gnum4: unconditionally disable format hardening#418934
Merged
alyssais merged 1 commit intoNixOS:stagingfrom Jun 28, 2025
Merged
gnum4: unconditionally disable format hardening#418934alyssais merged 1 commit intoNixOS:stagingfrom
alyssais merged 1 commit intoNixOS:stagingfrom
Conversation
13 tasks
trofi
approved these changes
Jun 22, 2025
Member
Author
|
Hmm, this doesn't seem to work on Darwin. |
Member
I don’t know why they’re excluding Clang here or really what on earth they’re doing in general but I can confirm that it does not work on Darwin. |
Member
Author
|
So seems like we still need hardeningDisable for Clang (not necessarily Darwin). Updated. |
Member
Author
|
Well, given that checking what compiler we're using causes infinite recursion (at least until #365057), I think unconditionally disabling format hardening is actually the best we can do :( |
trofi
approved these changes
Jun 27, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The use of hardeningDisable was incomplete, as it also affected musl and probably other configurations. Regardless, it's better to actually fix the issue than ignoring it, especially because it's difficult to notice in future when hardeningDisable entries are no longer necessary.
Things done
nix.conf? (See Nix manual)sandbox = relaxedsandbox = truenix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD". Note: all changes have to be committed, also see nixpkgs-review usage./result/bin/)Add a 👍 reaction to pull requests you find important.