Hi Mentors,

I'm adopting package lostirc with problems to solve hardening issue.

The package builds ok but with lintian:
I: lostirc: hardening-no-fortify-functions usr/bin/lostirc

blhc --all ../lostirc_0.4.6-5_amd64.build 
Returns nothing but 

hardening-check -v debian/lostirc/usr/bin/lostirc 
debian/lostirc/usr/bin/lostirc:
 Position Independent Executable: yes
 Stack protected: yes
 Fortify Source functions: no, only unprotected functions found!
        unprotected: memmove
        unprotected: read
        unprotected: memcpy
        unprotected: gethostname
        unprotected: recv
 Read-only relocations: yes
 Immediate binding: yes

I verified build log and I found flag: -D_FORTIFY_SOURCE=2 at all cpp compile 
lines.
I uploaded to mentors.

https://mentors.debian.net/debian/pool/main/l/lostirc/lostirc_0.4.6-5.dsc

Can you help me?

Thanks
[]'s
kretcheu
:x

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to