From: Solar Designer <solar@openwall.com>
To: kernel-hardening@lists.openwall.com
Subject: Re: [kernel-hardening] overview of PaX features
Date: Wed, 29 Jun 2011 23:43:39 +0400 [thread overview]
Message-ID: <20110629194339.GA15379@openwall.com> (raw)
In-Reply-To: <20110629183728.GA8163@albatros>
Vasiliy,
On Wed, Jun 29, 2011 at 10:37:28PM +0400, Vasiliy Kulikov wrote:
> That's not only about old apps, but also a default relaxed policy for
> the toolchain:
>
> http://www.gentoo.org/proj/en/hardened/gnu-stack.xml
Of course. In my experience, most programs that currently get
executable stack actually don't need it.
And for gcc trampolines we can include the emulation code in the kernel.
> For upstream linux the default policy is if no GNU_STACK present, the
> stack flags is defined by a constant. I think it makes sense for
> the upsteam to change it to per pid namespace, with the same default.
Sounds good. Then we'll have less code to maintain in our patch.
Thanks,
Alexander
next prev parent reply other threads:[~2011-06-29 19:43 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-06-26 18:33 [kernel-hardening] overview of PaX features Vasiliy Kulikov
2011-06-29 18:25 ` Solar Designer
2011-06-29 18:37 ` Vasiliy Kulikov
2011-06-29 19:43 ` Solar Designer [this message]
2011-06-30 16:03 ` Vasiliy Kulikov
2011-07-02 17:21 ` Solar Designer
2011-07-02 17:46 ` Vasiliy Kulikov
2011-07-03 1:06 ` Anthony G. Basile
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20110629194339.GA15379@openwall.com \
--to=solar@openwall.com \
--cc=kernel-hardening@lists.openwall.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox