1 |
The page at http://www.gentoo.org/proj/en/hardened/propolice.xml |
2 |
suggests the following regarding SSP: |
3 |
|
4 |
"If you would the protection on by default add -fstack-protector to your |
5 |
CFLAGS in /etc/make.conf." |
6 |
|
7 |
However, this is contradicted by other pages on the hardened project |
8 |
website which say USE="hardened" is the correct way. Obviously |
9 |
USE="hardened" is correct (as it implies -fstack-protector-all), but the |
10 |
above could confuse people. |
11 |
|
12 |
I arrived at that page from the grsecurity/PaX documentation at |
13 |
http://www.gentoo.org/proj/en/hardened/grsecurity2.xml, I can't see it |
14 |
linked elsewhere but I haven't looked exhaustively. |
15 |
|
16 |
The rest of the documentation is great, it seems the Gentoo documents |
17 |
cover more than the grsecurity ones in some aspects. I've now got a |
18 |
kernel with PaX/grsecurity and I'm just rebuilding world to get SSP. |
19 |
|
20 |
David |
21 |
|
22 |
-- |
23 |
gentoo-hardened@g.o mailing list |