Re: Extend default compiler settings to harden applications
"Manthey, Norbert via devel" <[email protected]>
| Newsgroups | gmane.linux.redhat.fedora.devel |
|---|---|
| Message-ID | <FR5SPRMB00177D4F16FECE6DCF66290DCFA72@FR5SPRMB0017.DEUP281.PROD.OUTLOOK.COM> |
Thanks Christoph, I will draft two independent change proposals with more details and will ping in case I need help to fill in the Fedora project specific details. Best, Norbert ________________________________ From: Christoph Erhardt Sent: Monday, August 17, 2026 8:30 AM To: [email protected] Cc: Manthey, Norbert Subject: RE: [EXTERNAL] Extend default compiler settings to harden applications On second thought, maybe 'hardening' isn't the most apt category to file these flags under. They are not so much about mitigating common exploitation techniques and more about preventing the compiler from being too clever in the optimisations it applies. Best regards, Christoph On Sunday, 16 August 2026 16:28:20 Central European Summer Time Christoph Erhardt wrote: > Hi Norbert, > > this sounds a sensible initiative to me. > > Do you have more information to share? Areas of interest: > * concrete numbers from the performance measurements, > * number and names of packages that required fixing, > * their upstream status. > > In principle I see two possible ways for introducing the new flags: > a) Append them to `_hardening_cflags` if we consider them generic hardening > options that should be set for every hardened build. > b) Allow more fine-grained control by introducing an extra macro, similar to > e.g. `_include_frame_pointers`. > > I'm not sure which is preferable here. > > Regarding `-ftrivial-auto-var-init=zero`: this is best done as a separate > effort because its implications are somewhat more invasive from what I know. > > Thanks, > Christoph -- _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new