nixpkgs/pkgs/stdenv/generic
Franz Pletz 3db93c351d cc-wrapper: add stack clash protection hardening flag
Most Linux distributions are enabling this these days and it does
protect against real world vulnerabilities as demonstrated by
CVE-2018-16864 and CVE-2018-16865.

Fix #53753.

Information on llvm version support gleaned from
6609892a2d
68e07da3e5
092507a730

Information on gcc version support a lot harder to gather,
but both 32bit and 64bit arm do appear to be supported
based on the test suite.
2024-06-07 20:23:46 +01:00
..
builder.sh
check-meta.nix Merge pull request #297987 from raboof/check-meta-fix-allow-predicate-instructions 2024-05-30 18:43:35 +02:00
common-path.nix
default-builder.sh treewide: refactor .attrs.sh detection 2023-10-04 18:36:57 +02:00
default.nix make-derivation.nix: Return mkDerivation as an attribute 2024-03-11 17:06:02 +01:00
make-derivation.nix cc-wrapper: add stack clash protection hardening flag 2024-06-07 20:23:46 +01:00
meta-types.nix stdenv/check-meta: Use bespoke type checking 2023-12-26 15:14:42 +13:00
setup.sh Annotate substituteStream deprecation warning 2024-05-25 18:32:10 +02:00