Todo List: hardening-wrapper removal

2017-07-10 - Bartłomiej Piotrowski

With recent changes in toolchain, it is feasible to replace hardening-wrapper with simple rebuild against testing (with testing/devtools installed). The major differences are lack of -fstack-check (which is not enough to prevent stack clashes without full distro rebuild) and no enforcement of full RELRO if LDFLAGS are ignored.

Remove hardening-wrapper from makedepends and run checksec on both old and rebuild packages to see if there is any regression. If yes, it means that build system should be patched to reflect out LDFLAGS instead; otherwise push packages to stable repositories and mark them as done.

Link to lists of pkgbase values:

Filter Todo List Packages

Select filter criteria
11 packages displayed out of 11 total packages.
Arch Repository Name Current Version Staging Version Maintainers Status Last Touched By
x86_64 Extra ffmpeg 1:4.2.3-2 1:4.2.3-4 alucryd Complete alucryd
x86_64 Extra ffmpeg2.8 Complete alucryd
x86_64 Extra ghostscript 9.52-1 andyrtr Complete andyrtr
x86_64 Extra gpsd 3.20-1 jlichtblau Complete anthraxx
x86_64 Community kodi 18.6-2 idevolder Complete idevolder
x86_64 Extra libunrar 1:5.9.2-1 arojas Complete arojas
x86_64 Community mpv 1:0.32.0-4 eworm Complete eworm
x86_64 Extra nginx 1.18.0-1 bpiotrowski, grazzolini Complete bpiotrowski
x86_64 Community nginx-mainline 1.19.0-1 grazzolini Complete bpiotrowski
x86_64 Extra python2 2.7.18-1 felixonmars Complete felixonmars
x86_64 Extra unrar 1:5.9.2-1 arojas Complete arojas