[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [RFC] Enabling bindnow by default in dpkg-buildflags?



On Wed, Nov 23, 2016 at 5:24 PM, Simon McVittie wrote:

> (I'm not entirely sure why we consider hardening packaged code to be so
> much more important than hardening the locally-built code compiled by
> our users, which changed compiler defaults like those in Ubuntu
> would also give us.)

IIRC, the Debian gcc maintainer (also the Ubuntu gcc maintainer)
vetoed enabling hardening in the Debian gcc package. Not sure why that
was fine for Ubuntu but not Debian though.

Personally I would like to see GCC upstream enabling the hardening
flags by default.

-- 
bye,
pabs

https://wiki.debian.org/PaulWise


Reply to: