tech-pkg archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Default hardening options



* On 2021-08-04 at 16:13 BST, nia wrote:

How do we feel about turning up the default hardening options?

It's probably worth clarifying whether you mean for all OS or just NetBSD. One consideration is that while I've also been enabling PKGSRC_USE_SSP=strong since 2016Q1 in my builds, it does add a dependency on libssp at least on older illumos systems which can complicate how packages are distributed with GCC dependencies.

Obviously for relro and pie it'd need to only be done on OS where they are supported.

--
Jonathan Perkin  -  Joyent, Inc.  -  www.joyent.com


Home | Main Index | Thread Index | Old Index