2011/10/20 Anthony G. Basile <bluen...@gentoo.org>: > USE=hardened refers to only toolchain hardening. The problems there are > mostly packages which break with PIE because they (ab)use assembly. > Things like virtualbox and some codecs. This can become a thorny mess. > > It would probably be nearly painless to bring in -D_FORTIFY_SOURCES=2 > and ssp into mainstream though. Packages which break because of either > of those two features are broken and should be fixed anyhow. >
This sounds like good idea to do so, I would say that most hardened features should be merged to to main profile as soon as they won't cause major PITA for the regular users. Cheers Tom