Bug 9948 - "-fstack-protector-strong" seems unnecessary in SECURITY_LDFLAGS
Summary: "-fstack-protector-strong" seems unnecessary in SECURITY_LDFLAGS
Status: RESOLVED WONTFIX
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: configuration (show other bugs)
Version: unspecified
Hardware: All Multiple
: Medium normal
Target Milestone: 2.3
Assignee: Joshua Lock
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2016-07-15 01:23 UTC by hujiajie.org
Modified: 2017-02-07 13:29 UTC (History)
1 user (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: Don't know


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description hujiajie.org 2016-07-15 01:23:52 UTC
According to https://gcc.gnu.org/onlinedocs/gcc/Instrumentation-Options.html, it seems that the "-fstack-protector-strong" flag is only needed for SECURITY_CFLAGS in meta/conf/distro/include/security_flags.inc, and there's no need to add it to SECURITY_LDFLAGS and SECURITY_X_LDFLAGS.
Comment 1 Joshua Lock 2016-08-05 13:40:20 UTC
Agreed, the docs state:

"Emit extra code to check for buffer overflows, such as stack smashing attacks. This is done by adding a guard variable to functions with vulnerable objects."

Emitting extra code is certainly a compiler, not linker, option.
Comment 2 Joshua Lock 2016-08-19 15:39:45 UTC
Patch sent to oe-core list: http://lists.openembedded.org/pipermail/openembedded-core/2016-August/125369.html
Comment 3 Joshua Lock 2017-02-07 13:29:43 UTC
There was some concern about dropping this and its presence doesn't appear to be causing issues. As we don't have a lot of bandwidth to fully test the ramifications of this on multiple toolchains and multiple layers I'm closing this as WONTFIX.

If you believe there's an issue with continuing to include this option in SECURITY*LDFLAGS please reopen this bug and we'll try to find resources in a future cycle.