Skip to content

cc_wrapper: Add pic to unsupported hardening flags if on i686 LLVM toolchain#196013

Open
peperunas wants to merge 1 commit intoNixOS:masterfrom
peperunas:cc-wrapper-i686-2
Open

cc_wrapper: Add pic to unsupported hardening flags if on i686 LLVM toolchain#196013
peperunas wants to merge 1 commit intoNixOS:masterfrom
peperunas:cc-wrapper-i686-2

Conversation

@peperunas
Copy link
Copy Markdown
Contributor

Description of changes

This issue is part of a series of bugfixes to improve the i686 cross-compilation pipeline.

Tracking issue: #195967

Things done
  • Built on platform(s)
    • x86_64-linux
    • aarch64-linux
    • x86_64-darwin
    • aarch64-darwin
  • For non-Linux: Is sandbox = true set in nix.conf? (See Nix manual)
  • Tested, as applicable:
  • Tested compilation of all packages that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD". Note: all changes have to be committed, also see nixpkgs-review usage
  • Tested basic functionality of all binary files (usually in ./result/bin/)
  • 22.11 Release Notes (or backporting 22.05 Release notes)
    • (Package updates) Added a release notes entry if the change is major or breaking
    • (Module updates) Added a release notes entry if the change is significant
    • (Module addition) Added a release notes entry if adding a new NixOS module
    • (Release notes changes) Ran nixos/doc/manual/md-to-db.sh to update generated release notes
  • Fits CONTRIBUTING.md.

@peperunas
Copy link
Copy Markdown
Contributor Author

Resuming comment by @lovesegfault on #195976:

Please leave a comment explaining why i686 + LLVM requires disabling PIC

This was added during my tests on cross-compiling derivations for i686. Some packages (unfortunately, I don't remember which) failed building if -pic was specified.

@r-burns
Copy link
Copy Markdown
Contributor

r-burns commented Oct 15, 2022

Is that true in general for i686/LLVM? If not, it's probably more appropriate to set hardeningDisable = "pic" for those packages individually.

@trofi
Copy link
Copy Markdown
Contributor

trofi commented Oct 29, 2022

+1 for for not blanket-disabling pic. There usually are milder ways to work around build failures for rare package failures.

@wegank wegank added 2.status: stale https://github.com/NixOS/nixpkgs/blob/master/.github/STALE-BOT.md 2.status: merge conflict This PR has merge conflicts with the target branch labels Mar 19, 2024
@stale stale bot removed the 2.status: stale https://github.com/NixOS/nixpkgs/blob/master/.github/STALE-BOT.md label Mar 20, 2024
@wegank wegank added the 2.status: stale https://github.com/NixOS/nixpkgs/blob/master/.github/STALE-BOT.md label Jul 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

2.status: merge conflict This PR has merge conflicts with the target branch 2.status: stale https://github.com/NixOS/nixpkgs/blob/master/.github/STALE-BOT.md

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants