Diff for /wikisrc/pkgsrc/hardening.mdwn between versions 1.20 and 1.21

version 1.20, 2017/08/25 01:52:19 version 1.21, 2017/09/07 11:32:21
Line 8  in `mk.conf`, and consist of: Line 8  in `mk.conf`, and consist of:
   Executables) when supported on the current platform. This option is necessary    Executables) when supported on the current platform. This option is necessary
   to fully leverage ASLR as a mitigation for security vulnerabilities.    to fully leverage ASLR as a mitigation for security vulnerabilities.
 * `PKGSRC_USE_FORTIFY`: allows substitute wrappers to be used for commonly used  * `PKGSRC_USE_FORTIFY`: allows substitute wrappers to be used for commonly used
   functions that do not bounds checking regularly - but could in some cases (now    functions that do not bounds checking regularly - but could in some cases
   enabled by default)    (enabled by default since pkgsrc-2017Q3)
 * `PKGSRC_USE_RELRO`: this also makes the exploitation of some security  * `PKGSRC_USE_RELRO`: this also makes the exploitation of some security
   vulnerabilities more difficult in some cases.    vulnerabilities more difficult in some cases.
 * `PKGSRC_USE_SSP`: enables a stack-smashing protection mitigation (now enabled  * `PKGSRC_USE_SSP`: enables a stack-smashing protection mitigation (enabled
   by default where known supported)    by default where known supported since pkgsrc-2017Q3)
 * `PKGSRC_USE_STACK_CHECK`: uses `-fstack-check` with GCC for another stack  * `PKGSRC_USE_STACK_CHECK`: uses `-fstack-check` with GCC for another stack
   protection mitigation.    protection mitigation.
   

Removed from v.1.20  
changed lines
  Added in v.1.21


CVSweb for NetBSD wikisrc <wikimaster@NetBSD.org> software: FreeBSD-CVSweb