Re: [PATCH] debian: enable build hardening features

2019-06-11 Thread David Bremner
Daniel Kahn Gillmor writes: > Debian's build hardening toolchain options produce binary artifacts > that are more resistant to compromise. The most visible change for > notmuch today is likely to be the addition of the "bindnow" linker > flag, which contributes to making the "Global Offset

[PATCH] debian: enable build hardening features

2019-06-10 Thread Daniel Kahn Gillmor
Debian's build hardening toolchain options produce binary artifacts that are more resistant to compromise. The most visible change for notmuch today is likely to be the addition of the "bindnow" linker flag, which contributes to making the "Global Offset Table" fully read-only. See