Bug 9948

Summary: "-fstack-protector-strong" seems unnecessary in SECURITY_LDFLAGS
Product: [Build System, Metadata & Runtime] OE-Core Reporter: hujiajie.org
Component: configurationAssignee: Joshua Lock <joshuagloe>
Status: RESOLVED WONTFIX QA Contact:
Severity: normal    
Priority: Medium CC: sgw
Version: unspecified   
Target Milestone: 2.3   
Hardware: All   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Don't know

Description hujiajie.org 2016-07-15 01:23:52 UTC
According to https://gcc.gnu.org/onlinedocs/gcc/Instrumentation-Options.html, it seems that the "-fstack-protector-strong" flag is only needed for SECURITY_CFLAGS in meta/conf/distro/include/security_flags.inc, and there's no need to add it to SECURITY_LDFLAGS and SECURITY_X_LDFLAGS.
Comment 1 Joshua Lock 2016-08-05 13:40:20 UTC
Agreed, the docs state:

"Emit extra code to check for buffer overflows, such as stack smashing attacks. This is done by adding a guard variable to functions with vulnerable objects."

Emitting extra code is certainly a compiler, not linker, option.
Comment 2 Joshua Lock 2016-08-19 15:39:45 UTC
Patch sent to oe-core list: http://lists.openembedded.org/pipermail/openembedded-core/2016-August/125369.html
Comment 3 Joshua Lock 2017-02-07 13:29:43 UTC
There was some concern about dropping this and its presence doesn't appear to be causing issues. As we don't have a lot of bandwidth to fully test the ramifications of this on multiple toolchains and multiple layers I'm closing this as WONTFIX.

If you believe there's an issue with continuing to include this option in SECURITY*LDFLAGS please reopen this bug and we'll try to find resources in a future cycle.