Bug 724004 - Library needs partial RELRO support added
Summary: Library needs partial RELRO support added
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: nss
Version: 6.1
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: rc
: ---
Assignee: Elio Maldonado Batiz
QA Contact: Aleš Mareček
URL:
Whiteboard:
Depends On:
Blocks: 743047 805723
TreeView+ depends on / blocked
 
Reported: 2011-07-21 17:29 UTC by Steve Grubb
Modified: 2012-03-21 21:42 UTC (History)
4 users (show)

Fixed In Version: nss-3.12.10-11.el6
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 805723 (view as bug list)
Environment:
Last Closed: 2011-12-06 12:11:06 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2011:1584 0 normal SHIPPED_LIVE nspr, nss, nss-softokn and nss-util bug fix and enhancement update 2011-12-06 00:38:51 UTC

Description Steve Grubb 2011-07-21 17:29:53 UTC
Description of problem:
The openssl package contains libraries. We would like them to be built with
partial RELRO support as a security enhancement.

Additional info:
Partial RELRO requires these passed at link:
-Wl,-z,relro

Comment 1 Elio Maldonado Batiz 2011-07-21 18:26:46 UTC
(In reply to comment #0)
> Description of problem:
> The openssl package contains libraries. We would like them to be built with
> partial RELRO support as a security enhancement.
> 
I think you meant to write nss. That would be all nss-related packages which are nss, nss-softokn, nss-util, and nspr.  I see that it's added for nss and nss-util. I now have to add it for nss-softokn and nspr.

Comment 2 Elio Maldonado Batiz 2011-07-21 18:34:01 UTC
Steve, (or someone with the required access) Could you add to Component(s) nss, nspr, and nss-softokn? Thanks.

Comment 3 Steve Grubb 2011-07-21 18:39:35 UTC
Yes, I made a copy and paste error. I opened 4 bugs, one on each component. I will also make a test script available that checks the whole rpm.

Comment 6 Elio Maldonado Batiz 2011-09-08 16:32:09 UTC
[emaldona@emaldonadesktop RHEL-6]$ make unused-patches
add-relro-linker-option.patch <--- this one is the one intended for this
nss-671266.patch  <- this one is obsolete
So the patch wasn't never applied in the spec file version I checked in and used for this build. I need to respin.

Comment 8 Elio Maldonado Batiz 2011-09-19 16:03:14 UTC
Changing status to assigned as the patch though checked wasn't never appplied in the spec file. New build coming soon.

Comment 16 errata-xmlrpc 2011-12-06 12:11:06 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2011-1584.html


Note You need to log in before you can comment on or make changes to this bug.