Switching on compiler/src options to harden FreeBSD
- Reply: Kyle Evans : "Re: Switching on compiler/src options to harden FreeBSD"
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 17 Jun 2026 19:58:01 UTC
Hi,
given the numerous talks at BSDCan about security in the last hours, and
the mention of maybe enabling fortify by default, I want to point out
https://www.leidinger.net/blog/2025/05/24/freebsd-security-hardening-with-compiler-options/
I run a lot of this stuff on real workloads. Not in a high performance
situation, more of a SOHO workload, but I have mysql, postgresql, redis,
java application servers, python application servers, php, nginx,
postfix, dovecot, squid, various dns servers (unbound, bind,
adguardhome) and samba in >60 jails (some of them service jails, some of
them normal jails, some of them service jails in normal jails). All of
those build in a local poudirere with those options enabled.
This stuff works today, and we should maybe think about just enabling
this stuff and go ahead. If it hinders a bit in the performance area,
and it is important, it can be deactivated by those which need the last
little bit of performance. In my situation where the CPUs are normally
not near 100%, I can not feel a difference.
Just my 2 cents...
Bye,
Alexander.
--
http://www.Leidinger.net Alexander@Leidinger.net: PGP 0x8F31830F9F2772BF
http://www.FreeBSD.org netchild@FreeBSD.org : PGP 0x8F31830F9F2772BF