[libkate] 01/01: Do hardening the old way until we upgrade to dh 9.

Petter Reinholdtsen pere at hungry.com
Fri Oct 24 13:40:10 UTC 2014


[Martin Steghöfer]
>     Do hardening the old way until we upgrade to dh 9.

This do not seem to work.  At least lintian report this when I build
in pbuilder:

E: libkate source: build-depends-on-obsolete-package build-depends: python-support => use dh_python2 instead
N: 
N:    The package build-depends on a package that has been superseded. If the
N:    superseded package is part of an ORed group, it should not be the first
N:    package in the group.
N:    
N:    Severity: important, Certainty: possible
N:    
N:    Check: fields, Type: binary, udeb, source
N: 
W: libkate1: hardening-no-relro usr/lib/libkate.so.1.3.0
N: 
N:    This package provides an ELF binary that lacks the "read-only
N:    relocation" link flag. This package was likely not built with the
N:    default Debian compiler flags defined by dpkg-buildflags. If built using
N:    dpkg-buildflags directly, be sure to import LDFLAGS.
N:    
N:    Refer to https://wiki.debian.org/Hardening for details.
N:    
N:    Severity: normal, Certainty: certain
N:    
N:    Check: binaries, Type: binary, udeb
N: 
I: libkate1: hardening-no-fortify-functions usr/lib/libkate.so.1.3.0
N: 
N:    This package provides an ELF binary that lacks the use of fortified libc
N:    functions. Either there are no potentially unfortified functions called
N:    by any routines, all unfortified calls have already been fully validated
N:    at compile-time, or the package was not built with the default Debian
N:    compiler flags defined by dpkg-buildflags. If built using
N:    dpkg-buildflags directly, be sure to import CPPFLAGS.
N:    
N:    NB: Due to false-positives, Lintian ignores some unprotected functions
N:    (e.g. memcpy).
N:    
N:    Refer to https://wiki.debian.org/Hardening and
N:    http://bugs.debian.org/673112 for details.
N:    
N:    Severity: normal, Certainty: wild-guess
N:    
N:    Check: binaries, Type: binary, udeb
N: 
W: libkate-tools: hardening-no-relro usr/bin/katalyzer
I: libkate-tools: hardening-no-fortify-functions usr/bin/katalyzer
W: libkate-tools: hardening-no-relro usr/bin/katedec
I: libkate-tools: hardening-no-fortify-functions usr/bin/katedec
W: libkate-tools: hardening-no-relro usr/bin/kateenc
I: libkate-tools: hardening-no-fortify-functions usr/bin/kateenc
E: libkate-tools: depends-on-obsolete-package depends: python-support (>= 0.90.0) => use dh_python2 instead
N: 
N:    The package depends on a package that has been superseded. If the
N:    superseded package is part of an ORed group, it should not be the first
N:    package in the group.
N:    
N:    Severity: important, Certainty: possible
N:    
N:    Check: fields, Type: binary, udeb, source
N: 
W: liboggkate1: hardening-no-relro usr/lib/liboggkate.so.1.2.2

Is this working for you.

-- 
Happy hacking
Petter Reinholdtsen



More information about the pkg-xiph-maint mailing list