Re: F45 Change Proposal: Enable Shadow Stack by Default on x86_64 (system-wide)

Arjun Shankar <[email protected]>
Newsgroups gmane.linux.redhat.fedora.devel
Message-ID <CAG_osaYM+W_kYAFqthwypgP9DR5DxBCzfVOGjyKki4YNWm6gNA@mail.gmail.com>
> > Please, please, please, make that /usr/lib/tunables.conf.d/app.conf
> > by default. As described below, this is clearly something that is
> > part of the rpm and not "local configuration".
> >
>
> I don't think this path exists. That's a glibc thing, I think, and the
> doc about it doesn't indicate any hermetic /usr support.
>
> https://sourceware.org/git/?p=glibc.git;a=blobdiff;f=manual/tunables.texi;h=828c68151ad887550430605f007e289b5235f110;hp=e1d9fbae9cebe961fe45203251a761c3323a9917;hb=fae194043a099d45c044c883467c934153ecc51f;hpb=fcea66cd4685f9f3719e09cac52c73b9ece4bade

Upstream doesn't need to support multiple configuration directories.
An appropriate "include" line in the configuration shipped by Fedora's
glibc can solve this. We intend to ship appropriate configuration to
allow drop-in files, and the /usr/lib route suggested earlier in this
thread sounds like a reasonable one.

-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.