Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1277014
| From | Michael Ellerman <mpe@ellerman.id.au> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH v3 1/4] mm: mmap: Add new /proc tunable for mmap_base ASLR. |
| Date | 2015-11-25 05:50 +0100 |
| Message-ID | <qyAbL-1dF-5@gated-at.bofh.it> (permalink) |
| References | <qwkkO-1pG-7@gated-at.bofh.it> <qwkkO-1pG-9@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Wed, 2015-11-18 at 15:20 -0800, Daniel Cashman wrote: > From: dcashman <dcashman@google.com> > > ASLR currently only uses 8 bits to generate the random offset for the > mmap base address on 32 bit architectures. This value was chosen to > prevent a poorly chosen value from dividing the address space in such > a way as to prevent large allocations. This may not be an issue on all > platforms. Allow the specification of a minimum number of bits so that > platforms desiring greater ASLR protection may determine where to place > the trade-off. ... > diff --git a/arch/Kconfig b/arch/Kconfig > index 4e949e5..141823f 100644 > --- a/arch/Kconfig > +++ b/arch/Kconfig > @@ -511,6 +511,70 @@ config ARCH_HAS_ELF_RANDOMIZE > - arch_mmap_rnd() > - arch_randomize_brk() > > +config HAVE_ARCH_MMAP_RND_BITS > + bool > + help > + An arch should select this symbol if it supports setting a variable > + number of bits for use in establishing the base address for mmap > + allocations and provides values for both: > + - ARCH_MMAP_RND_BITS_MIN > + - ARCH_MMAP_RND_BITS_MAX > + > +config ARCH_MMAP_RND_BITS_MIN > + int > + > +config ARCH_MMAP_RND_BITS_MAX > + int > + > +config ARCH_MMAP_RND_BITS_DEFAULT > + int > + > +config ARCH_MMAP_RND_BITS > + int "Number of bits to use for ASLR of mmap base address" if EXPERT > + range ARCH_MMAP_RND_BITS_MIN ARCH_MMAP_RND_BITS_MAX > + default ARCH_MMAP_RND_BITS_DEFAULT if ARCH_MMAP_RND_BITS_DEFAULT Here you support a default which is separate from the minimum. > + default ARCH_MMAP_RND_BITS_MIN > + depends on HAVE_ARCH_MMAP_RND_BITS ... > + > +config ARCH_MMAP_RND_COMPAT_BITS > + int "Number of bits to use for ASLR of mmap base address for compatible applications" if EXPERT > + range ARCH_MMAP_RND_COMPAT_BITS_MIN ARCH_MMAP_RND_COMPAT_BITS_MAX > + default ARCH_MMAP_RND_COMPAT_BITS_MIN But here you don't. Just forgot? I'd like to have a default which is separate from the minimum. That way we can have a default which is reasonably large, but allow it to be lowered easily if anything breaks. cheers -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH v3 0/4] Allow customizable random offset to mmap_base address. Daniel Cashman <dcashman@android.com> - 2015-11-19 00:30 +0100
[PATCH v3 1/4] mm: mmap: Add new /proc tunable for mmap_base ASLR. Daniel Cashman <dcashman@android.com> - 2015-11-19 00:30 +0100
Re: [PATCH v3 1/4] mm: mmap: Add new /proc tunable for mmap_base ASLR. Daniel Cashman <dcashman@android.com> - 2015-11-19 01:20 +0100
Re: [PATCH v3 1/4] mm: mmap: Add new /proc tunable for mmap_base ASLR. Andrew Morton <akpm@linux-foundation.org> - 2015-11-25 01:50 +0100
Re: [PATCH v3 1/4] mm: mmap: Add new /proc tunable for mmap_base ASLR. Kees Cook <keescook@chromium.org> - 2015-11-25 01:50 +0100
Re: [PATCH v3 1/4] mm: mmap: Add new /proc tunable for mmap_base ASLR. Daniel Cashman <dcashman@android.com> - 2015-11-25 20:20 +0100
Re: [PATCH v3 1/4] mm: mmap: Add new /proc tunable for mmap_base ASLR. Michael Ellerman <mpe@ellerman.id.au> - 2015-11-25 05:50 +0100
Re: [PATCH v3 1/4] mm: mmap: Add new /proc tunable for mmap_base ASLR. Daniel Cashman <dcashman@android.com> - 2015-11-25 20:40 +0100
Re: [PATCH v3 0/4] Allow customizable random offset to mmap_base address. Andrew Morton <akpm@linux-foundation.org> - 2015-11-25 01:40 +0100
Re: [PATCH v3 0/4] Allow customizable random offset to mmap_base address. Daniel Cashman <dcashman@android.com> - 2015-11-25 20:10 +0100
Re: [PATCH v3 0/4] Allow customizable random offset to mmap_base address. Martin Schwidefsky <schwidefsky@de.ibm.com> - 2015-11-26 16:20 +0100
Re: [PATCH v3 0/4] Allow customizable random offset to mmap_base address. Michael Ellerman <mpe@ellerman.id.au> - 2015-11-26 08:10 +0100
csiph-web