Re: Hardening build flags release goal

2011-09-21 Thread Raphael Hertzog
On Wed, 21 Sep 2011, Raphael Hertzog wrote: > On Wed, 21 Sep 2011, Ian Jackson wrote: > > Raphael Hertzog writes ("Hardening build flags release goal"): > > > we're not very far from having hardening build flags set by default by > > > dpkg-buildflags

Re: Hardening build flags release goal

2011-09-21 Thread Raphael Hertzog
On Wed, 21 Sep 2011, Ian Jackson wrote: > Raphael Hertzog writes ("Hardening build flags release goal"): > > we're not very far from having hardening build flags set by default by > > dpkg-buildflags (waiting on some documentation update that Kees should > >

Re: Hardening build flags release goal

2011-09-21 Thread Ian Jackson
Raphael Hertzog writes ("Hardening build flags release goal"): > we're not very far from having hardening build flags set by default by > dpkg-buildflags (waiting on some documentation update that Kees should > take care of). Can you please point us to the draft inte

Re: Hardening build flags release goal

2011-09-12 Thread Michael Gilbert
Moritz Mühlenhoff wrote: > > If you're interested, just respond and start creating the release goal > > wiki page: > > http://wiki.debian.org/ReleaseGoals > > I'm in, but it'll take a few days until I'll be able to work on the wiki > page. For anyone interested in contributing, I've just started

Re: Hardening build flags release goal

2011-09-07 Thread Kees Cook
On Tue, Sep 06, 2011 at 04:01:04PM +, The Fungi wrote: > On Mon, Sep 05, 2011 at 02:22:39PM -0700, Kees Cook wrote: > [...] > > It might be better to extend it further, like "all network daemons > > using dpkg-buildflags properly and enabling PIE" > [...] > > And since many network daemons are

Re: Hardening build flags release goal

2011-09-07 Thread Kees Cook
On Mon, Sep 05, 2011 at 07:42:30PM +0200, Moritz Mühlenhoff wrote: > I'm thinking of something along the lines of > "all pkgs with priority >= standard" and "all pkgs which had a DSA in the last > five years" as specific, important sub goals. Sounds good, I'm happy to help as well. -Kees -- Kee

Re: Hardening build flags release goal

2011-09-07 Thread Kees Cook
On Mon, Sep 05, 2011 at 09:34:37PM +0200, Raphael Hertzog wrote: > On Mon, 05 Sep 2011, Julien BLACHE wrote: > > Cyril Brulebois wrote: > > > Do we have a proper definition, and sample implementation(s) for “using > > > dpkg-buildflags properly”? On the top of my hat, it looks like semantics > > >

Re: Hardening build flags release goal

2011-09-06 Thread Marco d'Itri
On Sep 05, Kees Cook wrote: > It might be better to extend it further, like "all network daemons using > dpkg-buildflags properly and enabling PIE" I fully support this (and I have already enabled hardening for most of my packages with no adverse effects). -- ciao, Marco signature.asc Descrip

Re: Hardening build flags release goal

2011-09-06 Thread The Fungi
On Mon, Sep 05, 2011 at 02:22:39PM -0700, Kees Cook wrote: [...] > It might be better to extend it further, like "all network daemons > using dpkg-buildflags properly and enabling PIE" [...] And since many network daemons are implemented in interpreted languages, it might be nice to include packag

Re: Hardening build flags release goal

2011-09-06 Thread Pierre Chifflier
On Mon, Sep 05, 2011 at 07:42:30PM +0200, Moritz Mühlenhoff wrote: > Raphael Hertzog schrieb: > > Hello, > > > > we're not very far from having hardening build flags set by default by > > dpkg-buildflags (waiting on some documentation update that Kees should > > take care of). > > Thanks! > > >

Re: Hardening build flags release goal

2011-09-05 Thread Kees Cook
On Mon, Sep 05, 2011 at 10:52:40AM +0200, Raphael Hertzog wrote: > we're not very far from having hardening build flags set by default by > dpkg-buildflags (waiting on some documentation update that Kees should > take care of). I'm about halfway through this. Just brushing up on my groff syntax. ;

Re: Hardening build flags release goal

2011-09-05 Thread Julien BLACHE
Raphael Hertzog wrote: Hi, > No idea, I have only integrated the work others have done in dpkg. I > have not studied how other compilers support the hardening compilation > flags. > > What are the compilers you're thinking of? Here specifically, Clang. More generally, at this point in time, a

Re: Hardening build flags release goal

2011-09-05 Thread Raphael Hertzog
Hi, On Mon, 05 Sep 2011, Julien BLACHE wrote: > Cyril Brulebois wrote: > > Do we have a proper definition, and sample implementation(s) for “using > > dpkg-buildflags properly”? On the top of my hat, it looks like semantics > > and recommendations changed a bit over the years, so I kind of lost >

Re: Hardening build flags release goal

2011-09-05 Thread Raphael Hertzog
On Mon, 05 Sep 2011, Cyril Brulebois wrote: > Do we have a proper definition, and sample implementation(s) for “using > dpkg-buildflags properly”? On the top of my hat, it looks like semantics > and recommendations changed a bit over the years, so I kind of lost > count. I'm going to prepare a "Bi

Re: Hardening build flags release goal

2011-09-05 Thread Julien BLACHE
Cyril Brulebois wrote: Hi, > Do we have a proper definition, and sample implementation(s) for “using > dpkg-buildflags properly”? On the top of my hat, it looks like semantics > and recommendations changed a bit over the years, so I kind of lost > count. On top of that, what's the story with re

Re: Hardening build flags release goal

2011-09-05 Thread Cyril Brulebois
Raphael Hertzog (05/09/2011): > I would like to find one or two persons to lead a new release goal > centered around hardening. The big goal is to have the maximum number of > packages using hardening by the time Wheezy is released but it could > include more specific sub-goals like "all packages

Re: Hardening build flags release goal

2011-09-05 Thread Michael Gilbert
On Mon, 5 Sep 2011 19:42:30 +0200 Moritz Mühlenhoff wrote: > Raphael Hertzog schrieb: > > Hello, > > > > we're not very far from having hardening build flags set by default by > > dpkg-buildflags (waiting on some documentation update that Kees should > > take care of). > > Thanks! > > > I would

Re: Hardening build flags release goal

2011-09-05 Thread Moritz Mühlenhoff
Raphael Hertzog schrieb: > Hello, > > we're not very far from having hardening build flags set by default by > dpkg-buildflags (waiting on some documentation update that Kees should > take care of). Thanks! > I would like to find one or two persons to lead a new release goal > centered around ha

Hardening build flags release goal

2011-09-05 Thread Raphael Hertzog
Hello, we're not very far from having hardening build flags set by default by dpkg-buildflags (waiting on some documentation update that Kees should take care of). I would like to find one or two persons to lead a new release goal centered around hardening. The big goal is to have the maximum num