Page MenuHomeFreeBSD

Add a WITH_BIND_NOW build knob
ClosedPublic

Authored by emaste on Nov 5 2018, 2:21 PM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Dec 5, 5:36 PM
Unknown Object (File)
Sep 26 2024, 12:35 PM
Unknown Object (File)
Sep 8 2024, 11:01 PM
Unknown Object (File)
Aug 12 2024, 4:51 PM
Unknown Object (File)
Aug 12 2024, 5:47 AM
Unknown Object (File)
Jul 24 2024, 11:10 AM
Unknown Object (File)
Jul 10 2024, 9:23 AM
Unknown Object (File)
Jul 10 2024, 9:23 AM
Subscribers

Details

Summary

The linker's -z now flag sets the DF_BIND_NOW flag, which signals to the runtime loader that all relocation processing should be performed at process startup rather than on demand. In combination with lld's default of enabling relro this causes the GOT to be made read-only when the process starts, preventing GOT overwrite attacks.

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

I had originally suggested to Shawn that he extract a patch (https://github.com/HardenedBSD/hardenedBSD/issues/356), but looked at the diffs and realized the changes are both trivial and going to conflict with HardenedBSD anyway (which has MK_RETPOLINE) arranged slightly differently.

There's a lot of commonality between bsd.prog.mk and bsd.lib.mk that could be factored out as a subsequent change.

Also note that our readelf does not display the DF_BIND_NOW flag -- see PR232983.

This revision is now accepted and ready to land.Nov 5 2018, 5:34 PM
This revision was automatically updated to reflect the committed changes.