Gentoo Archives: gentoo-hardened

From: "Eric P." <ericp@××.net>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Fwd: PaX, SSP, grsecurity, and whatnot
Date: Mon, 16 Feb 2004 01:56:44
Message-Id: 200402151807.55241.ericp@he.net
1 Hello, All:
2
3 I'm emerge'ing a _new_ system and realized later that I *may* have made a
4 mistake:
5
6 I added '-fstack-protector' to CFLAGS and began emerge'ing the
7 system without emerge'ing hardened-gcc first.
8
9 According the the propolice.xml page, SSP has been included in gcc since
10 3.2.3-r1 so - it is my understanding that - the '-fstack-protector' should
11 enhance the security of the system against buffer-overflows. But by not using
12 hardened-gcc, I'm concerned that I may have missed-out on a critical security
13 enhancement.
14
15 Should I re-emerge the entire system or just emerge hardened-gcc before
16 emerge'ing grsec-sources?
17
18 Eric P.
19 Sunnyvale, CA
20
21 --
22 gentoo-hardened@g.o mailing list

Replies