Gentoo Archives: gentoo-hardened

From: David Cannings <lists@×××××.net>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Confusing documentation
Date: Tue, 30 Nov 2004 13:12:49
Message-Id: 41AC71AA.7040409@edeca.net
1 The page at http://www.gentoo.org/proj/en/hardened/propolice.xml
2 suggests the following regarding SSP:
3
4 "If you would the protection on by default add -fstack-protector to your
5 CFLAGS in /etc/make.conf."
6
7 However, this is contradicted by other pages on the hardened project
8 website which say USE="hardened" is the correct way. Obviously
9 USE="hardened" is correct (as it implies -fstack-protector-all), but the
10 above could confuse people.
11
12 I arrived at that page from the grsecurity/PaX documentation at
13 http://www.gentoo.org/proj/en/hardened/grsecurity2.xml, I can't see it
14 linked elsewhere but I haven't looked exhaustively.
15
16 The rest of the documentation is great, it seems the Gentoo documents
17 cover more than the grsecurity ones in some aspects. I've now got a
18 kernel with PaX/grsecurity and I'm just rebuilding world to get SSP.
19
20 David
21
22 --
23 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Confusing documentation Adam Mondl <tocharian@××××××.org>