[tor-bugs] #12103 [Tor bundles/installation]: Fully hardening firefox binary is broken since 3.5.3 on Linux

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri May 23 12:28:20 UTC 2014


#12103: Fully hardening firefox binary is broken since 3.5.3 on Linux
-------------------------------------+-------------------------------------
     Reporter:  gk                   |      Owner:  erinn
         Type:  defect               |     Status:  new
     Priority:  normal               |  Milestone:
    Component:  Tor                  |    Version:
  bundles/installation               |   Keywords:  tbb-security, tbb-
   Resolution:                       |  testcase
Actual Points:                       |  Parent ID:
       Points:                       |
-------------------------------------+-------------------------------------
Changes (by mikeperry):

 * keywords:  tbb-security => tbb-security, tbb-testcase


Comment:

 In January, there was this fix to binutils: "Update bfd to properly
 generate PT_GNU_RELRO segment for ld and objcopy. PRs 14207/16322/16323."
 http://gcc.gnu.org/ml/gcc/2014-01/msg00286.html

 It seems like RedHat may have independently patched this or a related
 issue in 2012: "Fix the creation of GNU_RELRO segments (#825736)"
 http://pkgs.org/centos-6/centos-
 x86_64/binutils-2.20.51.0.2-5.36.el6.x86_64.rpm.html

 It seems like running checksec regularly should be part of our test suite,
 to ensure against regressions like this when either the toolchain or how
 we use it changes.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/12103#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list