|
From: Heiko Z. <smi...@us...> - 2007-10-22 13:13:35
|
Update of /cvsroot/devil-linux/build/scripts In directory sc8-pr-cvs12.sourceforge.net:/tmp/cvs-serv26519/scripts Modified Files: binutils gcc-4 glibc heartbeat ipsec-tools mdadm minicom Log Message: - updated minicom-2.3 to rc1 - updated nfs-utils to 1.1.1 - updated quagga to 0.99.9-20071018 - updated mdadm to 2.6.4 - updated heartbeat to 2.1.2 - synced gcc hardened specs with current HLFS - updated glibc to 2.5.1 - updated ipsec-tools to 0.7 Index: glibc =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/glibc,v retrieving revision 1.53 retrieving revision 1.54 diff -u -d -r1.53 -r1.54 --- glibc 1 May 2007 00:30:31 -0000 1.53 +++ glibc 22 Oct 2007 13:13:07 -0000 1.54 @@ -48,17 +48,19 @@ touch devil-linux-glibc-patches.done fi - if [ ! -f devil-linux-glibc-hardened.done ]; then + # don't install pt_chown + sed '/^install.*pt_chown/d' -i.orig login/Makefile + + if [ "$CONFIG_GCC_HARDENED" = "y" ]; then + if [ ! -f devil-linux-glibc-hardened.done ]; then for PATCH in $(ls ../glibc-hardened/*) do echo applying patch: $PATCH patch -i $PATCH -p1 || exit 1 done touch devil-linux-glibc-hardened.done - fi - - if [ "$CONFIG_GCC_HARDENED" = "y" ]; then - if [ ! -f .done_hardened ]; then + fi + if [ ! -f .done_hardened ]; then # all of this stuff is stolen from the HLFS book #Use PIC assembly code in the utility programs: @@ -77,28 +79,14 @@ # -fstack-protector-all in our GCC specs. nscd can compile with -fstack-protector-all, so fix that: sed 's/fstack-protector/&-all/' -i.orig nscd/Makefile - # This next command adds the stack_chk_fail_local function to libc.so so that libc.so can be compiled - # with -fstack-protector (by the hardened GCC specs): - sed 's/^$(common-objpfx)libc.so: $(elfobjdir)\/soinit.os \\/&\ - \t\t\t $(common-objpfx)debug\/stack_chk_fail_local.oS \\/' \ - -i.orig Makerules - # These next commands add -fno-stack-protector to a few places: - sed 's/^CPPFLAGS += -DHAVE_INITFINI/& -fno-stack-protector/' \ - -i.orig csu/Makefile - sed 's/^CPPFLAGS-.os +=/& -fno-stack-protector/' \ - -i.orig elf/Makefile - sed 's/^CFLAGS-rtld :=/& -fno-stack-protector/' \ - -i.orig elf/rtld-Rules - sed -e 's/^CFLAGS-init.c =/& -fno-stack-protector/' \ - -e 's/^CFLAGS-unwind.* =/& -fno-stack-protector/' \ - -i nptl/Makefile + #The ldconfig program is statically linked. The next command adds compiler options so it will not be built as PIC unnessessarily: + sed 's/CFLAGS-ldconfig.c =/& -fno-PIC -fno-PIE/' -i.orig elf/Makefile + # Add MUDFLAP_OPTIONS to the list of environment variables which are removed by libc for suid programs. # This will keep local users, including root, from disabling bounds checking on suid programs linked to libmudflap.so: sed 's/#define UNSECURE_ENVVARS.