[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xen-devel] Re: -fpie or ssp (IBM stack hardening)



Jerome Brown wrote:
B.G. Bruce wrote:

Has anyone looked into how compatible XEN is with pie (-fpie) or ssp?


Yes, I've tried it on gentoo-hardened with PIE(ET_DYN)/SSP.
I works without any problems.

But .. Is there any other purpose in compiling the system as PIE, other than for using PaX ?

Unfortunately, nobody is porting PaX to XEN ... very bad, especially if we're talking about secure systems.

Lack of PaX for XEN prevents me from using xen on my servers.

--
voices (at) metallicrain (dot) com



-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxxxx
https://lists.sourceforge.net/lists/listinfo/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.