F22 System Wide Change: Harden all packages with position-independent code

Stephen Gallagher sgallagh at redhat.com
Thu Jan 8 13:48:10 UTC 2015




On Thu, 2015-01-08 at 08:47 -0500, Paul Wouters wrote:
> On Thu, 8 Jan 2015, Dhiru Kholia wrote:
> 
> >> |     Your package accepts/processes untrusted input.
> >>
> >> This seems to be about every package that I use, because I most if not
> >> all tools process untrusted data from the Internet.
> >
> > +1. This view is rapidly gaining traction and visibility in recent times.
> 
> Can we throw prelink out as well when we do this?


Prelink is already gone. We haven't been running it since F19, IIRC.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 181 bytes
Desc: This is a digitally signed message part
URL: <http://lists.fedoraproject.org/pipermail/devel/attachments/20150108/062a721a/attachment.sig>


More information about the devel mailing list