[openssh-commits] [openssh] branch master updated: Don't automatically enable FORTIFY_SOURCE.

git+noreply at mindrot.org git+noreply at mindrot.org
Mon Oct 5 18:11:13 AEDT 2026


This is an automated email from the git hooks/post-receive script.

dtucker pushed a commit to branch master
in repository openssh.

The following commit(s) were added to refs/heads/master by this push:
     new 4b29da595 Don't automatically enable FORTIFY_SOURCE.
4b29da595 is described below

commit 4b29da5952b1ede28f0d225cf722dee4923ba04c
Author: Darren Tucker <dtucker at dtucker.net>
AuthorDate: Mon Oct 5 17:08:15 2026 +1100

    Don't automatically enable FORTIFY_SOURCE.
    
    It can cause problems on some platforms, in particular NetBSD <11 since
    it will cause function pointer comparisons in atomicio to fail and some
    things including scp to hang.  Previously we had a workaround but that
    was removed in a765b86d.  See NetBSD bug 45200 and pkgsrc bug pkg/60563.
---
 configure.ac | 1 -
 1 file changed, 1 deletion(-)

diff --git a/configure.ac b/configure.ac
index 278d7c73c..aa59ba3dd 100644
--- a/configure.ac
+++ b/configure.ac
@@ -218,7 +218,6 @@ if test "$GCC" = "yes" || test "$GCC" = "egcs"; then
 	OSSH_CHECK_CFLAG_COMPILE([-Wbitwise-instead-of-logical])
 	OSSH_CHECK_CFLAG_COMPILE([-fno-strict-aliasing])
     if test "x$use_toolchain_hardening" = "x1"; then
-	OSSH_CHECK_CFLAG_COMPILE([-D_FORTIFY_SOURCE=2])
 	OSSH_CHECK_LDFLAG_LINK([-Wl,-z,relro])
 	OSSH_CHECK_LDFLAG_LINK([-Wl,-z,now])
 	OSSH_CHECK_LDFLAG_LINK([-Wl,-z,noexecstack])

-- 
To stop receiving notification emails like this one, please contact
djm at mindrot.org.


More information about the openssh-commits mailing list