[libkate] 01/01: Do hardening the old way until we upgrade to dh 9.
Petter Reinholdtsen
pere at hungry.com
Fri Oct 24 13:40:10 UTC 2014
[Martin Steghöfer]
> Do hardening the old way until we upgrade to dh 9.
This do not seem to work. At least lintian report this when I build
in pbuilder:
E: libkate source: build-depends-on-obsolete-package build-depends: python-support => use dh_python2 instead
N:
N: The package build-depends on a package that has been superseded. If the
N: superseded package is part of an ORed group, it should not be the first
N: package in the group.
N:
N: Severity: important, Certainty: possible
N:
N: Check: fields, Type: binary, udeb, source
N:
W: libkate1: hardening-no-relro usr/lib/libkate.so.1.3.0
N:
N: This package provides an ELF binary that lacks the "read-only
N: relocation" link flag. This package was likely not built with the
N: default Debian compiler flags defined by dpkg-buildflags. If built using
N: dpkg-buildflags directly, be sure to import LDFLAGS.
N:
N: Refer to https://wiki.debian.org/Hardening for details.
N:
N: Severity: normal, Certainty: certain
N:
N: Check: binaries, Type: binary, udeb
N:
I: libkate1: hardening-no-fortify-functions usr/lib/libkate.so.1.3.0
N:
N: This package provides an ELF binary that lacks the use of fortified libc
N: functions. Either there are no potentially unfortified functions called
N: by any routines, all unfortified calls have already been fully validated
N: at compile-time, or the package was not built with the default Debian
N: compiler flags defined by dpkg-buildflags. If built using
N: dpkg-buildflags directly, be sure to import CPPFLAGS.
N:
N: NB: Due to false-positives, Lintian ignores some unprotected functions
N: (e.g. memcpy).
N:
N: Refer to https://wiki.debian.org/Hardening and
N: http://bugs.debian.org/673112 for details.
N:
N: Severity: normal, Certainty: wild-guess
N:
N: Check: binaries, Type: binary, udeb
N:
W: libkate-tools: hardening-no-relro usr/bin/katalyzer
I: libkate-tools: hardening-no-fortify-functions usr/bin/katalyzer
W: libkate-tools: hardening-no-relro usr/bin/katedec
I: libkate-tools: hardening-no-fortify-functions usr/bin/katedec
W: libkate-tools: hardening-no-relro usr/bin/kateenc
I: libkate-tools: hardening-no-fortify-functions usr/bin/kateenc
E: libkate-tools: depends-on-obsolete-package depends: python-support (>= 0.90.0) => use dh_python2 instead
N:
N: The package depends on a package that has been superseded. If the
N: superseded package is part of an ORed group, it should not be the first
N: package in the group.
N:
N: Severity: important, Certainty: possible
N:
N: Check: fields, Type: binary, udeb, source
N:
W: liboggkate1: hardening-no-relro usr/lib/liboggkate.so.1.2.2
Is this working for you.
--
Happy hacking
Petter Reinholdtsen
More information about the pkg-xiph-maint
mailing list