- 主页 [ruderich.org]
build log hardening check
Perl tool which checks build logs for missing hardening flags. Hardening flags enable additional security features in the compiler to prevent e.g. stack overflows, format string vulnerabilities, GOT overwrites, etc. See e.g. <http://wiki.debian.org/ReleaseGoals/SecurityHardeningBuildFlags>.
Because most build systems are quite complicated there are many places where compiler flags from the environment might be ignored. The parser verifies that all compiler commands use the correct hardening flags and thus all hardening features are correctly used.
It's designed to check build logs generated by Debian's dpkg-buildpackage (or tools for packaging, using dpkg-buildpackage like pbuilder or the official buildd build logs) to help maintainers detect missing hardening flags in their packages.
Only gcc is detected as compiler at the moment (but other compilers maybe supported).
其他与 blhc 有关的软件包
- dep: libdpkg-perl
- Dpkg perl modules