diff --git a/Makefile b/Makefile index 616cbf73..06524fcd 100644 --- a/Makefile +++ b/Makefile @@ -16,14 +16,14 @@ GIT_BRANCH := $(shell git branch | sed -n 's/^\* //p') GIT_VERSION := $(shell git --no-pager describe --tags --always --dirty) GIT_DATE := $(shell git --no-pager show --date=short --format="%ai" --name-only | head -n 1) -# -fstack-protector: The program will be resistant to having itsstack overflowed. +# -fstack-protector: The program will be resistant to having its stack overflowed # -D_FORTIFY_SOURCE=2 and -O1 or higher: This causes certain unsafe glibc functions zo be replaced with their safer counterparts # -Wl,-z,relro: reduces the possible areas of memory in a program that can be used by an attacker that performs a successful memory corruption exploit # -Wl,-z,now: When combined with RELRO above, this further reduces the regions of memory available to memory corruption attacks -# -ftrapv: Generates traps for signed overflow +# -pie -fPIE: For ASLR CC=gcc -HARDENING_FLAGS=-fstack-protector-all -Wstack-protector --param ssp-buffer-size=4 -D_FORTIFY_SOURCE=2 -O3 -Wl,-z,relro,-z,now -ftrapv -CFLAGS=-I$(IDIR) -Wall -g $(HARDENING_FLAGS) +HARDENING_FLAGS=-fstack-protector -D_FORTIFY_SOURCE=2 -O3 -Wl,-z,relro,-z,now -pie -fPIE +CFLAGS=-I$(IDIR) -Wall -g2 $(HARDENING_FLAGS) LIBS=-rdynamic ODIR =obj diff --git a/daemon.c b/daemon.c index b1bfd7bc..b1d1cfbf 100644 --- a/daemon.c +++ b/daemon.c @@ -27,6 +27,7 @@ bool test_singularity(void) { logg("WARNING: Unable to read PID from file (cannot read PID from file)."); logg(" Cannot test if another FTL process is running!"); + fclose(f); return true; } fclose(f);