Bug#1021292: Enabling branch protection on amd64 and arm64

2023-06-27 Thread Moritz Mühlenhoff
Am Wed, Jun 21, 2023 at 05:41:36PM +0200 schrieb Emanuele Rocca: > Hey Moritz, > > On 2022-10-26 08:20, Moritz Mühlenhoff wrote: > > I think this should rather be applied early after the Bookworm > > release (and ideally we can also finish off the necessary testing >

Bug#918914: add -fstack-clash-protection to default buildflags

2023-06-21 Thread Moritz Mühlenhoff
Am Fri, May 27, 2022 at 09:48:05AM +0200 schrieb Guillem Jover: > I don't think the issues presented by Florian were ever resolved, so > my concerns in https://bugs.debian.org/918914#15 would still apply, > even though Ubuntu has enabled this, but they have a different set of > architectures. I

Bug#918914: add -fstack-clash-protection to default buildflags

2020-09-03 Thread Moritz Mühlenhoff
On Thu, Jan 10, 2019 at 09:42:10AM -0500, Harlan Lieberman-Berg wrote: > Package: dpkg-dev > Version: 1.19.2 > Severity: wishlist > Tags: security > > Hello GCC Maintainers! > > It would be Really Awesome (TM) if we could add the > -fstack-clash-protection flag to our default hardening posture.

Re: [RFC PATCH] dpkg-buildflags: Switch to -fstack-protector-strong

2014-06-27 Thread Moritz Mühlenhoff
On Tue, Jun 24, 2014 at 09:38:18PM +0200, Niels Thykier wrote: I think we need a lintian check to gain some traction. Already implemented in 2.5.23 (#711193)[1]. Thanks! Seems I was fooled by outdated lintian results in the PTS. It didn't list an error for ploop, while running lintian

Bug#653846: Please add an option for dpkg-buildflags to emit a different optimization level

2012-01-02 Thread Moritz Mühlenhoff
On Mon, Jan 02, 2012 at 12:59:16PM -0600, Jonathan Nieder wrote: Moritz Muehlenhoff wrote: Is the evaluation order of GCC options properly specified, i.e. is there a guarantee that -Os overrides the previous -O2 Yes. (From the manual: If you use multiple -O options, with or