Community Packages

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#68955 - [alacritty] Security hardening options

Attached to Project: Community Packages
Opened by N.T. (NikTo) - Saturday, 12 December 2020, 15:30 GMT
Last edited by Morten Linderud (Foxboron) - Saturday, 19 December 2020, 10:50 GMT
Task Type Bug Report
Category Packages
Status Closed
Assigned To No-one
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Hello!

Description:
* STACK CANARY - no canary found;
* FORTIFY - no.

Additional info
* alacritty 0.6.0-1
* https://wiki.archlinux.org/index.php/Arch_package_guidelines/Security

Steps to reproduce:
$ checksec --verbose --extended --output=cli --file=/usr/bin/alacritty
This task depends upon

Closed by  Morten Linderud (Foxboron)
Saturday, 19 December 2020, 10:50 GMT
Reason for closing:  Upstream
Additional comments about closing:  All hardening that can be enabled has been enabled in the package. If there are missing features you need to look at upstream.
Comment by loqs (loqs) - Saturday, 12 December 2020, 22:18 GMT
@NikTo do you have a fix for the PKGBUILD that enables the missing hardening options? Does this not apply to all rust packages?

See also [1] [2].

[1] https://github.com/rust-lang/rust/issues/15179
[2] https://stackoverflow.com/questions/48547475/how-to-add-stack-canaries-to-rust-executables
Comment by N.T. (NikTo) - Sunday, 13 December 2020, 08:16 GMT
@loqs | I don't have a fix. But I see that some other rust packages have the stack protection (bat,exa,fd,toastify).

Loading...