[Development] -reduce-relocations vs hardening
kevin.kofler at chello.at
Fri Aug 21 20:15:35 CEST 2015
Timo Jyrinki wrote:
> We patched a couple of packages to use:
> export DEB_BUILD_MAINT_OPTIONS = hardening=+all,-pie
> due to this, seeing it as the best option at the moment to get GCC5
> transition completed for those packages that had some insistence of
> adding -fPIE where we did not want it.
For the record, how the hardening works in Fedora is that we do not pass
-fPIE in CFLAGS/CXXFLAGS directly, but:
and likewise for the linking step:
The contents of the specs files:
+ -z now
In particular, redhat-hardened-cc1 takes care to only pass -fPIE if -fPIC is
not being passed.
I hope this helps.
More information about the Development