Gentoo Archives: gentoo-hardened

From: Ned Ludd <solar@g.o>
To: ericp@××.net
Cc: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Fwd: PaX, SSP, grsecurity, and whatnot
Date: Mon, 16 Feb 2004 07:02:27
Message-Id: 1076914604.21432.2516.camel@simple
In Reply to: [gentoo-hardened] Fwd: PaX, SSP, grsecurity, and whatnot by "Eric P."
1 On Sun, 2004-02-15 at 13:07, Eric P. wrote:
2 > Hello, All:
3 >
4 > I'm emerge'ing a _new_ system and realized later that I *may* have made a
5 > mistake:
6 >
7 > I added '-fstack-protector' to CFLAGS and began emerge'ing the
8 > system without emerge'ing hardened-gcc first.
9 >
10 > According the the propolice.xml page, SSP has been included in gcc since
11 > 3.2.3-r1 so - it is my understanding that - the '-fstack-protector' should
12 > enhance the security of the system against buffer-overflows. But by not using
13 > hardened-gcc, I'm concerned that I may have missed-out on a critical security
14 > enhancement.
15
16 You have.
17 But without a kernel to support it would do little good.
18
19 Should I re-emerge the entire system or just emerge hardened-gcc before
20 > emerge'ing grsec-sources?
21
22 The kernel has been known not to play along with hgcc at times so
23 probably your best bet is building your kernel beforehand and then
24 merging hardened-gcc then finishing it off with an emerge -e world
25
26 good luck.
27
28 >
29 > Eric P.
30 > Sunnyvale, CA
31 >
32 > --
33 > gentoo-hardened@g.o mailing list
34 --
35 Ned Ludd <solar@g.o>
36 Gentoo Linux Developer

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] Fwd: PaX, SSP, grsecurity, and whatnot "Eric P." <ericp@××.net>