Bug#918914: add -fstack-clash-protection to default buildflags

2023-08-16 Thread Emanuele Rocca
Hi! On 2019-01-29 09:56, Guillem Jover wrote: > Given its arch-dependent behavior this might need more exposure than a > simple rebuild on say amd64. Enabling this at the beginning of a > release cycle might seem more appropriate. Lucas performed a full archive rebuild on arm64 with

Bug#918914: add -fstack-clash-protection to default buildflags

2023-08-04 Thread Martin Uecker
On Wed, 21 Jun 2023 17:57:41 +0200 =?UTF-8?Q?Moritz_M=C3=BChlenhoff?= wrote: > Am Fri, May 27, 2022 at 09:48:05AM +0200 schrieb Guillem Jover: > > I don't think the issues presented by Florian were ever resolved, so > > my concerns in https://bugs.debian.org/918914#15 would still apply, > > even

Bug#918914: add -fstack-clash-protection to default buildflags

2023-06-22 Thread Guillem Jover
Hi! On Wed, 2023-06-21 at 17:57:41 +0200, Moritz Mühlenhoff wrote: > Am Fri, May 27, 2022 at 09:48:05AM +0200 schrieb Guillem Jover: > > I don't think the issues presented by Florian were ever resolved, so > > my concerns in https://bugs.debian.org/918914#15 would still apply, > > even though

Bug#918914: add -fstack-clash-protection to default buildflags

2023-06-21 Thread Moritz Mühlenhoff
Am Fri, May 27, 2022 at 09:48:05AM +0200 schrieb Guillem Jover: > I don't think the issues presented by Florian were ever resolved, so > my concerns in https://bugs.debian.org/918914#15 would still apply, > even though Ubuntu has enabled this, but they have a different set of > architectures. I

Bug#918914: add -fstack-clash-protection to default buildflags

2022-05-27 Thread Guillem Jover
Hi! On Thu, 2020-09-03 at 21:00:09 +0200, Moritz Mühlenhoff wrote: > On Thu, Jan 10, 2019 at 09:42:10AM -0500, Harlan Lieberman-Berg wrote: > > Package: dpkg-dev > > Version: 1.19.2 > > Severity: wishlist > > Tags: security > > It would be Really Awesome (TM) if we could add the > >

Bug#918914: add -fstack-clash-protection to default buildflags

2020-09-03 Thread Moritz Mühlenhoff
On Thu, Jan 10, 2019 at 09:42:10AM -0500, Harlan Lieberman-Berg wrote: > Package: dpkg-dev > Version: 1.19.2 > Severity: wishlist > Tags: security > > Hello GCC Maintainers! > > It would be Really Awesome (TM) if we could add the > -fstack-clash-protection flag to our default hardening posture.

Bug#918914: add -fstack-clash-protection to default buildflags

2019-01-29 Thread Guillem Jover
Control: tags -1 moreinfo Hi! On Thu, 2019-01-10 at 16:20:23 +0100, Florian Weimer wrote: > * Harlan Lieberman-Berg: > > It would be Really Awesome (TM) if we could add the > > -fstack-clash-protection flag to our default hardening posture. This > > would have provided protection against the

Bug#918914: add -fstack-clash-protection to default buildflags

2019-01-10 Thread Florian Weimer
* Harlan Lieberman-Berg: > Hello GCC Maintainers! > > It would be Really Awesome (TM) if we could add the > -fstack-clash-protection flag to our default hardening posture. This > would have provided protection against the recent System Down > vulnerability (CVE-2018-16864, CVE-2018-16865,

Bug#918914: add -fstack-clash-protection to default buildflags

2019-01-10 Thread Harlan Lieberman-Berg
Package: dpkg-dev Version: 1.19.2 Severity: wishlist Tags: security Hello GCC Maintainers! It would be Really Awesome (TM) if we could add the -fstack-clash-protection flag to our default hardening posture. This would have provided protection against the recent System Down vulnerability