Bug 1283951 - no hardening build on F23
no hardening build on F23
Product: Fedora
Classification: Fedora
Component: xorg-x11-server (Show other bugs)
Unspecified Unspecified
unspecified Severity unspecified
: ---
: ---
Assigned To: X/OpenGL Maintenance List
Fedora Extras Quality Assurance
Depends On:
  Show dependency treegraph
Reported: 2015-11-20 06:28 EST by Harald Reindl
Modified: 2015-11-20 06:38 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2015-11-20 06:37:17 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Harald Reindl 2015-11-20 06:28:52 EST

Xorg  32117 Partial RELRO     Canary found           NX enabled    No PIE

since it is long running and runs mostly as root even before F23 the packaging guidelines where pretty clear that the package MUST be hardened
Comment 1 Hans de Goede 2015-11-20 06:37:17 EST
<sigh> If you would have taken 10 seconds of your time to look at:


You would have seen the following there:

# X.org requires lazy relocations to work.
%undefine _hardened_build

Due to way how xorg loads video and input drivers (and other modules) It can NOT be build hardened. 

Fixing this is very hard, and would break compatiblity with e.g. the nvidia binary driver.
Comment 2 Harald Reindl 2015-11-20 06:38:08 EST
FULL RELRO is one topic
PIE is a completly different one

Note You need to log in before you can comment on or make changes to this bug.