From mboxrd@z Thu Jan 1 00:00:00 1970 From: ng0@n0.is Subject: hardening Date: Mon, 29 Jan 2018 12:44:09 +0000 Message-ID: <87a7wwesx2.fsf@abyayala.i-did-not-set--mail-host-address--so-tickle-me> Mime-Version: 1.0 Content-Type: text/plain Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:49155) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eg8nl-0001a0-VU for guix-devel@gnu.org; Mon, 29 Jan 2018 07:44:46 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1eg8ng-0000OM-WB for guix-devel@gnu.org; Mon, 29 Jan 2018 07:44:46 -0500 Received: from aibo.runbox.com ([91.220.196.211]:36806) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1eg8ng-0000M3-Oa for guix-devel@gnu.org; Mon, 29 Jan 2018 07:44:40 -0500 Received: from [10.9.9.212] (helo=mailfront12.runbox.com) by mailtransmit03.runbox with esmtp (Exim 4.86_2) (envelope-from ) id 1eg8ne-0003gW-6t for guix-devel@gnu.org; Mon, 29 Jan 2018 13:44:38 +0100 Received: from dslb-092-073-177-142.092.073.pools.vodafone-ip.de ([92.73.177.142] helo=localhost) by mailfront12.runbox.com with esmtpsa (uid:892961 ) (TLS1.2:RSA_AES_256_CBC_SHA1:256) (Exim 4.82) id 1eg8nA-0001dV-2C for guix-devel@gnu.org; Mon, 29 Jan 2018 13:44:08 +0100 List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org Hi, as we've long talked and not really taken action on hardening builds I've started working on an opt-in way as last discussed in september 2016, modifying the gnu-build-system with a #:hardening-flags keyword. For my testing purposes I will use > CFLAGS="-fPIE -fstack-protector-all -D_FORTIFY_SOURCE=2" LDFLAGS="-Wl,-z,now -Wl,-z,relro" which is used by Gentoo, but adjustments (wether to opt-in or opt-out) will be made. -- ng0 :: https://ea.n0.is A88C8ADD129828D7EAC02E52E22F9BBFEE348588 :: https://ea.n0.is/keys/