[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Enabling hardening build flags



On Tue, Aug 02, 2011 at 10:43:49PM +0200, Jonathan Nieder wrote:
> Raphael Hertzog wrote:
> 
> > I also wonder whether we should keep -Werror=format-security given that no
> > archive rebuild has been made with this option so we don't really know how
> > many packages will be affected by this.
> 
> I'd say, enable it, keeping in mind that the failure mode is just a
> failed build and it's easy to disable again if someone screams. :)

And it's easy to filter out by the maintainer if they want. :)

-- 
Kees Cook                                            @debian.org


Reply to: