F22 System Wide Change: Harden all packages with position-independent code

Dennis Gilmore dennis at ausil.us
Thu Jan 8 23:16:57 UTC 2015


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thu, 08 Jan 2015 20:25:36 +0100
Reindl Harald <h.reindl at thelounge.net> wrote:

> 
> Am 08.01.2015 um 19:45 schrieb Miloslav Trmač:
> >> = Proposed System Wide Change: Harden all packages with
> >> position-independent code =
> >>
> >> Harden all packages with position-independent code to limit the
> >> damage from certain security vulnerabilities.
> >
> > So this proposal is for _all_ architectures, including the
> > register-starved 32-bit i?86 where the overhead is, IIRC, around
> > 10%.  I am by now quite convinced that x86_64 should be using PIE
> > by default.  As for 32-bit, I’m torn between “this is too much
> > overhead” and “32-bit isn’t worth the worry, let’s instead make the
> > defaults consistent.”
> 
> probably not worth the worry, new machines are x86_64 mostly, keep in 
> mind RHEL7 dropped i686 at all
> 
> even if they are still used - 10% sounds much *but* such old machines 
> mostly have a special task and are far away from noticeable load and
> it really depends on the workload if you even notice 20% performance
> drop
> 
> at least i doubt there is a noticeable userbase with i686 running
> Fedora at all *and* would notice the drop noticeable

all of the OLPC XO 1.0 and 1.5 devices are running i686 fedora, that
userbase is in the millions, but would they notice  the performance
drop I do not know. 

It would be interesting to see how performance was impacted on 32 bit
arm 

Dennis

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBAgAGBQJUrw/pAAoJEH7ltONmPFDRcmIQAIE+s6LNOA+Sj1nWnzzhRb+N
e4Zf5DUAJl7N48taMiHgivVm9nQR1poOu99H1FMMPtskaoKFBgEEgBpSH3THXQSm
c/PS6T6SeDn5BwO/9LIsmd/A+JtWlMBGl4N4HjSiLvMOu93YYlIoYUFjuln+ION0
GjMrMkIiKAGI5de7xmhohd/f82+69stANxqukkGhP4KJOq20PA075eKNvtNIwBqE
kpTCueEBbpZtaYFRLC749flURRhyFKFJsqWiYa5SW6azq4xQOIOsQ8NJ7HazmA4z
bwTkjGYzoE2NDD0+Cqb2hHbjuC3gZBEIqfF0b0eX9gRBHTfxw4VquBky/dKnjHMc
UUHCNyMtnVDotfz5bGRekJGlkcynEmquzNz9sEhhB6cfhnr79I4eNRnjMeEzhkIo
ysYbVh/iXJL5jdiRCC2AjBcVX0tOe/etUz7MLCDyWeh929iulkPVXUPhrN0fRLO5
RDz1Z2t7uE6RZGQ4JtzZvHcdgBAOSJSj2cxwdDtyvGwbDFxTQRmAoY+pmuL7Ny71
wxaMUkmODszSEsNxxp7TKU3+Q26Ju9jdA2AToFFdm9WqyJVQYO239414TXgQzDAM
MMmM+YUKIDVGf/dwrEteyw4+ksF2C39r8KHSIx4jC/wbf84Ain91cNzUFTQow2RC
JgR5QsmMIy593naNYzbv
=+w+u
-----END PGP SIGNATURE-----


More information about the devel mailing list