Bug#552688: Please decide how Debian should enable hardening build flags
I believe at this point the dpkg-buildflags solution has proven reasonably
successful and is being widely deployed. I think we should confirm that
the TC agrees with that approach and close out this bug.
I therefore propose the following ballot:
A. The Technical Committee agrees with the dpkg-buildflags approach
currently in use to enable hardening flags.
B. Further discussion.
I think the remaining open question is whether there is a desire to list
overriding the GCC maintainer and patching GCC to enable the flags for all
compilation on the ballot. My guess is that there is not; if anyone
disagrees, please speak up and I'll draft a revised ballot including that
option.
If there is no other feedback, I plan to call for a vote on the above
ballot in a few days.
--
Russ Allbery (rra@debian.org) <http://www.eyrie.org/~eagle/>
Reply to: