Source: gnote
Version: 2.9.6-2
Severity: normal
User: [email protected]
Usertags: hardening-format-security hardening

the package gnote fails to compile with the new hardened compiler
flags dpkg-buildflag outputs [0].
The problematic flag is: -Werror=format-security
See the ubuntu buildlog:
https://launchpadlibrarian.net/83182557/buildlog_ubuntu-precise-i386.gnote_0.8.0-1_FAILEDTOBUILD.txt.gz
Snippet:
  CC    remotecontrolproxy.o
remotecontrolproxy.cpp: In static member function 'static void
gnote::RemoteControlProxy::load_introspection_xml()':
remotecontrolproxy.cpp:129:87: error: format not a string literal and no
format arguments [-Werror=format-security]
cc1plus: some warnings being treated as errors

The buildflags are not exported in debian, but can be enabled e.g. by
adding this to debian/rules:

 DPKG_EXPORT_BUILDFLAGS = 1
 include /usr/share/dpkg/buildflags.mk

Please fix the issues and maybe also enable the hardened build in debian.

[0] http://lists.debian.org/debian-devel-announce/2011/09/msg00001.html









Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to