[openssh-commits] [openssh] branch V_10_5 updated: Don't automatically enable FORTIFY_SOURCE.

git+noreply at mindrot.org git+noreply at mindrot.org
Mon Oct 5 18:10:39 AEDT 2026


This is an automated email from the git hooks/post-receive script.

dtucker pushed a commit to branch V_10_5
in repository openssh.

The following commit(s) were added to refs/heads/V_10_5 by this push:
     new 66a0ea3b9 Don't automatically enable FORTIFY_SOURCE.
66a0ea3b9 is described below

commit 66a0ea3b97bfc68ef2b59e635e2065b64d18004d
Author: Darren Tucker <dtucker at dtucker.net>
AuthorDate: Mon Oct 5 17:08:15 2026 +1100

    Don't automatically enable FORTIFY_SOURCE.
    
    It can cause problems on some platforms, in particular NetBSD <11 since
    it will cause function pointer comparisons in atomicio to fail and some
    things including scp to hang.  Previously we had a workaround but that
    was removed in a765b86d.  See NetBSD bug 45200 and pkgsrc bug pkg/60563.
---
 configure    | 161 -----------------------------------------------------------
 configure.ac |   1 -
 2 files changed, 162 deletions(-)

diff --git a/configure b/configure
index d85e0d58a..8c5cac361 100755
--- a/configure
+++ b/configure
@@ -9022,167 +9022,6 @@ printf "%s\n" "$ac_res" >&6; }
 }
     if test "x$use_toolchain_hardening" = "x1"; then
 	{
-  ossh_cache_var=ossh_cv_cflag__D_FORTIFY_SOURCE_2
-  { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if $CC supports compile flag -D_FORTIFY_SOURCE=2" >&5
-printf %s "checking if $CC supports compile flag -D_FORTIFY_SOURCE=2... " >&6; }
-if eval test \${$ossh_cache_var+y}
-then :
-  printf %s "(cached) " >&6
-else $as_nop
-
-	saved_CFLAGS="$CFLAGS"
-	CFLAGS="$CFLAGS $WERROR -D_FORTIFY_SOURCE=2"
-	_define_flag=""
-	test "x$_define_flag" = "x" && _define_flag="-D_FORTIFY_SOURCE=2"
-	cat confdefs.h - <<_ACEOF >conftest.$ac_ext
-/* end confdefs.h.  */
-
-#include <stdlib.h>
-#include <stdarg.h>
-#include <stdio.h>
-#include <string.h>
-#include <unistd.h>
-/* Trivial function to help test for -fzero-call-used-regs */
-int f(int n) {return rand() % n;}
-char *f2(char *s, ...) {
-	char ret[64];
-	va_list args;
-	va_start(args, s);
-	vsnprintf(ret, sizeof(ret), s, args);
-	va_end(args);
-	return strdup(ret);
-}
-int i;
-double d;
-const char *f3(int s) {
-	i = (int)d;
-	return s ? "good" : "gooder";
-}
-int main(int argc, char **argv) {
-	char b[256], *cp;
-	const char *s;
-	/* Some math to catch -ftrapv problems in the toolchain */
-	int i = 123 * argc, j = 456 + argc, k = 789 - argc;
-	float l = i * 2.1;
-	double m = l / 0.5;
-	long long int n = argc * 12345LL, o = 12345LL * (long long int)argc;
-	(void)argv;
-	f(1);
-	s = f3(f(2));
-	snprintf(b, sizeof b, "%d %d %d %f %f %lld %lld %s\n", i,j,k,l,m,n,o,s);
-	if (write(1, b, 0) == -1) exit(0);
-	cp = f2("%d %d %d %f %f %lld %lld %s\n", i,j,k,l,m,n,o,s);
-	if (write(1, cp, 0) == -1) exit(0);
-	free(cp);
-	/*
-	 * Test fallthrough behaviour.  clang 10's -Wimplicit-fallthrough does
-	 * not understand comments and we don't use the "fallthrough" attribute
-	 * that it's looking for.
-	 */
-	switch(i){
-	case 0: j += i;
-		/* FALLTHROUGH */
-	default: j += k;
-	}
-	exit(0);
-}
-
-
-_ACEOF
-if ac_fn_c_try_compile "$LINENO"
