<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>9948</bug_id>
          
          <creation_ts>2016-07-15 01:23:52 +0000</creation_ts>
          <short_desc>&quot;-fstack-protector-strong&quot; seems unnecessary in SECURITY_LDFLAGS</short_desc>
          <delta_ts>2017-02-07 13:29:43 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>configuration</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WONTFIX</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>2.3</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>hujiajie.org</reporter>
          <assigned_to name="Joshua Lock">joshuagloe</assigned_to>
          <cc>sgw</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>Don&apos;t know</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>64016</commentid>
    <comment_count>0</comment_count>
    <who name="">hujiajie.org</who>
    <bug_when>2016-07-15 01:23:52 +0000</bug_when>
    <thetext>According to https://gcc.gnu.org/onlinedocs/gcc/Instrumentation-Options.html, it seems that the &quot;-fstack-protector-strong&quot; flag is only needed for SECURITY_CFLAGS in meta/conf/distro/include/security_flags.inc, and there&apos;s no need to add it to SECURITY_LDFLAGS and SECURITY_X_LDFLAGS.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>64931</commentid>
    <comment_count>1</comment_count>
    <who name="Joshua Lock">joshuagloe</who>
    <bug_when>2016-08-05 13:40:20 +0000</bug_when>
    <thetext>Agreed, the docs state:

&quot;Emit extra code to check for buffer overflows, such as stack smashing attacks. This is done by adding a guard variable to functions with vulnerable objects.&quot;

Emitting extra code is certainly a compiler, not linker, option.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>65355</commentid>
    <comment_count>2</comment_count>
    <who name="Joshua Lock">joshuagloe</who>
    <bug_when>2016-08-19 15:39:45 +0000</bug_when>
    <thetext>Patch sent to oe-core list: http://lists.openembedded.org/pipermail/openembedded-core/2016-August/125369.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>70487</commentid>
    <comment_count>3</comment_count>
    <who name="Joshua Lock">joshuagloe</who>
    <bug_when>2017-02-07 13:29:43 +0000</bug_when>
    <thetext>There was some concern about dropping this and its presence doesn&apos;t appear to be causing issues. As we don&apos;t have a lot of bandwidth to fully test the ramifications of this on multiple toolchains and multiple layers I&apos;m closing this as WONTFIX.

If you believe there&apos;s an issue with continuing to include this option in SECURITY*LDFLAGS please reopen this bug and we&apos;ll try to find resources in a future cycle.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>