From mboxrd@z Thu Jan 1 00:00:00 1970 From: Thomas Petazzoni Date: Wed, 6 Feb 2019 16:40:27 +0100 Subject: [Buildroot] [RFC PATCH 1/2] annobin: New package In-Reply-To: <62ae845de2ae3fe09dbdb9c0cc00cddd92e86362.camel@spectralink.com> References: <20180503143147.5301-1-stefan.sorensen@spectralink.com> <20180503143147.5301-2-stefan.sorensen@spectralink.com> <20190206160450.0b2a899c@windsurf> <62ae845de2ae3fe09dbdb9c0cc00cddd92e86362.camel@spectralink.com> Message-ID: <20190206164027.502ae567@windsurf> List-Id: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: buildroot@busybox.net Hello, On Wed, 6 Feb 2019 15:27:52 +0000 "S?rensen, Stefan" wrote: > On Wed, 2019-02-06 at 16:04 +0100, Thomas Petazzoni wrote: > > > This one is already in Buildroot, and is a lot easier to integrate > > than a gcc plugin. So unless you see an issue with checksec that is > > solved by annobin, we'll probably stick to using checksec. > > The issue with checksec is that is only checks if *some* of the code in > the binary is compiled with the correct security options - it does not > detect that the correct options has not been used for compiling all of > the code. Ah, OK. > Unfortunately I do not have any time right now to spend on this, but I > hope that I will be able to update this to a more recent annobin relase > soon. Yes, please send a new series when you have some time then. Thomas -- Thomas Petazzoni, CTO, Bootlin Embedded Linux and Kernel engineering https://bootlin.com