Bug 2006856

Summary: RPM inspection failure about hardening binaries
Product: Red Hat Enterprise Linux 9 Reporter: Jacek Migacz <jmigacz>
Component: emacsAssignee: Jacek Migacz <jmigacz>
Status: CLOSED ERRATA QA Contact: Frantisek Sumsal <fsumsal>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 9.0CC: fsumsal
Target Milestone: rcKeywords: Triaged
Target Release: ---Flags: pm-rhel: mirror+
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: emacs-27.2-6.el9 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-05-09 07:49:00 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jacek Migacz 2021-09-22 14:36:31 UTC
Description of problem:
annocheck fails if run against binaries due to invalid hardening options 

Version-Release number of selected component (if applicable):
27.2-5

How reproducible:
run annocheck against rpm file

Steps to Reproduce:
$ annocheck emacs-27.2-5.el9.x86_64.rpm

Actual results:
annocheck: Version 9.79.
Hardened: emacs-27.2: FAIL: pie test because not built with '-Wl,-pie' (gcc/clang) or '-buildmode pie' (go) 
Hardened: emacs-27.2: FAIL: bind-now test because not linked with -Wl,-z,now 
Hardened: Rerun annocheck with --verbose to see more information on the tests.

Expected results:
annocheck: Version 9.79.
Hardened: emacs-27.2: PASS.

Comment 13 errata-xmlrpc 2023-05-09 07:49:00 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: emacs security and bug fix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2023:2366