Switching on compiler/src options to harden FreeBSD

From: Alexander Leidinger <Alexander_at_Leidinger.net>
Date: Wed, 17 Jun 2026 19:58:01 UTC
Hi,

given the numerous talks at BSDCan about security in the last hours, and 
the mention of maybe enabling fortify by default, I want to point out
     
https://www.leidinger.net/blog/2025/05/24/freebsd-security-hardening-with-compiler-options/

I run a lot of this stuff on real workloads. Not in a high performance 
situation, more of a SOHO workload, but I have mysql, postgresql, redis, 
java application servers, python application servers, php, nginx, 
postfix, dovecot, squid, various dns servers (unbound, bind, 
adguardhome) and samba in >60 jails (some of them service jails, some of 
them normal jails, some of them service jails in normal jails). All of 
those build in a local poudirere with those options enabled.

This stuff works today, and we should maybe think about just enabling 
this stuff and go ahead. If it hinders a bit in the performance area, 
and it is important, it can be deactivated by those which need the last 
little bit of performance. In my situation where the CPUs are normally 
not near 100%, I can not feel a difference.

Just my 2 cents...

Bye,
Alexander.

-- 
http://www.Leidinger.net Alexander@Leidinger.net: PGP 0x8F31830F9F2772BF
http://www.FreeBSD.org    netchild@FreeBSD.org  : PGP 0x8F31830F9F2772BF