1 |
Hi, |
2 |
|
3 |
i'm confused. Perhaps somebody could help me, please. |
4 |
|
5 |
I thought, if I use "hardened gentoo" sources, it would be compiled with |
6 |
PIE/SSP, or not? |
7 |
|
8 |
But http://www.gentoo.org/proj/en/hardened/pax-quickstart.xml tells: |
9 |
|
10 |
--- SNIP --- |
11 |
5. Building a PIE/SSP Enabled Userland |
12 |
Hardened Gentoo has added support for transparent PIE/SSP building via |
13 |
GCC's specfile. This means that any users upgrading an older Hardened |
14 |
install should remove any LDFLAGS or CFLAGS used to trigger PIE/SSP. |
15 |
Also, the hardened-gcc package is now deprecated and should be unmerged |
16 |
(version 5.0 is a dummy package). To get the current GCC, add |
17 |
USE="hardened pic" to /etc/make.conf if not using the hardened profile. |
18 |
To maintain a consistant toolchain, first emerge binutils gcc |
19 |
virtual/libc. Next, rebuild the entire system with emerge -e world. All |
20 |
future packages will be built with PIE/SSP. |
21 |
--- SNAP --- |
22 |
|
23 |
So I start "emerge binutils gcc virtual/libc"... But it take now more |
24 |
then three hours on my old machine and I think it would take additional |
25 |
four or more hours... And I think "emerge -e world" would take more |
26 |
time, or not? |
27 |
|
28 |
Is it really necessary to recompile that whole stuff? |
29 |
|
30 |
Thanks a lot. |
31 |
|
32 |
Bye, |
33 |
Mike |
34 |
-- |
35 |
Michael Decker Michael.Decker@×××××.de |
36 |
TESIS SYSware GmbH http://www.tesis.de |
37 |
Baierbrunnerstr. 15 * 81379 Muenchen * Tel. +49 89 747377-0 |
38 |
|
39 |
-- |
40 |
gentoo-hardened@g.o mailing list |