Gentoo Archives: gentoo-hardened

From: Michael Decker <MDecker@×××××.de>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Using PaX / Need to recompile whole gentoo?
Date: Wed, 05 Jul 2006 11:30:55
Message-Id: 44ABA1E0.3050808@tesis.de
1 Hi,
2
3 i'm confused. Perhaps somebody could help me, please.
4
5 I thought, if I use "hardened gentoo" sources, it would be compiled with
6 PIE/SSP, or not?
7
8 But http://www.gentoo.org/proj/en/hardened/pax-quickstart.xml tells:
9
10 --- SNIP ---
11 5. Building a PIE/SSP Enabled Userland
12 Hardened Gentoo has added support for transparent PIE/SSP building via
13 GCC's specfile. This means that any users upgrading an older Hardened
14 install should remove any LDFLAGS or CFLAGS used to trigger PIE/SSP.
15 Also, the hardened-gcc package is now deprecated and should be unmerged
16 (version 5.0 is a dummy package). To get the current GCC, add
17 USE="hardened pic" to /etc/make.conf if not using the hardened profile.
18 To maintain a consistant toolchain, first emerge binutils gcc
19 virtual/libc. Next, rebuild the entire system with emerge -e world. All
20 future packages will be built with PIE/SSP.
21 --- SNAP ---
22
23 So I start "emerge binutils gcc virtual/libc"... But it take now more
24 then three hours on my old machine and I think it would take additional
25 four or more hours... And I think "emerge -e world" would take more
26 time, or not?
27
28 Is it really necessary to recompile that whole stuff?
29
30 Thanks a lot.
31
32 Bye,
33 Mike
34 --
35 Michael Decker Michael.Decker@×××××.de
36 TESIS SYSware GmbH http://www.tesis.de
37 Baierbrunnerstr. 15 * 81379 Muenchen * Tel. +49 89 747377-0
38
39 --
40 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Using PaX / Need to recompile whole gentoo? Rumen Yotov <rumen@××××××.org>