FAQ Search Today's Posts Mark Forums Read
» Video Reviews

» Linux Archive

Linux-archive is a website aiming to archive linux email lists and to make them easily accessible for linux users/developers.


» Sponsor

» Partners

» Sponsor

Go Back   Linux Archive > Redhat > Fedora Packaging

 
 
LinkBack Thread Tools
 
Old 02-24-2012, 04:21 PM
Bill Nottingham
 
Default Guideline change request: make PIE 'must' instead of 'should'

https://fedorahosted.org/fpc/ticket/144

The guidelines currently read:

...
If your package meets the following critera you should consider enabling the
PIE compiler flags:

Your package is long running. This means it's likely to be started and
keep running until the machine is rebooted, not start on demand and quit on
idle.

Your package has suid binaries, or binaries with capabilities.

Your package runs as root.

Your package accepts/processes untrusted input.
...

I'd like to change this from 'should' to 'must'. I do not believe there are
convincing performance reasons that we have found that would require not
using it for packages that fit this criteria. The only concern would be
programs that don't work as PIE ... those can be treated as exceptions.

Comments?

Bill
--
packaging mailing list
packaging@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/packaging
 

Thread Tools




All times are GMT. The time now is 07:55 AM.

VBulletin, Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.
Copyright 2007 - 2008, www.linux-archive.org