Stuart Henderson <[email protected]> writes:

> On 2013/04/06 03:31, Jérémie Courrèges-Anglas wrote:
>> Hi folks,
>> 
>> here's a tarball.  The dependancy on p5-IO-Tty has been dropped.
>> 
>> Works fine here.

[...]

> This tries to force PIE, which I suspect will result in broken binaries
> on arm/hppa. I think it's probably better to remove this as we enable
> PIE by default where possible, but comments from others on this would
> be welcome. Other than that it looks good to me.

Ah, nice catch.  Thinking about it, the default --enable-hardening
parameter doesn't seem to help much, does it?

* -fno-strict-overflow - on by default with -O2
* -D_FORTIFY_SOURCE=2  - no-op afaik
* SSP                  - on by default
* PIE                  - on by default, where applicable

No idea about these and their usefulness on OpenBSD:

* ld -z,relro
* ld -z,now

> Seems rather slow on a fast network though ;)

and CPU hungry...

-- 
Jérémie Courrèges-Anglas
PGP Key fingerprint: 61DB D9A0 00A4 67CF 2A90  8961 6191 8FBF 06A1 1494

Reply via email to