View previous topic :: View next topic |
Author |
Message |
LukynZ Apprentice
Joined: 19 Dec 2008 Posts: 230 Location: The Czech Republic
|
Posted: Sun Apr 13, 2014 9:02 am Post subject: hardened -> desktop switch |
|
|
Is entire world reemerge really necessary? Or just packages with pax_kernel use flag and gcc itsefl will be fine? |
|
Back to top |
|
|
Moonboots Apprentice
Joined: 02 Dec 2006 Posts: 161
|
Posted: Tue Apr 15, 2014 4:43 pm Post subject: Re: hardened -> desktop switch |
|
|
LukynZ wrote: | Is entire world reemerge really necessary? Or just packages with pax_kernel use flag and gcc itsefl will be fine? |
Certainly when you change from a hardened profile you're going to lose the "hardened" flag and gain some others that were previously masked.
emerge --newuse etc will reveal those packages that are in need of re-emerging.
Weather you need to re-emerge the entire world i'm not sure, perhaps if there are no problems ?........ |
|
Back to top |
|
|
mv Watchman
Joined: 20 Apr 2005 Posts: 6747
|
Posted: Tue Apr 15, 2014 9:17 pm Post subject: |
|
|
After emerging hardened gcc you should recompile everything in order to make use of the hardened CFLAGS which implicitly go with hardened gcc.
Otherwise, your binaries will e.g. not use PIE, even if corresponding support is activated in your kernel. |
|
Back to top |
|
|
Moonboots Apprentice
Joined: 02 Dec 2006 Posts: 161
|
Posted: Wed Apr 16, 2014 6:32 am Post subject: |
|
|
mv wrote: | After emerging hardened gcc you should recompile everything in order to make use of the hardened CFLAGS which implicitly go with hardened gcc.
Otherwise, your binaries will e.g. not use PIE, even if corresponding support is activated in your kernel. |
Unless I've misread the post he wants to go in the opposite direction ie from a hardened to non-hardened profile (desktop) ? |
|
Back to top |
|
|
mv Watchman
Joined: 20 Apr 2005 Posts: 6747
|
Posted: Wed Apr 16, 2014 9:11 am Post subject: |
|
|
Moonboots wrote: | Unless I've misread the post he wants to go in the opposite direction |
That should be no problem. Of course, the binaries will remain slower (e.g. because of the implicit -fstack-protector-all) until recompiled. |
|
Back to top |
|
|
|