Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 679510 - net-misc/ntpsec does not respect CFLAGS (pie) and LDFLAGS (relro)
Summary: net-misc/ntpsec does not respect CFLAGS (pie) and LDFLAGS (relro)
Status: CONFIRMED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Steve Arnold
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-03-05 10:08 UTC by Agostino Sarubbo
Modified: 2021-01-26 03:21 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2019-03-05 10:08:31 UTC
This is an auto-filled bug because this package does not respect user's CFLAGS.

While SSP is really good for security purpose, I'd expect that with CFLAGS="-fno-stack-protector" the package should not have stack protection.
In this case the file /usr/sbin/ntpd (and maybe some other file from this package) has stack protection.
To check the SSP status you can use: checksec --file /usr/sbin/ntpd

The same issue happens for relro and pie.
Comment 1 Agostino Sarubbo gentoo-dev 2019-03-11 07:49:34 UTC
I'm sorry but the stack-protection issue was a false positive.

Anyway the bug is present for RELRO and pie.

PIE, in other packages is managed by a useflag (see ssh and pam)
Comment 2 Steve Arnold gentoo-dev 2021-01-26 03:21:12 UTC
At least this one appears fixed in 1.2.0, which I'm about to push.