Bug#949549: tango-accesscontrol: Does not use hardening flags for compilation

Thomas Braun thomas.braun at byte-physics.de
Tue Jan 21 21:06:06 GMT 2020


Package: tango-accesscontrol
Version: 9.3.4~rc2+dfsg2-1~exp3
Severity: normal

Dear Maintainer,

according to the lintian output and my own testing the hardening flags
are not set correctly for TangoAccessControl.

/usr/lib/tango/TangoAccessControl:
 Position Independent Executable: yes
 Stack protected: yes
 Fortify Source functions: no, only unprotected functions found!
 Read-only relocations: yes
 Immediate binding: yes
 Stack clash protection: unknown, no -fstack-clash-protection
instructions found
 Control flow integrity: unknown, no -fcf-protection instructions
found!

They seems to be set correctly for DatabaseDS and Starter.

-- System Information:
Debian Release: bullseye/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental-debug'), (1,
'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 5.4.0-2-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8),
LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages tango-accesscontrol depends on:
ii  init-system-helpers  1.57
ii  libc6                2.29-9
ii  libgcc1              1:9.2.1-23
ii  libmariadb3          1:10.3.21-2
ii  libomniorb4-2        4.2.2-0.9+b1
ii  libomnithread4       4.2.2-0.9+b1
ii  libstdc++6           9.2.1-23
ii  libtango-tools       9.3.4~rc2+dfsg2-1~exp3
ii  libtango9            9.3.4~rc2+dfsg2-1~exp3
ii  lsb-base             11.1.0
ii  tango-db             9.2.5a+dfsg1-2+b2
ii  tango-starter        9.2.5a+dfsg1-2+b2

tango-accesscontrol recommends no packages.

tango-accesscontrol suggests no packages.

-- no debconf information



More information about the debian-science-maintainers mailing list