44ABAB69.2010800@tesis.de
In Reply to: Re: [gentoo-hardened] Using PaX / Need to recompile whole gentoo? by Rumen Yotov
1 Thank you for your quick response!
2
3 >> I thought, if I use "hardened gentoo" sources, it would be compiled
4 >> with PIE/SSP, or not?
5 >>
6 >> But http://www.gentoo.org/proj/en/hardened/pax-quickstart.xml
7 >> tells: [...] So I start "emerge binutils gcc virtual/libc"... But
8 >> it take now more then three hours on my old machine and I think it
9 >> would take additional four or more hours... And I think "emerge -e
10 >> world" would take more time, or not?
11 >>
12 >> Is it really necessary to recompile that whole stuff?
13
14 > The name "hardened-sources" applies just to the kernel-sources, they
15 > are *hardened* so to say. To have a hardened (so to say) userland you
16 > need a hardened-toolchain and consequently this will result in having
17 > hardened userland programs (SSP,PIC,PIE) + PaX from the kernel. But
18 > better use a "hardened-stage3" tarball right from the install (less
19 > compilation).
20
21 Thank you very much. I was confused, because of section "5. Building a
22 PIE/SSP Enabled Userland", that tells I should do this. Even I use
23 hardened gentoo.
24
25 Could somebody recheck that section or the whole page? That would be nice.
26
27 Thanks a lot
28
29 Bye,
30 Michael Decker
31
32
33 --
34 Michael Decker Michael.Decker@×××××.de
35 TESIS SYSware GmbH http://www.tesis.de
36 Baierbrunnerstr. 15 * 81379 Muenchen * Tel. +49 89 747377-0
37
38 --
39 gentoo-hardened@g.o mailing list