*/&\ "MUDFLAP_OPTIONS\\0" \\/' -i.orig sysdeps/generic/unsecvars.h - # Add -nonow to CC so the testsuite will have better results. When Glibc's build uses -Wl,-z,now it will supersede this -nonow option: - sed 's/^CC =.*/& -nonow/' -i.orig config.make touch .done_hardened fi fi @@ -111,8 +99,42 @@ ../glibc-2*/configure --prefix=/usr --disable-profile --enable-add-ons --libexecdir=/usr/lib/glibc \ --enable-kernel=2.6.0 --enable-bind-now --enable-stackguard-randomization || exit 1 + + if [ "$CONFIG_GCC_HARDENED" = "y" ]; then + # The Glibc libraries can not be built with -fstack-protector[-all], -D_FORTIFY_SOURCE, or -Wl,-z,now. + echo 'build-programs=no +CC = gcc -fPIC -fno-stack-protector -U_FORTIFY_SOURCE -nonow -nopie +CXX = g++ -fPIC -fno-stack-protector -U_FORTIFY_SOURCE -nonow -nopie +' > configparms + make $PMAKE || exit 1 + rm -v configparms + # Glibc links startfiles explicitly. The following will modify the link command used, so that the programs + # will be linked to the sharable startfiles, and explicitly use -fPIE. The sln is another statically + #linked program, so options are added so it is not compiled as PIC: + echo 'CC = gcc -fPIE +CXX = g++ -fPIE +CFLAGS-sln.c += -fno-PIC -fno-PIE ++link = $(CC) -nostdlib -nostartfiles -fPIE -pie -o $@ \ + $(sysdep-LDFLAGS) $(config-LDFLAGS) $(LDFLAGS) $(LDFLAGS-$(@F)) \ + -Wl,-z,combreloc -Wl,-z,relro -Wl,-z,now $(hashstyle-LDFLAGS) \ + $(addprefix $(csu-objpfx),S$(start-installed-name)) \ + $(+preinit) `$(CC) --print-file-name=crtbeginS.o` \ + $(filter-out $(addprefix $(csu-objpfx),start.o \ + $(start-installed-name))\ + $(+preinit) $(link-extra-libs) \ + $(common-objpfx)libc% $(+postinit),$^) \ + $(link-extra-libs) $(link-libc) `$(CC) --print-file-name=crtendS.o` $(+postinit) +' > configparms + make $PMAKE || exit 1 + + rm -v configparms +echo 'CC = gcc -fPIC -fno-stack-protector -U_FORTIFY_SOURCE -nonow -nopie +CXX = g++ -fPIC -fno-stack-protector -U_FORTIFY_SOURCE -nonow -nopie +' > configparms + else + make $PMAKE || exit 1 + fi - make $PMAKE || exit 1 strip_debug || exit 1 # we have to install this immediately, because this is a library and could be needed by other sources @@ -120,13 +142,13 @@ make install install_root=$TMPDIR || exit 1 # ok we need to do this a little tricky, otherwise all hell breaks loose - cd $TMPDIR || exit 1 + pushd $TMPDIR || exit 1 mkdir -p $TMPDIR/etc || exit 1 touch $TMPDIR/etc/ld.so.conf tar -cf glibc.tar * || exit 1 tar -C / -xf glibc.tar || exit 1 - cd .. || exit 1 - + popd || exit 1 + rm -rf $TMPDIR || exit 1 ;; Index: minicom =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/minicom,v retrieving revision 1.8 retrieving revision 1.9 diff -u -d -r1.8 -r1.9 --- minicom 19 Apr 2007 15:39:21 -0000 1.8 +++ minicom 22 Oct 2007 13:13:07 -0000 1.9 @@ -39,8 +39,6 @@ rm -rf $TMPDIR || exit 1 mkdir -p $TMPDIR || exit 1 make install DESTDIR=$TMPDIR || exit 1 - mkdir -p $TMPDIR/usr/share/man || exit 1 - mv $TMPDIR/usr/man/* $TMPDIR/usr/share/man/ || exit 1 copy_files $TMPDIR/usr $CDDIR || exit 1 rm -rf $TMPDIR || exit 1 fi Index: ipsec-tools =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/ipsec-tools,v retrieving revision 1.9 retrieving revision 1.10 diff -u -d -r1.9 -r1.10 --- ipsec-tools 31 Jul 2007 12:23:53 -0000 1.9 +++ ipsec-tools 22 Oct 2007 13:13:07 -0000 1.10 @@ -37,7 +37,8 @@ fi ./bootstrap CC="gcc -D_FORTIFY_SOURCE=0" ./configure --prefix=/usr --localstatedir=/var --sysconfdir=/etc/ipsec-tools --with-kernel-headers=/usr/include \ - --enable-frag --enable-stats --enable-dpd --enable-natt --with-libpam --with-libradius=$LIBRADIUSDIR $GSSAPI --enable-hybrid --enable-adminport || exit 1 + --enable-frag --enable-stats --enable-dpd --enable-natt --with-libpam --with-libradius=$LIBRADIUSDIR $GSSAPI --enable-hybrid \ + --enable-adminport --disable-security-context || exit 1 make || exit 1 make install || exit 1 strip_debug Index: heartbeat =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/heartbeat,v retrieving revision 1.11 retrieving revision 1.12 diff -u -d -r1.11 -r1.12 --- heartbeat 19 Apr 2007 15:39:21 -0000 1.11 +++ heartbeat 22 Oct 2007 13:13:07 -0000 1.12 @@ -32,7 +32,9 @@ SNMP="--disable-snmp" fi - CFLAGS="-D_FORTIFY_SOURCE=0" ./configure --prefix=/usr --localstatedir=/var --sysconfdir=/etc ${SNMP} || exit 1 + #CFLAGS="-D_FORTIFY_SOURCE=0" + #CC="gcc -nopie -fno-stack-protector" + CFLAGS="-fno-stack-protector -D_FORTIFY_SOURCE=0" ./configure --prefix=/usr --localstatedir=/var --sysconfdir=/etc ${SNMP} || exit 1 make $PMAKE all || exit 1 strip_debug Index: gcc-4 =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/gcc-4,v retrieving revision 1.2 retrieving revision 1.3 diff -u -d -r1.2 -r1.3 --- gcc-4 19 Apr 2007 15:39:21 -0000 1.2 +++ gcc-4 22 Oct 2007 13:13:07 -0000 1.3 @@ -36,100 +36,34 @@ touch gcc-patches.done fi - sed -i 's/install_to_$(INSTALL_DEST) //' libiberty/Makefile.in - #replace_str gcc/Makefile.in "CFLAGS = -g" "CFLAGS = -g -D_LIBC_PROVIDES_SSP_" - #replace_str gcc/Makefile.in "BOOT_CFLAGS = -g -O2" "CFLAGS=-g -O2 -D_LIBC_PROVIDES_SSP_" - sed -i 's/^XCFLAGS =$/& -fomit-frame-pointer/' gcc/Makefile.in - sed -i 's@\./fixinc\.sh@-c true@' gcc/Makefile.in - sed -i 's/@have_mktemp_command@/yes/' gcc/gccbug.in - if [ "$CONFIG_GCC_HARDENED" = "y" ]; then # and now make sure we use SSP and other stuff when compiling # thanks to Robert Connolly and the HLFS project + if [ ! -f gcc-patches-fortify_source.done ]; then + echo "applying gcc fortify_source patch" + bzcat $DL_DIR/src/gcc-4*-fortify_source-*.patch.bz2 | patch -p1 || exit 1 + touch gcc-patches-fortify_source.done + fi + if [ ! -f gcc-patches-fstack_protector.done ]; then + echo "applying gcc pie patch" + bzcat $DL_DIR/src/gcc-4*-fstack_protector-*.patch.bz2 | patch -p1 || exit 1 + touch gcc-patches-fstack_protector.done + fi + if [ ! -f gcc-patches-pie.done ]; then + echo "applying gcc pie patch" + bzcat $DL_DIR/src/gcc-4*-fpie-*.patch.bz2 | patch -p1 || exit 1 + touch gcc-patches-pie.done + fi - #The following file redefines GCC's default behaviour to add various options: -echo '#ifndef HARDENED_SPECS_H -#define HARDENED_SPECS_H - -#if defined(__i386__) && defined(__linux__) && defined(__ELF__) \ - && defined(HAVE_LD_PIE) && defined(TARGET_LIBC_PROVIDES_SSP) - -#undef CPP_SPEC -#define CPP_SPEC "%{posix:-D_POSIX_SOURCE} %{pthread:-D_REENTRANT} \ - %{D_FORTIFY_SOURCE*|D_LIBC_REENTRANT:;:-D_FORTIFY_SOURCE=2}" - -#undef CC1_SPEC -#define CC1_SPEC "%(cc1_cpu) %{profile:-p} \ - %{D__KERNEL__|fpic|fPIC|fpie|fPIE|fno-pic|fno-PIC \ - :;shared|nostdlib|nostartfiles:-fPIC} \ - %{static|D__KERNEL__|fpic|fPIC|fpie|fPIE|fno-pie|fno-PIE| \ - shared|nostdlib|nostartfiles:;:-fPIE} \ - %{D__KERNEL__|fno-stack-protector|fstack-protector| \ - fstack-protector-all:;D_LIBC_REENTRANT:-fstack-protector;: \ - -fstack-protector-all} %{D_FORTIFY_SOURCE*|D_LIBC_REENTRANT|O*:;:-O}" - -#undef CC1PLUS_SPEC -#define CC1PLUS_SPEC \ - "%{D__KERNEL__|fpic|fPIC|fpie|fPIE|fno-pic|fno-PIC \ - :;shared|nostdlib|nostartfiles:-fPIC} \ - %{static|D__KERNEL__|fpic|fPIC|fpie|fPIE|fno-pie|fno-PIE| \ - shared|nostdlib|nostartfiles:;:-fPIE} \ - %{D__KERNEL__|fno-stack-protector|fstack-protector| \ - fstack-protector-all:;D_LIBC_REENTRANT:-fstack-protector;: \ - -fstack-protector-all} %{D_FORTIFY_SOURCE*|D_LIBC_REENTRANT|O*:;:-O}" - -#undef ENDFILE_SPEC -#define ENDFILE_SPEC "%{ffast-math|funsafe-math-optimizations: \ - crtfastmath.o%s} \ - %{static|nopie:crtend.o%s;:crtendS.o%s} crtn.o%s" - -#undef STARTFILE_SPEC -#define STARTFILE_SPEC "%{shared:;pg|p|profile:gcrt1.o%s; \ - static|nopie:crt1.o%s;:Scrt1.o%s} crti.o%s \ - %{static:crtbeginT.o%s;nopie:crtbegin.o%s;:crtbeginS.o%s}" - -#undef LINK_PIE_SPEC -#define LINK_PIE_SPEC "%{pie:-pie} %{!static:%{!Bstatic: \ - %{nonow:-z lazy;:-z now} %{norelro:-z norelro;:-z relro} \ - %{nocombreloc:-z nocombreloc;:-z combreloc} \ - %{shared|Bshareable|i|r|pie|nopie:;:-pie}}}" - -#else /* __i386__ && __linux__ && __ELF__ && HAVE_LD_PIE */ -#error "You are using an unsupported system. This header can not be used." -#endif /* __i386__ && __linux__ && __ELF__ && HAVE_LD_PIE */ -#endif /* HARDENED_SPECS_H */' > gcc/hardened-specs.h - - #This command includes the hardened-specs header in the right place: - cp -vi gcc/gcc.c{,.orig} - sed '0,/.*config.h can define.*/s//#include "hardened-specs.h"\n&/' \ - gcc/gcc.c.orig > gcc/gcc.c - - # Don't build libssp.[a,so] with -fstack-protector[-all]. This library - # won't be used but will be built and installed: - cp -vi libssp/Makefile.in{,.orig} - sed 's/^AM_CFLAGS =/& -fno-stack-protector/' \ - libssp/Makefile.in.orig > libssp/Makefile.in - - # Don't build libgcc.[a,so] with -fstack-protector[-all]. libgcc.a is often linked into - # other static libraries and they will fail to resolve __stack_chk symbols: - cp -vi gcc/Makefile.in{,.orig3} - sed 's/^LIBGCC2_CFLAGS =/& -fno-stack-protector/' \ - gcc/Makefile.in.orig3 > gcc/Makefile.in - - # Don't build crtbegin[,S,T].o or crtend[,S].o files with -fstack-protector[-all]. These libraries should be - # devoid of dependencies (including the depenency to libc for SSP functions): - cp -vi gcc/Makefile.in{,.orig4} - sed 's/^CRTSTUFF_CFLAGS =/& -fno-stack-protector/' \ - gcc/Makefile.in.orig4 > gcc/Makefile.in - - sed 's/violation_mode = viol_nop/violation_mode = viol_abort/' \ - -i.orig libmudflap/mf-runtime.c - - # - EXTRAOPTIONS="$EXTRAOPTIONS gcc_cv_libc_provides_ssp=yes" + #EXTRAOPTIONS="$EXTRAOPTIONS gcc_cv_libc_provides_ssp=yes" CONFIG_EXTRA="$CONFIG_EXTRA --disable-werror" fi + # This version of GCC has a small bug/typo with RPATH_ENVVAR value for bfd and opcode. + # Use the following commands to fix this bug, so that .--enable-shared. will work: + cp -v Makefile.in{,.orig} + sed -e 's@/.:$$r@/.libs:$$r@' -e 's@/.:@/.libs:@' Makefile.in.orig > Makefile.in + rm -rf ../gcc4-build mkdir ../gcc4-build || exit 1 cd ../gcc4-build || exit 1 @@ -142,7 +76,9 @@ # install it, so we use the same version everywhere make install || exit 1 - + + # Install the libiberty header file that is needed by some packages + install -v -m0644 ../gcc-4*/include/libiberty.h /usr/include ;; Index: mdadm =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/mdadm,v retrieving revision 1.11 retrieving revision 1.12 diff -u -d -r1.11 -r1.12 --- mdadm 6 Jul 2007 04:19:17 -0000 1.11 +++ mdadm 22 Oct 2007 13:13:07 -0000 1.12 @@ -27,11 +27,11 @@ build ) if [ "$CONFIG_MDADM" = "y" ]; then if [ ! -f devil-linux-mdadm-patch.done ]; then - bzcat $DL_DIR/src/mdadm-*.patch.bz2 | patch -p1 || exit 1 + #bzcat $DL_DIR/src/mdadm-*.patch.bz2 | patch -p1 || exit 1 touch devil-linux-mdadm-patch.done fi - make $PMAKE all || exit 1 + make CC="gcc -D_FORTIFY_SOURCE=0" $PMAKE all || exit 1 strip_debug fi ;; Index: binutils =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/binutils,v retrieving revision 1.16 retrieving revision 1.17 diff -u -d -r1.16 -r1.17 --- binutils 23 Apr 2007 20:17:58 -0000 1.16 +++ binutils 22 Oct 2007 13:13:07 -0000 1.17 @@ -47,7 +47,7 @@ #make headers -C bfd || exit 1 - CC="gcc -D_FORTIFY_SOURCE=0" $WORKDIR/binutils-2*/configure --prefix=/usr --localstatedir=/var --enable-shared || exit 1 + CC="gcc -D_FORTIFY_SOURCE=0" $WORKDIR/binutils-2*/configure --prefix=/usr --localstatedir=/var --enable-shared --disable-werror || exit 1 make tooldir=/usr all || exit 1 strip_debug |