Gentoo Archives: gentoo-hardened

From: Brant Williams <brant@×××××.net>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Upgrading GCC in hardened
Date: Fri, 10 Nov 2006 07:49:24
Message-Id: Pine.LNX.4.64.0611100143270.20457@surreal.mirage.org
In Reply to: [gentoo-hardened] Upgrading GCC in hardened by Derrick Hendricks
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4
5
6 If you are running the "hardened" profile, you will automatically be using
7 the hardened compiler. You need not be a developer to use it. Gentoo
8 uses the GCC spec file to make the change transparent.
9
10 What are some of the "out of date" messages that you get? Also, what does
11 `emerge --info` show you?
12
13
14 Public GPG/PGP key for Brant Williams: 0x88E1AA9E.
15 Available at your friendly local public keyserver.
16
17
18
19 On Thu, 9 Nov 2006, Derrick Hendricks wrote:
20
21 > I'm running a firewall for our work network using hardened gentoo.
22 > Emerges have been working fine until now. I'm getting errors in the
23 > builds saying that my gcc is out of date. I've upgraded other machines
24 > that had this problem, and had no real problems in the upgrade.
25 >
26 > However, in looking at a gcc-config -l, I noticed that I'm using the
27 > 3.3.6 compiler, and not the hardened version. I have choices of other
28 > compilers that I could upgrade to. Some of them being the hardened
29 > varieties. So, I'm wondering which kernel I should upgrade to.
30 >
31 > I seem to remember reading from before that you should not use a
32 > hardened compiler unless you are a developer. I don't remember where,
33 > but I think that's why I'm not using the hardened version of the current
34 > compiler.
35 >
36 > Here are my kernel choices:
37 > [1] i686-pc-linux-gnu-3.3.6 *
38 > [2] i686-pc-linux-gnu-3.3.6-hardened
39 > [3] i686-pc-linux-gnu-3.3.6-hardenednopie
40 > [4] i686-pc-linux-gnu-3.3.6-hardenednopiessp
41 > [5] i686-pc-linux-gnu-3.3.6-hardenednossp
42 > [6] i686-pc-linux-gnu-3.4.6
43 > [7] i686-pc-linux-gnu-3.4.6-hardened
44 > [8] i686-pc-linux-gnu-3.4.6-hardenednopie
45 > [9] i686-pc-linux-gnu-3.4.6-hardenednopiessp
46 > [10] i686-pc-linux-gnu-3.4.6-hardenednossp
47 > [11] i686-pc-linux-gnu-4.1.1
48 >
49 >
50 > Which one should I upgrade to?
51 >
52 > --
53 > gentoo-hardened@g.o mailing list
54 >
55 -----BEGIN PGP SIGNATURE-----
56 Version: GnuPG v1.4.5 (GNU/Linux)
57
58 iD8DBQFFVC6GYfOV94jhqp4RAjuDAKCIIrA/6qSx7RV6qV/hZewDHyEZhQCgp3kb
59 BATS7paYaU4iQuY4ZolyIeI=
60 =MPiH
61 -----END PGP SIGNATURE-----
62 --
63 gentoo-hardened@g.o mailing list