libao is not currently using the default build flags set by dpkg-buildflags(1). The default flags are chosen for multiple reasons including security, performance, reproducibility, adherence to standards, and error handling. Please make sure that libao builds using the default build flags. blhc(1p) and hardening-check(1) can be used to confirm that the issue is fixed. In the general case, packages honoring CFLAGS, LDFLAGS, and other similar environment variables get the default build flags for free without the need for any work on the maintainer side. In the case of libao, the flags are either ignored or overridden. The most common reasons for this are: Hand-written Makefiles ---------------------- Some upstream Makefiles either override the values of variables such as CFLAGS and similar or do not use them at all. See: https://wiki.debian.org/HardeningWalkthrough#Handwritten_Makefiles Misconfigured build systems --------------------------- If the upstream code uses autotools, CMake, or other popular build systems, it usually requires no further modifications. If might however be that some variables are hardcoded in some way. In this CMake snippet, the value of CXXFLAGS is overwritten with "-O2": set(CMAKE_CXX_FLAGS "-O2") If the intention is to append to CXXFLAGS, one should use the following instead: set(CMAKE_CXX_FLAGS "-O2 ${CMAKE_CXX_FLAGS}") See #655870 for a similar autotools example. Very old debhelper usage ------------------------ Packages not using dh(1), or those using a debhelper compatibility level less than 9, need to manually include /usr/share/dpkg/buildflags.mk in order for the dpkg-buildflags variables to be set: https://wiki.debian.org/Hardening#dpkg-buildflags Flags hardcoded in debian/rules (either voluntarily or not) ----------------------------------------------------------- Some packages voluntarily hardcode the values of CFLAGS and friends in debian/rules, ignoring the defaults set by dpkg-buildflags(1). Others attempt to append to the variables, but end up accidentally overriding the defaults: #!/usr/bin/make -f export CFLAGS += -pipe -fPIC -Wall %: dh $@ Debhelper only sets CFLAGS if it is not set yet. In the example above, when dh is invoked the value of CFLAGS is "-pipe -fPIC -Wall", hence the hardened defaults are not used. The right way to append to CFLAGS is using DEB_CFLAGS_MAINT_APPEND instead, as documented in dpkg-buildflags(1). For a detailed analysis of this issue, see https://hal.science/hal-05334704/
We believe that the bug you reported is fixed in the latest version of
libao, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1124864@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Andreas Tille <tille@debian.org> (supplier of updated libao package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 15 Jul 2026 15:50:33 +0200
Source: libao
Architecture: source
Version: 1.2.2+20180113-1.4
Distribution: unstable
Urgency: medium
Maintainer: Ron Lee <ron@debian.org>
Changed-By: Andreas Tille <tille@debian.org>
Closes: 911232 1006858 1089839 1124864 1142115
Changes:
libao (1.2.2+20180113-1.4) unstable; urgency=medium
.
* Non-maintainer upload.
.
[ Andreas Tille ]
* Maintain package in Debian team on Salsa
Closes: #1142115
* Suggest libsndio7.0 instead of libsndio6.1
Closes: #911232
* d/watch: version=5
* d/copyright:
- DEP5
- Add missing src/plugins/sndio/ao_sndio.c
* d/rules: hardening
* Refer to specific version of license GPL-2+.
* Remove redundant Priority: optional from source stanza.
* Trim trailing whitespace.
* Use secure URI in Homepage field.
* Standards-Version: 4.7.4
* Add debian/lrc.config
.
[ Vagrant Cascadian ]
* reproducible-builds: Do not embed build path into libraries
Closes: #1006858
.
[ Alessandro Astone ]
* debian: adapt to compatibility level 13 and use autoreconf template.
* debian/libao.conf: Set the default output to pulseaudio (LP: #1075479)
Closes: #1089839, #1124864
Checksums-Sha1:
d6780a76c718881854b000ef4854febebb90de25 2100 libao_1.2.2+20180113-1.4.dsc
3fb5d51b31794240f8a73811974bf4f1eba94ecf 7888 libao_1.2.2+20180113-1.4.debian.tar.xz
5cce76c6dc152dd278bcbafd612e1d95066791c3 8860 libao_1.2.2+20180113-1.4_amd64.buildinfo
Checksums-Sha256:
63bb49a6dacc8a4c560e62a4d794f0647fdddbcd17bdc9fb16f49ccb72d8f915 2100 libao_1.2.2+20180113-1.4.dsc
103385becbc6abb68d3815ab11c52c46111e5f531695550b1c014d760807a712 7888 libao_1.2.2+20180113-1.4.debian.tar.xz
0790c64a98419357f7b34a4c11b528edcc88eb9c03f9beb6bc806f2fa613d5f0 8860 libao_1.2.2+20180113-1.4_amd64.buildinfo
Files:
d29eb175f2b381baf130a816487c6fe3 2100 libs optional libao_1.2.2+20180113-1.4.dsc
6b6749630b4726df3dc26120002f173f 7888 libs optional libao_1.2.2+20180113-1.4.debian.tar.xz
e35445b7d3468e54741298e6689068b4 8860 libs optional libao_1.2.2+20180113-1.4_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJFBAEBCgAvFiEE8fAHMgoDVUHwpmPKV4oElNHGRtEFAmpXkTQRHHRpbGxlQGRl
Ymlhbi5vcmcACgkQV4oElNHGRtGZlg/9FQ2+SHqIvn2Nb18f7Vp/u12cDXFu9Bh7
111M2sMZ/ZD8tSBpA2N72M8VztK6TR/V74jCXvy2/It+Nott0xpHoxBN2+DnV7R5
Eoaxw5SeKUf7E3sUytvivBC47ISPlvVn6l2fdgYRRrUqle9PqiKzJ7jQ6Dz4kQJP
W2Zf1nICthKpl/F86bYPghRvmG7rZdjnFFj6dpfqYk3xNPy1tg9MbdCnQcRJvya5
AHEMGYWC09apW54GvGswqg/PdStImyuz0tOHrmnc0vBHq+Tz+oiUOCleidgbR6dN
kSpxFfbE1tL4I/lCUxTlwsa/QUQ5YpoS9Yd2tabi8ALyWcCE2X9P96+5jYH6Opd8
D9/7e2XiDu9iE5W69yBOSQKjndPY/HIaqAuC5zC6GfuTr7lWk9bQYaHZzPWC6JQ3
y8RU5b6rRBKj3PBbXtVjJF+kYNx68XkWtqrH84BkMLzKxHvcEpXC4/iJG6bsFzCz
9obvx51KW5OVmAY5HKG9Nhwz6ClK+QVRl+bX3bEZC7mywTG8XIJBIoUobGJXNhwM
zIl70hvCpx/tEU25X9CbyriD3pzHshu3zFUBCz41r8AvDFt5CqczIq4MjFau6ILK
OuX5coml8ahM0C7BV2BLqU3crJImm3LH5/BHhWtfWNjD9SK5qdSMUtonFg9m4PrB
rij85Jw4mWQ=
=Ps4L
-----END PGP SIGNATURE-----