mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Ingo Molnar <mingo@elte.hu>
To: linux-kernel@vger.kernel.org
Subject: [patch] updated exec-shield patch, 2.4/2.6 -G3
Date: Fri, 26 Sep 2003 14:28:54 +0200 (CEST)	[thread overview]
Message-ID: <Pine.LNX.4.56.0309261410130.14571@localhost.localdomain> (raw)


in the recent boom of buffer-overflow bugs in various open-source packages
i got lots of requests for exec-shield being ported to various popular
kernel trees. Here's the latest update of exec-shield:

against vanilla 2.6.0-test5:

	redhat.com/~mingo/exec-shield/exec-shield-2.6.0-test5-G2

against vanilla 2.4.22:

	redhat.com/~mingo/exec-shield/exec-shield-2.4.22-G2

against 2.4.22-ac + NPTL:

	[ redhat.com/~mingo/nptl-patches/nptl-2.4.22-ac1-A2 ]

	redhat.com/~mingo/exec-shield/exec-shield-2.4.22-ac1-nptl-G2

Changes in this exec-shield version:

 - more refined support for PIE binaries (Position Independent Executables
   - a feature of latest binutils)

 - complete randomization of the whole address space [except the static 
   binary mappings for non-PIE binaries]. Randomized executable mappings,
   heap, data mappings, stack, env/argv/aux spaces. With PIE binaries
   there's not a single constant address left.

 - ability to turn off exec-shield without changing the binary.
   (try 'setarch i386 /bin/cat /proc/self/maps'.)

 - various compatibility features and fixes.

 - randomization can be turned off via /proc/sys/kernel/exec-shield-randomize.

valid /proc/sys/kernel/exec-shield levels are:

   = 0   exec-shield disabled
   = 1   exec-shield on PT_GNU_STACK executables [ie. binaries compiled 
                                                  with newest gcc]
   = 2   (default) exec-shield on all executables

value 1 is recommended with glibc and gcc versions that support
PT_GNU_STACK all across the spectrum. (Fedora Core test2 [released
yesterday] includes all of this and all applications were recompiled to
have valid PT_GNU_STACK settings.) On other systems the value of '2' is
recommended, use setarch for those binaries that cannot take exec-shield
[eg. Loki games].

reports, comments welcome. Enjoy it,

	Ingo

             reply	other threads:[~2003-09-26 12:28 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-09-26 12:28 Ingo Molnar [this message]
2003-09-26 17:13 ` Valdis.Kletnieks
2003-09-26 17:24   ` Ingo Molnar

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Pine.LNX.4.56.0309261410130.14571@localhost.localdomain \
    --to=mingo@elte.hu \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®