F22 System Wide Change: Harden all packages with position-independent code

Miloslav Trmač mitr at redhat.com
Thu Jan 8 18:45:20 UTC 2015


Hello,
> = Proposed System Wide Change: Harden all packages with position-independent
> code =
>
> Harden all packages with position-independent code to limit the damage from
> certain security vulnerabilities.

So this proposal is for _all_ architectures, including the register-starved 32-bit i?86 where the overhead is, IIRC, around 10%.  I am by now quite convinced that x86_64 should be using PIE by default.  As for 32-bit, I’m torn between “this is too much overhead” and “32-bit isn’t worth the worry, let’s instead make the defaults consistent.”
   Mirek


More information about the devel mailing list