1 |
On Tue, 03 Oct 2006 22:32:52 +0200 |
2 |
Marek Wróbel <smbmarek@×××××××××××.pl> wrote: |
3 |
|
4 |
> Chris PeBenito wrote: |
5 |
> > Glibc 2.4 and gcc 4.1 being masked is because the |
6 |
> > hardened compiler is not available in gcc yet. |
7 |
> |
8 |
> Do you know what is current status of hardened GCC 4.* ? |
9 |
> Is there any hope that it will be available in next few months ? |
10 |
|
11 |
Yes. It's work in progress at the moment. We'll post a notice here |
12 |
when it becomes available. |
13 |
|
14 |
> I have tried to search GCC site, but I haven't found anything |
15 |
> interesting. There is no real development roadmap and it is very hard |
16 |
> to find anything about SSP. |
17 |
|
18 |
"Hardened GCC" is a Gentoo thing where we change the normal default |
19 |
settings of the compiler - it has nothing to do with upstream GCC so |
20 |
you won't see any mention of it on the GCC website. |
21 |
|
22 |
> On the other hand, Wikipedia |
23 |
> (http://en.wikipedia.org/wiki/Stack-smashing_protection) and official |
24 |
> ProPolice site |
25 |
> (http://www.research.ibm.com/trl/projects/security/ssp/) say that GCC |
26 |
> 4.1 contains reimplementation of SSP. |
27 |
|
28 |
That is correct. However SSP is not switched on by default in the |
29 |
normal compiler (that is part of what the "Gentoo Hardened GCC" does). |
30 |
|
31 |
> So after hour of reading I am really confused and I would be very |
32 |
> grateful if you could write something about it. |
33 |
|
34 |
To understand the hardened toolchain, read through |
35 |
http://www.gentoo.org/proj/en/hardened/hardened-toolchain.xml |
36 |
|
37 |
-- |
38 |
Kevin F. Quinn |