Re: Extend default compiler settings to harden applications

Christoph Erhardt <[email protected]>
Newsgroups gmane.linux.redhat.fedora.devel
Message-ID <[email protected]>
On second thought, maybe 'hardening' isn't the most apt category to file these 
flags under. They are not so much about mitigating common exploitation 
techniques and more about preventing the compiler from being too clever in the 
optimisations it applies.

Best regards,
Christoph

On Sunday, 16 August 2026 16:28:20 Central European Summer Time Christoph 
Erhardt wrote:
> Hi Norbert,
> 
> this sounds a sensible initiative to me.
> 
> Do you have more information to share? Areas of interest:
> * concrete numbers from the performance measurements,
> * number and names of packages that required fixing,
> * their upstream status.
> 
> In principle I see two possible ways for introducing the new flags:
> a) Append them to `_hardening_cflags` if we consider them generic hardening
> options that should be set for every hardened build.
> b) Allow more fine-grained control by introducing an extra macro, similar to
> e.g. `_include_frame_pointers`.
> 
> I'm not sure which is preferable here.
> 
> Regarding `-ftrivial-auto-var-init=zero`: this is best done as a separate
> effort because its implications are somewhat more invasive from what I know.
> 
> Thanks,
> Christoph

-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEwp5/nkNlccrQ2UKH4yzDBS9Gs8IFAmqCqowACgkQ4yzDBS9G
s8IF7RAAhCDZjvfDV25vjOuBzw7dZIBY0LgeQIG96py6FGqlJpBtNpHSrUWZwgJc
cNx/aXBPJ/fQ4Bjkr7GXPFI/iGSTvDsH0bRgbbUCkR3OPpbjenlSCAx4dfNta8aF
sgPbxtoBZxUcaEu31H5l+Dbhl5pWaETw5/vtncj3Q0UCszCNyZYhH1k/h29Lqgl0
PRD026UoVf/ZelGh/I2YYkM6cwMA04W8lFTNnFBg2ymHRx3qKBmBHx7LtTpNqCfg
rM4rV9uepe3a6uLXOPyIg3BrONLw+aCaa7956RQNXvHRUQQuLP23fo6wYU7fCPhK
ETwnBRLY4J1E6I8aREdd3YM4MJPNv3T+mNulLWRpsX3ZJetRxNM+F7CgeId5YcWF
R+ESG4SyT4L1K2mOryP3tezavWytGVV/U16JmIjIdI3jkkbhZQZkNx6nVC4DurGz
nk0/kBjkwsCdrHU+qYETh/BMM5viTqgj0JOkTDCkIfFO9do6Tb1mtBoSBvPqXSlw
kVRxmmU6yBB3nqYfsY81RMx0E5pK43/FqJJ+QCRaRYIfAtzF+G759pq6SQ+6wzkY
jW+e4ECXX2vhqk3rpCbwbs9k+z0nFKugf5DxPrHpyKyWgkpRKfsDG3/eGjy8TIlR
yujsCpAFHCk1uB6/aRnvTSqmsMqpQ+TPAZrsYgHkG2qEq0TyhyQ=
=BvgZ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.