Your message dated Sun, 08 Apr 2012 08:47:29 +0000
with message-id <[email protected]>
and subject line Bug#667926: fixed in browser-history 2.8-15
has caused the Debian Bug report #667926,
regarding browser-history: CPPFLAGS hardening flags missing
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
667926: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=667926
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: browser-history
Version: 2.8-14
Severity: important
Tags: patch

Dear Maintainer,

The CPPFLAGS hardening flags are missing because the build system
ignores them.

The following patch fixes the issue by adding them to CFLAGS. For
more hardening information please have a look at [1], [2] and
[3].

diff -Nru browser-history-2.8/debian/rules browser-history-2.8/debian/rules
--- browser-history-2.8/debian/rules    2012-04-02 13:30:27.000000000 +0200
+++ browser-history-2.8/debian/rules    2012-04-07 16:53:36.000000000 +0200
@@ -10,7 +10,7 @@
 else
 CROSS := CC=$(DEB_HOST_GNU_TYPE)-gcc
 endif
-FLAGS := CFLAGS='$(shell dpkg-buildflags --get CFLAGS) -Wall' \
+FLAGS := CFLAGS='$(shell dpkg-buildflags --get CFLAGS) $(shell dpkg-buildflags 
--get CPPFLAGS) -Wall' \
         LDFLAGS='$(shell dpkg-buildflags --get LDFLAGS)'
 
 override_dh_auto_build:

To check if all flags were correctly enabled you can use
`hardening-check` from the hardening-includes package and check
the build log (hardening-check doesn't catch everything):

    $ hardening-check /usr/bin/browser-history
    /usr/bin/browser-history:
     Position Independent Executable: no, normal executable!
     Stack protected: yes
     Fortify Source functions: yes (some protected functions found)
     Read-only relocations: yes
     Immediate binding: no not found!

(Position Independent Executable and Immediate binding is not
enabled by default.)

Use find -type f \( -executable -o -name \*.so\* \) -exec
hardening-check {} + on the build result to check all files.

Regards,
Simon

[1]: https://wiki.debian.org/ReleaseGoals/SecurityHardeningBuildFlags
[2]: https://wiki.debian.org/HardeningWalkthrough
[3]: https://wiki.debian.org/Hardening
-- 
+ privacy is necessary
+ using gnupg http://gnupg.org
+ public key id: 0x92FEFDB7E44C32F9

Attachment: signature.asc
Description: Digital signature


--- End Message ---
--- Begin Message ---
Source: browser-history
Source-Version: 2.8-15

We believe that the bug you reported is fixed in the latest version of
browser-history, which is due to be installed in the Debian FTP archive:

browser-history_2.8-15.debian.tar.gz
  to main/b/browser-history/browser-history_2.8-15.debian.tar.gz
browser-history_2.8-15.dsc
  to main/b/browser-history/browser-history_2.8-15.dsc
browser-history_2.8-15_i386.deb
  to main/b/browser-history/browser-history_2.8-15_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Colin Watson <[email protected]> (supplier of updated browser-history package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 08 Apr 2012 09:28:51 +0100
Source: browser-history
Binary: browser-history
Architecture: source i386
Version: 2.8-15
Distribution: unstable
Urgency: low
Maintainer: Colin Watson <[email protected]>
Changed-By: Colin Watson <[email protected]>
Description: 
 browser-history - User daemon that tracks URLs looked at and logs them
Closes: 667926
Changes: 
 browser-history (2.8-15) unstable; urgency=low
 .
   * Honour 'dpkg-buildflags --get CPPFLAGS' (thanks, Simon Ruderich; closes:
     #667926).
Checksums-Sha1: 
 138a4266de90b45496747ff27b8a26dfd78e889e 1835 browser-history_2.8-15.dsc
 6c48b6b07ebaf3f3222bf23fa4b85f4f031d279d 19118 
browser-history_2.8-15.debian.tar.gz
 09f972da28bddc6bc5cb1edf2e43dbb28c152d00 35292 browser-history_2.8-15_i386.deb
Checksums-Sha256: 
 db29720bd2729590323d44090441a86b32d0908aa0ebad486d44dc87d2ed8706 1835 
browser-history_2.8-15.dsc
 7c735f479b1fa1e905f0eccb6c708d963875d44a02c6067b60df93fb73869f37 19118 
browser-history_2.8-15.debian.tar.gz
 4c20f5038622eb54f03118a380991bb704845ac1914c35743585bce04e07c47d 35292 
browser-history_2.8-15_i386.deb
Files: 
 e493b9d28c2ca25206266e1d77665bb9 1835 web optional browser-history_2.8-15.dsc
 40aef0fc954c2b18b837bf072c5c8925 19118 web optional 
browser-history_2.8-15.debian.tar.gz
 9ae985c85c0b6084b9d5fe00dda26921 35292 web optional 
browser-history_2.8-15_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Colin Watson <[email protected]> -- Debian developer

iQIVAwUBT4FPLjk1h9l9hlALAQhtMQ/8CKII22HXlAFZ2ILY+/WG5yjGqdzPbXc5
RmwU4ks5GGaJ4IqhkGQVPBcvJPO6MJby2BdqVFRX4txxV1UZulM/2DrhEJD8v0GZ
fEOYYq/bNo98hAzTgaJQpysr26PWcs1SjZc2qcGu/g/iRlNjyqIUU0HFri4STquA
mb9T+nlny03LY1ZY2vW+GIyuB8YxnPCfsabJrq6T+R65uGrE3xvnSv3FMWZAJLtV
mBEpPLiu8Obtq5t8a3m/4hsrcbfm6xjEsUl0KsvyNTPn0+PiPUQ2z0IGwYrlPV6O
brUx5VqKQj1KFYf7rX9FpTVoE8HOAApZUcHIe7Ss5O3mavnFPd56IrguU2akajBs
UbOYEcHBhwfKVnv/2E7Plc9KtVDpxqlLFoghpZygNFNHq3yGQ8NEhwW0py0+ct2j
G8CJFHj55KVLdVZq3CIIZeUu3QeqLTDNNUyyNnKXnnG97/XYdtH3peBLjdYD06k8
X3rui2f34hiHUiCX+HAjtJSNTmvPr0nPNg309KW5gU/QObPqN7zj6ZdMpetGA88n
oKJNuNfNr93+I5EvEKZZuhaqhjjXFAvxtH0NNHlKPTAsjxuyaJACFEuLKxXTz2Mm
4R0PEochA3kDbUKYSUzQjnDglcmOxsFh1CRY1baqJXOn4dSO07zUACK6nAX+f4CO
u27k+kshxjg=
=26zx
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to