Source: grads
Version: 2.0.a9-2
Severity: normal
User: [email protected]
Usertags: hardening-format-security hardening

the package grads fails to compile with the new hardened compiler
flags dpkg-buildflag outputs [0].
The problematic flag is: -Werror=format-security
See the ubuntu buildlog:
https://launchpadlibrarian.net/83137933/buildlog_ubuntu-precise-i386.grads_2.0.a9-2_FAILEDTOBUILD.txt.gz
Snippet:
gcc -DHAVE_CONFIG_H -I. -I/usr/include/ -I/usr/include/gd
-I/usr/include/grib2c  -I/usr/include/udunits -I/usr/include/netcdf
-I/usr/include/hdf5 -I/usr/include/tiff -I/usr/include/geotiff
-I/usr/include/shapelib -I/usr/include/shp     -I/usr/include/hdf
-D_FORTIFY_SOURCE=2  -g -O2 -fstack-protector --param=ssp-buffer-size=4
-Wformat -Wformat-security -Werror=format-security -rdynamic -c gagx.c
gagx.c: In function 'gashpwrt':
gagx.c:3524:5: error: format not a string literal and no format
arguments [-Werror=format-security]
gagx.c:3524:5: error: format not a string literal and no format
arguments [-Werror=format-security]
cc1: some warnings being treated as errors



The buildflags are not exported in debian, but can be enabled e.g. by
adding this to debian/rules:

 DPKG_EXPORT_BUILDFLAGS = 1
 include /usr/share/dpkg/buildflags.mk

Please fix the issues and maybe also enable the hardened build in debian.

[0] http://lists.debian.org/debian-devel-announce/2011/09/msg00001.html




Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to