Hi All,
2016-05-28 23:16 GMT+02:00 Bálint Réczey :
> Hi,
>
> 2016-05-18 2:21 GMT+02:00 Guillem Jover :
>> On Tue, 2016-05-17 at 12:08:09 +0200, Matthias Klose wrote:
>>> I'm not a fan myself for turning on hardening flags in the compiler itself,
>>> but
> "Guillem" == Guillem Jover writes:
>> I agree that it would be the easier way and I also tried building
>> packages with patched GCC 5 setting PIE as default with success,
>> but we have a CTTE decision which says that we should set
>> hardening flags
Hi,
2016-05-18 2:21 GMT+02:00 Guillem Jover :
> On Tue, 2016-05-17 at 12:08:09 +0200, Matthias Klose wrote:
>> I'm not a fan myself for turning on hardening flags in the compiler itself,
>> but if you do that, then dpkg issues like https://bugs.debian.org/823869
>> need to be
Hi,
2016-05-16 13:09 GMT+02:00 Christoph Egger :
> Hi!
>
> Iustin Pop writes:
>> - that bug seems to have been opened in the context of custom patches to
>> GCC, back in 2009-2012
>> - the CTTE seems to have made an informal decision (see last update
>>
Hi!
Iustin Pop writes:
> - that bug seems to have been opened in the context of custom patches to
> GCC, back in 2009-2012
> - the CTTE seems to have made an informal decision (see last update
> #272) on that topic
And most importantly
- the tech-ctte primarily refused
On Tue, 2016-05-17 at 12:08:09 +0200, Matthias Klose wrote:
> I'm not a fan myself for turning on hardening flags in the compiler itself,
> but if you do that, then dpkg issues like https://bugs.debian.org/823869
> need to be addressed (whether all obscure build systems picking these up, or
>
Hi!
On Sun, 2016-05-15 at 21:45:55 +0200, Bálint Réczey wrote:
> 2016-05-15 20:49 GMT+02:00 Niels Thykier :
> > Bálint Réczey:
> >> I think making PIE and bindnow default in dpkg (at least for amd64) would
> >> be
> >> perfect release goals for Stretch.
> >
> > I support the
On 15.05.2016 23:10, Iustin Pop wrote:
On 2016-05-15 21:45:55, Bálint Réczey wrote:
Hi Niels,
2016-05-15 20:49 GMT+02:00 Niels Thykier :
Bálint Réczey:
Hi,
[...]
Hi,
I think making PIE and bindnow default in dpkg (at least for amd64) would be
perfect release goals
Le 15 mai 2016 20:49:38 GMT+02:00, Niels Thykier a écrit :
>Bálint Réczey:
>> Hi,
>>
>> [...]
>>
>
>Hi,
>
>> I think making PIE and bindnow default in dpkg (at least for amd64)
>would be
>> perfect release goals for Stretch.
>>
>
>I support the end goal, but I suspect we
On Sun, May 15, 2016 at 08:13:19PM +0200, Bálint Réczey wrote:
> I think the next step could be an archive rebuild with the changed defaults
I assume you are talking about a test rebuild here… first, as a next
step.
I'm replying here now about the "real rebuilds" coming later:
reproducible
On 2016-05-15 21:45:55, Bálint Réczey wrote:
> Hi Niels,
>
> 2016-05-15 20:49 GMT+02:00 Niels Thykier :
> > Bálint Réczey:
> >> Hi,
> >>
> >> [...]
> >>
> >
> > Hi,
> >
> >> I think making PIE and bindnow default in dpkg (at least for amd64) would
> >> be
> >> perfect release
On 15 May 2016 at 19:49, Niels Thykier wrote:
> Bálint Réczey:
>> Hi,
>>
>> [...]
>>
>
> Hi,
>
>> I think making PIE and bindnow default in dpkg (at least for amd64) would be
>> perfect release goals for Stretch.
>>
>
> I support the end goal, but I suspect we should enable PIE
Hi Niels,
2016-05-15 20:49 GMT+02:00 Niels Thykier :
> Bálint Réczey:
>> Hi,
>>
>> [...]
>>
>
> Hi,
>
>> I think making PIE and bindnow default in dpkg (at least for amd64) would be
>> perfect release goals for Stretch.
>>
>
> I support the end goal, but I suspect we should
Bálint Réczey:
> Hi,
>
> [...]
>
Hi,
> I think making PIE and bindnow default in dpkg (at least for amd64) would be
> perfect release goals for Stretch.
>
I support the end goal, but I suspect we should enable PIE by default
via GCC-6's new configure switch[1]. Assuming it does what I hope,
Hi,
2016-05-15 4:11 GMT+02:00 Dimitri John Ledkov :
> On 14 May 2016 at 21:12, Niels Thykier wrote:
>> Marco d'Itri:
>>> On May 03, Josh Triplett wrote:
>>>
While this doesn't make PIC absolutely free, it does eliminate almost
15 matches
Mail list logo