From 5894407401d600adefcab3962648c8063bf6a961 Mon Sep 17 00:00:00 2001 From: Robert Scott Date: Fri, 4 Apr 2025 13:21:46 +0100 Subject: [PATCH] systemd: disable pacret hardening flag if withLibBPF for same reason as other flags mentioned here - really we should not be using a wrapped clang for bpf compilation --- pkgs/os-specific/linux/systemd/default.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/os-specific/linux/systemd/default.nix b/pkgs/os-specific/linux/systemd/default.nix index c67384b3d938..884f19ecc6ed 100644 --- a/pkgs/os-specific/linux/systemd/default.nix +++ b/pkgs/os-specific/linux/systemd/default.nix @@ -331,11 +331,13 @@ stdenv.mkDerivation (finalAttrs: { [ # https://gcc.gnu.org/bugzilla/show_bug.cgi?id=111523 "trivialautovarinit" - # breaks clang -target bpf; should be fixed to filter target? ] ++ (lib.optionals withLibBPF [ + # breaks clang -target bpf; should be fixed to not use + # a wrapped clang? "zerocallusedregs" "shadowstack" + "pacret" ]); nativeBuildInputs =