-then :
-
-if $ac_cv_path_EGREP -i "unrecognized option|warning.*ignored" conftest.err >/dev/null
-then
-		eval "$ossh_cache_var=no"
-		CFLAGS="$saved_CFLAGS"
-else
-				if test "$cross_compiling" = yes
-then :
-   eval "$ossh_cache_var=yes"
-			  CFLAGS="$saved_CFLAGS $_define_flag"
-else $as_nop
-  cat confdefs.h - <<_ACEOF >conftest.$ac_ext
-/* end confdefs.h.  */
-
-#include <stdlib.h>
-#include <stdarg.h>
-#include <stdio.h>
-#include <string.h>
-#include <unistd.h>
-/* Trivial function to help test for -fzero-call-used-regs */
-int f(int n) {return rand() % n;}
-char *f2(char *s, ...) {
-	char ret[64];
-	va_list args;
-	va_start(args, s);
-	vsnprintf(ret, sizeof(ret), s, args);
-	va_end(args);
-	return strdup(ret);
-}
-int i;
-double d;
-const char *f3(int s) {
-	i = (int)d;
-	return s ? "good" : "gooder";
-}
-int main(int argc, char **argv) {
-	char b[256], *cp;
-	const char *s;
-	/* Some math to catch -ftrapv problems in the toolchain */
-	int i = 123 * argc, j = 456 + argc, k = 789 - argc;
-	float l = i * 2.1;
-	double m = l / 0.5;
-	long long int n = argc * 12345LL, o = 12345LL * (long long int)argc;
-	(void)argv;
-	f(1);
-	s = f3(f(2));
-	snprintf(b, sizeof b, "%d %d %d %f %f %lld %lld %s\n", i,j,k,l,m,n,o,s);
-	if (write(1, b, 0) == -1) exit(0);
-	cp = f2("%d %d %d %f %f %lld %lld %s\n", i,j,k,l,m,n,o,s);
-	if (write(1, cp, 0) == -1) exit(0);
-	free(cp);
-	/*
-	 * Test fallthrough behaviour.  clang 10's -Wimplicit-fallthrough does
-	 * not understand comments and we don't use the "fallthrough" attribute
-	 * that it's looking for.
-	 */
-	switch(i){
-	case 0: j += i;
-		/* FALLTHROUGH */
-	default: j += k;
-	}
-	exit(0);
-}
-
-
-_ACEOF
-if ac_fn_c_try_run "$LINENO"
-then :
-   eval "$ossh_cache_var=yes"
-			  CFLAGS="$saved_CFLAGS $_define_flag"
-else $as_nop
-   eval "$ossh_cache_var='no, fails at run time'"
-			  CFLAGS="$saved_CFLAGS"
-fi
-rm -f core *.core core.conftest.* gmon.out bb.out conftest$ac_exeext \
-  conftest.$ac_objext conftest.beam conftest.$ac_ext
-fi
-
-fi
-else $as_nop
-   eval "$ossh_cache_var=no"
-		  CFLAGS="$saved_CFLAGS"
-
-fi
-rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext
-
-fi
-eval ac_res=\$$ossh_cache_var
-	       { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $ac_res" >&5
-printf "%s\n" "$ac_res" >&6; }
-}
-	{
   ossh_cache_var=ossh_cv_ldflag__Wl__z_relro
   { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if $LD supports link flag -Wl,-z,relro" >&5
 printf %s "checking if $LD supports link flag -Wl,-z,relro... " >&6; }
diff --git a/configure.ac b/configure.ac
index 7e0399198..5f28798c9 100644
--- a/configure.ac
+++ b/configure.ac
@@ -217,7 +217,6 @@ if test "$GCC" = "yes" || test "$GCC" = "egcs"; then
 	OSSH_CHECK_CFLAG_COMPILE([-Wbitwise-instead-of-logical])
 	OSSH_CHECK_CFLAG_COMPILE([-fno-strict-aliasing])
     if test "x$use_toolchain_hardening" = "x1"; then
-	OSSH_CHECK_CFLAG_COMPILE([-D_FORTIFY_SOURCE=2])
 	OSSH_CHECK_LDFLAG_LINK([-Wl,-z,relro])
 	OSSH_CHECK_LDFLAG_LINK([-Wl,-z,now])
 	OSSH_CHECK_LDFLAG_LINK([-Wl,-z,noexecstack])

-- 
To stop receiving notification emails like this one, please contact
djm at mindrot.org.


More information about the openssh-commits mailing list