| domain | hardenedbsd.org |
| summary | This document details a series of hardening and optimization changes implemented in the HardenedBSD codebase. The primary focus is on disabling `HARDCFLAGS` and `FORTIFYSOURCE` flags for numerous packages, alongside specific fixes and adjustments to improve build stability and security. Key changes include:
* Compilation Hardening: General hardening through disabling `HARDCFLAGS` for various projects like X11, graphics libraries, databases, compilers, and utilities. * Database Optimizations: Removal of unnecessary database patches and adjustments to `HARDCFLAGS` for databases like Redis and SQLite. * Security Enhancements: Addressing vulnerabilities related to format strings and security through patches and `-Werrorformat-security` options. * Game Port Fixes: Specific fixes and enhancements for game ports like ioquake3 and libretro-reicast. * Build Improvements: Improvements to builds for various packages including OmniORB, bcrypt_pbkdf, and tex-libtexluajit. * Bug Fixes: Resolution of build errors, such as the grub2-bhyve issue. * Feature Enablement: Enabling SLH for ioquake3 and re-enabling PIE and RELRO for Redis. * Contributor Acknowledgement: Alan Somers and FreeBSD developers are acknowledged for their contributions. |
| title | HardenedBSD |
| description | HardenedBSD |
| keywords | build, support, stable, report, status, have, rust, https, will, branch, more, ports, shawn, webb, work, package, server |
| upstreams |
|
| downstreams |
|
| nslookup | A 199.233.231.2 |
| created | 2025-11-09 |
| updated | 2026-01-27 |
| summarized | 2026-01-30 |
|
|