Re: F28 System Wide Change: Hardening Flags Updates for Fedora 28

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 01/05/2018 10:17 AM, Zbigniew Jędrzejewski-Szmek wrote:
On Thu, Jan 04, 2018 at 09:36:27PM -0800, John Reiser wrote:
4) All code must be generated by a compiler that enforces the probing policy,
and all language support run-time routines also must enforce the policy.
No mixing of old or foreign compilers with the new gcc.
No mixing of old or foreign C libraries with the new glibc.
Direct use by an app developer of the 'clone' system call is forbidden.

Hmmm, systemd uses clone (the raw syscall) quite a bit. And libsystemd
is linked into quite a few things in the distro. Based on what you
write here, this could be a big problem.

As far as the raw system call is concerned, there is no problem because there is no stack switching involved.

Thanks,
Florian
_______________________________________________
devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux