Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1455970 > unrolled thread

[PATCH] MIPS: dont specify STACKPROTECTOR in defconfigs

Started byPaul Gortmaker <paul.gortmaker@windriver.com>
First post2016-08-03 21:10 +0200
Last post2016-08-04 16:20 +0200
Articles 3 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH] MIPS: dont specify STACKPROTECTOR in defconfigs Paul Gortmaker <paul.gortmaker@windriver.com> - 2016-08-03 21:10 +0200
    Re: [PATCH] MIPS: dont specify STACKPROTECTOR in defconfigs James Hartley <james.hartley@imgtec.com> - 2016-08-04 00:50 +0200
    Re: [PATCH] MIPS: dont specify STACKPROTECTOR in defconfigs Ralf Baechle <ralf@linux-mips.org> - 2016-08-04 16:20 +0200

#1455970 — [PATCH] MIPS: dont specify STACKPROTECTOR in defconfigs

FromPaul Gortmaker <paul.gortmaker@windriver.com>
Date2016-08-03 21:10 +0200
Subject[PATCH] MIPS: dont specify STACKPROTECTOR in defconfigs
Message-ID<s29Id-6D8-1@gated-at.bofh.it>
Only one defconfig has a STACKPROTECTOR value.  And it asks for
the strong variant, which isn't supported by older toolchains.

Due to the nature of MIPS having more platform specific code than say
x86, the allyesconfig and allmodconfig aren't as effective for build
coverage.  So, in addition, I like to use a trivial script to walk all
the defconfigs and build each one.

However I will get false positives on unsupported stackprotector values
with an older toolchain like gcc-4.6.3.  As in this instance I am just
using the compiler as a glorified syntax checker on a machine where I
build a bunch of other arch for the same reason, there is no real
motivation to get a newer toolchain for improved optimization etc.

Since there is only one of them, and there is nothing about these
settings that are board/platform specific, I propose we just eliminate
the existing instance and take the default.

Cc: James Hartley <james.hartley@imgtec.com>
Cc: Ionela Voinescu <ionela.voinescu@imgtec.com>
Cc: Ralf Baechle <ralf@linux-mips.org>
Cc: linux-mips@linux-mips.org
Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com>
---
 arch/mips/configs/pistachio_defconfig | 1 -
 1 file changed, 1 deletion(-)

diff --git a/arch/mips/configs/pistachio_defconfig b/arch/mips/configs/pistachio_defconfig
index 8b7429127a1d..698631327c8c 100644
--- a/arch/mips/configs/pistachio_defconfig
+++ b/arch/mips/configs/pistachio_defconfig
@@ -29,7 +29,6 @@ CONFIG_CC_OPTIMIZE_FOR_SIZE=y
 CONFIG_EMBEDDED=y
 # CONFIG_COMPAT_BRK is not set
 CONFIG_PROFILING=y
-CONFIG_CC_STACKPROTECTOR_STRONG=y
 CONFIG_MODULES=y
 CONFIG_MODULE_UNLOAD=y
 CONFIG_MODULE_FORCE_UNLOAD=y
-- 
2.8.4

[toc] | [next] | [standalone]


#1456049

FromJames Hartley <james.hartley@imgtec.com>
Date2016-08-04 00:50 +0200
Message-ID<s2d97-iR-5@gated-at.bofh.it>
In reply to#1455970
Hi Paul,


On 03/08/16 20:03, Paul Gortmaker wrote:
> Only one defconfig has a STACKPROTECTOR value.  And it asks for
> the strong variant, which isn't supported by older toolchains.
>
> Due to the nature of MIPS having more platform specific code than say
> x86, the allyesconfig and allmodconfig aren't as effective for build
> coverage.  So, in addition, I like to use a trivial script to walk all
> the defconfigs and build each one.
>
> However I will get false positives on unsupported stackprotector values
> with an older toolchain like gcc-4.6.3.  As in this instance I am just
> using the compiler as a glorified syntax checker on a machine where I
> build a bunch of other arch for the same reason, there is no real
> motivation to get a newer toolchain for improved optimization etc.
>
> Since there is only one of them, and there is nothing about these
> settings that are board/platform specific, I propose we just eliminate
> the existing instance and take the default.
Are you sure that this is not platform specific - my understanding is
that this can be used to give a small security enhancement, which could
be platform rather than arch specific.  Either way, I don't believe that
pistachio requires this option, so:

Acked-by: James Hartley <james.hartley@imgtec.com>

James.

>
> Cc: James Hartley <james.hartley@imgtec.com>
> Cc: Ionela Voinescu <ionela.voinescu@imgtec.com>
> Cc: Ralf Baechle <ralf@linux-mips.org>
> Cc: linux-mips@linux-mips.org
> Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com>
> ---
>  arch/mips/configs/pistachio_defconfig | 1 -
>  1 file changed, 1 deletion(-)
>
> diff --git a/arch/mips/configs/pistachio_defconfig b/arch/mips/configs/pistachio_defconfig
> index 8b7429127a1d..698631327c8c 100644
> --- a/arch/mips/configs/pistachio_defconfig
> +++ b/arch/mips/configs/pistachio_defconfig
> @@ -29,7 +29,6 @@ CONFIG_CC_OPTIMIZE_FOR_SIZE=y
>  CONFIG_EMBEDDED=y
>  # CONFIG_COMPAT_BRK is not set
>  CONFIG_PROFILING=y
> -CONFIG_CC_STACKPROTECTOR_STRONG=y
>  CONFIG_MODULES=y
>  CONFIG_MODULE_UNLOAD=y
>  CONFIG_MODULE_FORCE_UNLOAD=y

[toc] | [prev] | [next] | [standalone]


#1456427

FromRalf Baechle <ralf@linux-mips.org>
Date2016-08-04 16:20 +0200
Message-ID<s2rF7-1SU-19@gated-at.bofh.it>
In reply to#1455970
On Wed, Aug 03, 2016 at 03:03:59PM -0400, Paul Gortmaker wrote:

> Only one defconfig has a STACKPROTECTOR value.  And it asks for
> the strong variant, which isn't supported by older toolchains.
> 
> Due to the nature of MIPS having more platform specific code than say
> x86, the allyesconfig and allmodconfig aren't as effective for build
> coverage.  So, in addition, I like to use a trivial script to walk all
> the defconfigs and build each one.
> 
> However I will get false positives on unsupported stackprotector values
> with an older toolchain like gcc-4.6.3.  As in this instance I am just
> using the compiler as a glorified syntax checker on a machine where I
> build a bunch of other arch for the same reason, there is no real
> motivation to get a newer toolchain for improved optimization etc.
> 
> Since there is only one of them, and there is nothing about these
> settings that are board/platform specific, I propose we just eliminate
> the existing instance and take the default.

Yeah, I can see how that one may get annoying.  I wish there was something
along the lines of KCONFIG_ALLCONFIG that was working not only for
allyesconfig/allmodconfig/allnoconfig/randconfig.

Applied.  Thanks,

  Ralf

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web