From: Ingo Molnar <mingo@elte.hu>
To: linux-kernel@vger.kernel.org
Subject: [patch] exec-shield patch for 2.6.7-rc2-bk2, integrated with NX
Date: Wed, 2 Jun 2004 23:04:21 +0200 [thread overview]
Message-ID: <20040602210421.GA22011@elte.hu> (raw)
Here's the latest exec-shield patch for 2.6.7-rc2-bk2, integrated with
the 'NX' feature (see the announcement from earlier today):
http://redhat.com/~mingo/exec-shield/exec-shield-on-nx-2.6.7-rc2-bk2-A7
you first have to apply the NX patch, which can be found at:
http://redhat.com/~mingo/nx-patches/nx-2.6.7-rc2-bk2-AE
prebuild kernel RPMs for Fedora Core 2, with this latest version of
exec-shield, are available at:
http://redhat.com/~arjanv/2.6/RPMS.kernel/
(kernel-2.6.6-1.411 has this latest, NX-aware exec-shield.)
if the CPU supports NX (and the kernel has been compiled with
CONFIG_HIGHMEM64G) then exec-shield will use NX to provide page-level
finegrained control over execution. On legacy CPUs that dont support NX
the segment-limit method is used to control execution (in a coarser
way). In the NX case the segment-limit is turned off altogether.
e.g. on an Athlon64 box the boot message looks:
NX (Execute Disable) protection: active
on a CPU without NX the boot message is:
NX (Execute Disable) protection: not present!
Using x86 segment limits to approximate NX protection
note: the NX patch will also protect against kernel-space code
injection.
all the other components of exec-shield are identical between NX and
non-NX: the brk area is non-executable, libraries and PIE binaries are
moved into the ascii-shield as much as possible, and all aspects of the
address space are randomized.
Ingo
next reply other threads:[~2004-06-02 21:03 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-06-02 21:04 Ingo Molnar [this message]
2004-06-04 15:59 ` [patch] exec-shield patch for 2.6.7-rc2-bk2, integrated with NX Christoph Hellwig
2004-06-04 16:25 ` Ingo Molnar
2004-06-04 17:19 ` Joe Korty
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20040602210421.GA22011@elte.hu \
--to=mingo@elte.hu \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.