1 |
On Sun, 2004-02-15 at 13:07, Eric P. wrote: |
2 |
> Hello, All: |
3 |
> |
4 |
> I'm emerge'ing a _new_ system and realized later that I *may* have made a |
5 |
> mistake: |
6 |
> |
7 |
> I added '-fstack-protector' to CFLAGS and began emerge'ing the |
8 |
> system without emerge'ing hardened-gcc first. |
9 |
> |
10 |
> According the the propolice.xml page, SSP has been included in gcc since |
11 |
> 3.2.3-r1 so - it is my understanding that - the '-fstack-protector' should |
12 |
> enhance the security of the system against buffer-overflows. But by not using |
13 |
> hardened-gcc, I'm concerned that I may have missed-out on a critical security |
14 |
> enhancement. |
15 |
|
16 |
You have. |
17 |
But without a kernel to support it would do little good. |
18 |
|
19 |
Should I re-emerge the entire system or just emerge hardened-gcc before |
20 |
> emerge'ing grsec-sources? |
21 |
|
22 |
The kernel has been known not to play along with hgcc at times so |
23 |
probably your best bet is building your kernel beforehand and then |
24 |
merging hardened-gcc then finishing it off with an emerge -e world |
25 |
|
26 |
good luck. |
27 |
|
28 |
> |
29 |
> Eric P. |
30 |
> Sunnyvale, CA |
31 |
> |
32 |
> -- |
33 |
> gentoo-hardened@g.o mailing list |
34 |
-- |
35 |
Ned Ludd <solar@g.o> |
36 |
Gentoo Linux Developer |