Re: RFC mass bug reporting: checksec failures

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



На 12.09.2015 в 08:48, Dominik 'Rathann' Mierzejewski написа:

Question is how to deal with these because they appear to be in the hundreds ?

How many, exactly? We have around 20000 SRPMs in the distribution.

On a system with 1170 packages installed I got 233 reported as failed. I'll try to get an exact number for all of the packages but my guess is over 1000.

This excludes most libraries (where instead of PIE enabled, checksec reports DSO) and excludes acceptable RPATHs (/usr/lib.*/.*).


The list is at:
https://github.com/atodorov/fedora-scripts/blob/master/checksec.log


The script which produced it is at:
https://github.com/atodorov/fedora-scripts/blob/master/checksec-collect


Packages like grub2 should probably be excluded, maybe also -devel ones or files like .o .a ? Are there any other packages that need to be excluded ?


I will also bring this up on fedora-devel in accordance with the mass bug filing wiki page before doing anything further.


--
Alex

--
packaging mailing list
packaging@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/packaging




[Index of Archives]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite Forum]     [KDE Users]

  Powered by Linux