git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] mingw: enable DEP and ASLR

From
Jonathan Nieder <jrnieder@gmail.com>
Date
May 1, 2019, 22:02 UTC
Message-ID
<20190501220219.GA42435@google.com>
In-Reply-To
<20190501204631.GB13372@sigill.intra.peff.net>
Hi,
Jeff King wrote:
Show 22 quoted lines
> I wonder if this points to this patch touching the wrong level. These
> compiler flags are a thing that _some_ builds want (i.e., production
> builds where people care most about security and not about debugging),
> but not necessarily all.
>
> I'd have expected this to be tweakable by a Makefile knob (either a
> specific knob, or just the caller setting the right CFLAGS etc), and
> then for the builds of Git for Windows to turn those knobs when making a
> package to distribute.
>
> Our internal package builds at GitHub all have this in their config.mak
> (for Linux, of course):
>
>   CFLAGS += -U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=1
>   CFLAGS += -fstack-protector-strong
>
>   CFLAGS += -fpie
>   LDFLAGS += -z relro -z now
>   LDFLAGS += -pie
>
> and I wouldn't be surprised if other binary distributors (like the
> Debian package) do something similar.
Yes, the Debian package uses
	CFLAGS := -Wall \
		$(shell dpkg-buildflags --get CFLAGS) \
		$(shell dpkg-buildflags --get CPPFLAGS)
and then passes CFLAGS='$(CFLAGS)' to "make".
That means we're using
	-g -O2 -fstack-protector-strong -Wformat -Werror=format-security
	-Wdate-time -D_FORTIFY_SOURCE=2

Dscho's suggestion for the Windows build sounds fine to me (if checking for -Og, too). Maybe it would make sense to factor out a makefile variable for this, that could be used for builds on other platforms, too. That way, the autodetection can be in one place, and there is a standard way to override it when the user wants something else.

Thanks, Jonathan

Previous: Jeff KingNext: Johannes Schindelin
Message 11 of 16 in “Enable Data Execution Protection and Address Space Layout Randomization on Windows”
  1. 0/2 Enable Data Execution Protection and Address Space Layout Randomization on WindowsJohannes Schindelin via GitGitGadget, Apr 29, 2019
  2. 2/2 mingw: enable DEP and ASLRİsmail Dönmez via GitGitGadget, Apr 29, 2019
  3. Johannes SixtApr 30, 2019
  4. Johannes SchindelinApr 30, 2019
  5. Johannes SixtApr 30, 2019
  6. Alban GruinMay 1, 2019
  7. brian m. carlsonMay 1, 2019
  8. Johannes SchindelinMay 8, 2019
  9. Johannes SchindelinMay 8, 2019
  10. Jeff KingMay 1, 2019
  11. Jonathan NiederMay 1, 2019
  12. Johannes SchindelinMay 8, 2019
  13. 1/2 mingw: do not let ld strip relocationsİsmail Dönmez via GitGitGadget, Apr 29, 2019
  14. 0/2 Enable Data Execution Protection and Address Space Layout Randomization on WindowsJohannes Schindelin via GitGitGadget, May 8, 2019
  15. 2/2 mingw: enable DEP and ASLRİsmail Dönmez via GitGitGadget, May 8, 2019
  16. 1/2 mingw: do not let ld strip relocationsİsmail Dönmez via GitGitGadget, May 8, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.