diff mbox series

[v2,4/7] tpm2-abrmd: do not enforce -fstack-protector-all

Message ID 20190115101522.21042-4-peter@korsgaard.com
State Accepted
Commit db828b919214db5cc2cbce644a75db3e3d4f74d6
Headers show
Series [v2,1/7] tpm2-tss: do not enforce -fstack-protector-all | expand

Commit Message

Peter Korsgaard Jan. 15, 2019, 10:15 a.m. UTC
Stack protection is now controlled Buildroot wide with the BR2_SSP_*
options, so disable the explicit -fstack-protector-all so the SSP logic in
the toolchain wrapper is used instead.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
---
 package/tpm2-abrmd/tpm2-abrmd.mk | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

Comments

Peter Korsgaard Jan. 16, 2019, 1:25 p.m. UTC | #1
>>>>> "Peter" == Peter Korsgaard <peter@korsgaard.com> writes:

 > Stack protection is now controlled Buildroot wide with the BR2_SSP_*
 > options, so disable the explicit -fstack-protector-all so the SSP logic in
 > the toolchain wrapper is used instead.

 > Signed-off-by: Peter Korsgaard <peter@korsgaard.com>

Committed, thanks.
Peter Korsgaard Jan. 25, 2019, 7:29 a.m. UTC | #2
>>>>> "Peter" == Peter Korsgaard <peter@korsgaard.com> writes:

 > Stack protection is now controlled Buildroot wide with the BR2_SSP_*
 > options, so disable the explicit -fstack-protector-all so the SSP logic in
 > the toolchain wrapper is used instead.

 > Signed-off-by: Peter Korsgaard <peter@korsgaard.com>

Committed to 2018.11.x after adjusting the variable names for v1.3.0,
thanks.
diff mbox series

Patch

diff --git a/package/tpm2-abrmd/tpm2-abrmd.mk b/package/tpm2-abrmd/tpm2-abrmd.mk
index 74cc66ba20..2834615ac3 100644
--- a/package/tpm2-abrmd/tpm2-abrmd.mk
+++ b/package/tpm2-abrmd/tpm2-abrmd.mk
@@ -11,9 +11,10 @@  TPM2_ABRMD_LICENSE_FILES = LICENSE
 TPM2_ABRMD_INSTALL_STAGING = YES
 TPM2_ABRMD_DEPENDENCIES = dbus libglib2 tpm2-tss host-pkgconf
 
-# configure.ac doesn't contain a link test, so it doesn't detect when
-# libssp is missing.
-TPM2_ABRMD_CONF_ENV = ax_cv_check_cflags___________Werror_______fstack_protector_all=$(if $(BR2_TOOLCHAIN_HAS_SSP),yes,no)
+# -fstack-protector-all is used by default. Disable that so the
+# BR2_SSP_* options in the toolchain wrapper are used instead
+TPM2_ABRMD_CONF_ENV = \
+	ax_cv_check_cflags___________Werror_______fstack_protector_all=no
 
 TPM2_ABRMD_CONF_OPTS += \
 	--with-systemdsystemunitdir=$(if $(BR2_INIT_SYSTEMD),/usr/lib/systemd/system,no) \