From Gentoo Wiki
< User:SamJump to:navigation Jump to:search
See also: User:Sam/TODO#Security.
State of the hardened profiles in 2021:
- Defaults to -fstack-clash-protection
- Defaults to -z,now
- About to add USE=cet to sys-devel/gcc which, when combined with USE=hardened, builds with -fcf-protection=full by default
- Migrate -fstack-clash-protection into main profiles? See bug #675050.
- Migrate -z,now to main profiles?
- Make CET on-by-default on hardened
- Move CET into main profiles, on by default