1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
Peter Simons wrote: |
5 |
| Richard Laager writes: |
6 |
| |
7 |
| > Any pointers to instructions? |
8 |
| |
9 |
| I didn't bootstrap my system with hardened-gcc, so I guess I can't |
10 |
| help you there ... Sorry. |
11 |
| |
12 |
| Anyway, here is what I did: |
13 |
| |
14 |
| 1. scripts/bootstrap.sh |
15 |
| 2. enable -fstack-protector |
16 |
| 3. emerge system (plus network stuff, cron, etc.) |
17 |
| 4. emerge hardened-gcc |
18 |
| 5. emerge all the rest |
19 |
| |
20 |
| Then I re-compiled the core packages bit by bit. All that is left are |
21 |
| glibc and gcc, which coincidently have new versions anyway. That's why |
22 |
| I asked. :-) |
23 |
|
24 |
|
25 |
I ran into problems with new glibc and gcc and stack-protector; the |
26 |
default configuration (as well as the hardened-gentoo-stage3) cannot |
27 |
build static binaries. |
28 |
|
29 |
See http://bugs.gentoo.org/show_bug.cgi?id=25299 |
30 |
|
31 |
I would like to enable ProPolice for glibc but it results in a system |
32 |
that cannot "emerge system". |
33 |
|
34 |
- - boyd |
35 |
-----BEGIN PGP SIGNATURE----- |
36 |
Version: GnuPG v1.2.3 (GNU/Linux) |
37 |
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org |
38 |
|
39 |
iD8DBQE/jkj40is8k1r0QeURAvDJAJ9TbJ1J+o7ApE7NIx4lV9KsHUPm2ACdGbfd |
40 |
IE5d7J5yXzWUph4dM9M/NA0= |
41 |
=+5dL |
42 |
-----END PGP SIGNATURE----- |
43 |
|
44 |
|
45 |
-- |
46 |
gentoo-hardened@g.o mailing list |