Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
https://wiki.archlinux.org/title/Bug_reporting_guidelines
Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.
REPEAT: Do NOT report bugs for outdated packages!
FS#71372 - [glhack] FTBFS lacks FULL RELRO unsafe printf usage
Attached to Project:
Community Packages
Opened by loqs (loqs) - Sunday, 27 June 2021, 13:35 GMT
Last edited by George Rawlinson (rawlinsong) - Wednesday, 09 August 2023, 09:16 GMT
Opened by loqs (loqs) - Sunday, 27 June 2021, 13:35 GMT
Last edited by George Rawlinson (rawlinsong) - Wednesday, 09 August 2023, 09:16 GMT
|
DetailsDescription:
glhack fails during package due to the games group not being present because the systemd package which provides sysusers.d is not installed. glhack's Makefile does not use LDFLAGS leading to a lack of FULL RELRO. [3] Applies the changes for the issues above as well as applying a patch from Debian [2] for unsafe printf use. Additional info: * glhack 1.2-9 * [1] glhack-1.2-9-x86_64-package.log.xz [2] https://sources.debian.org/data/main/g/glhack/1.2-4/debian/patches/07-harden-build-flags.patch [3] PKGBUILD.diff Steps to reproduce: extra-x86_64-build |
This task depends upon
Closed by George Rawlinson (rawlinsong)
Wednesday, 09 August 2023, 09:16 GMT
Reason for closing: Fixed
Additional comments about closing: 1.2-10
Wednesday, 09 August 2023, 09:16 GMT
Reason for closing: Fixed
Additional comments about closing: 1.2-10
glhack-1.2-9-x86_64-package.l...
PKGBUILD.diff
You could contact Debian and ask if they submitted the patch authored eight years after glhack's last commit to upstream.
Alternatively to applying the patch -Wnoerror=format-security can be used to override -Werror=format-security.
[1] https://sourceforge.net/blog/decommissioning-cvs-for-commits/