Page Menu
Home
FreeBSD
Search
Configure Global Search
Log In
Files
F141967429
D21081.id60179.diff
No One
Temporary
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Mute Notifications
Flag For Later
Award Token
Size
4 KB
Referenced Files
None
Subscribers
None
D21081.id60179.diff
View Options
Index: sys/amd64/amd64/elf_machdep.c
===================================================================
--- sys/amd64/amd64/elf_machdep.c
+++ sys/amd64/amd64/elf_machdep.c
@@ -82,6 +82,7 @@
.sv_schedtail = NULL,
.sv_thread_detach = NULL,
.sv_trap = NULL,
+ .sv_stackgap = elf64_stackgap,
};
INIT_SYSENTVEC(elf64_sysvec, &elf64_freebsd_sysvec);
Index: sys/compat/freebsd32/freebsd32_misc.c
===================================================================
--- sys/compat/freebsd32/freebsd32_misc.c
+++ sys/compat/freebsd32/freebsd32_misc.c
@@ -3166,6 +3166,9 @@
destp = rounddown2(destp, sizeof(uint32_t));
vectp = (uint32_t *)destp;
+ if (imgp->sysent->sv_stackgap != NULL)
+ imgp->sysent->sv_stackgap(imgp, (u_long *)&vectp);
+
if (imgp->auxargs) {
/*
* Allocate room on the stack for the ELF auxargs
Index: sys/compat/ia32/ia32_sysvec.c
===================================================================
--- sys/compat/ia32/ia32_sysvec.c
+++ sys/compat/ia32/ia32_sysvec.c
@@ -128,6 +128,7 @@
.sv_schedtail = NULL,
.sv_thread_detach = NULL,
.sv_trap = NULL,
+ .sv_stackgap = elf32_stackgap,
};
INIT_SYSENTVEC(elf_ia32_sysvec, &ia32_freebsd_sysvec);
Index: sys/kern/imgact_elf.c
===================================================================
--- sys/kern/imgact_elf.c
+++ sys/kern/imgact_elf.c
@@ -156,6 +156,11 @@
&__elfN(aslr_honor_sbrk), 0,
__XSTRING(__CONCAT(ELF, __ELF_WORD_SIZE)) ": assume sbrk is used");
+static int __elfN(aslr_stack_gap) = 1;
+SYSCTL_INT(ASLR_NODE_OID, OID_AUTO, stack_gap, CTLFLAG_RW,
+ &__elfN(aslr_stack_gap), 0,
+ __XSTRING(__CONCAT(ELF, __ELF_WORD_SIZE)) ": allow stack gap");
+
static Elf_Brandinfo *elf_brand_list[MAX_BRANDS];
#define aligned(a, t) (rounddown2((u_long)(a), sizeof(t)) == (u_long)(a))
@@ -2720,3 +2725,24 @@
flags |= PF_W;
return (flags);
}
+
+void
+__elfN(stackgap)(struct image_params *imgp, u_long *stack_base)
+{
+ u_long range, rbase, gap;
+ int pct;
+
+ if ((imgp->map_flags & MAP_ASLR) == 0)
+ return;
+ pct = __elfN(aslr_stack_gap);
+ if (pct == 0)
+ return;
+ if (pct > 50)
+ pct = 50;
+ range = imgp->eff_stack_sz / 100;
+ range *= pct;
+ arc4rand(&rbase, sizeof(rbase), 0);
+ gap = rbase % range;
+ gap &= ~(sizeof(u_long) - 1);
+ *stack_base -= gap;
+}
Index: sys/kern/kern_exec.c
===================================================================
--- sys/kern/kern_exec.c
+++ sys/kern/kern_exec.c
@@ -1128,6 +1128,7 @@
} else {
ssiz = maxssiz;
}
+ imgp->eff_stack_sz = ssiz;
stack_addr = sv->sv_usrstack - ssiz;
error = vm_map_stack(map, stack_addr, (vm_size_t)ssiz,
obj != NULL && imgp->stack_prot != 0 ? imgp->stack_prot :
@@ -1615,6 +1616,9 @@
destp = rounddown2(destp, sizeof(void *));
vectp = (char **)destp;
+ if (imgp->sysent->sv_stackgap != NULL)
+ imgp->sysent->sv_stackgap(imgp, (u_long *)&vectp);
+
if (imgp->auxargs) {
/*
* Allocate room on the stack for the ELF auxargs
Index: sys/sys/imgact.h
===================================================================
--- sys/sys/imgact.h
+++ sys/sys/imgact.h
@@ -87,6 +87,7 @@
int pagesizeslen;
vm_prot_t stack_prot;
u_long stack_sz;
+ u_long eff_stack_sz;
struct ucred *newcred; /* new credentials if changing */
bool credential_setid; /* true if becoming setid */
bool textset;
Index: sys/sys/imgact_elf.h
===================================================================
--- sys/sys/imgact_elf.h
+++ sys/sys/imgact_elf.h
@@ -98,6 +98,7 @@
int __elfN(freebsd_fixup)(register_t **, struct image_params *);
int __elfN(coredump)(struct thread *, struct vnode *, off_t, int);
size_t __elfN(populate_note)(int, void *, void *, size_t, void **);
+void __elfN(stackgap)(struct image_params *, u_long *);
/* Machine specific function to dump per-thread information. */
void __elfN(dump_thread)(struct thread *, void *, size_t *);
Index: sys/sys/sysent.h
===================================================================
--- sys/sys/sysent.h
+++ sys/sys/sysent.h
@@ -109,6 +109,7 @@
int (*sv_coredump)(struct thread *, struct vnode *, off_t, int);
/* function to dump core, or NULL */
int (*sv_imgact_try)(struct image_params *);
+ void (*sv_stackgap)(struct image_params *, u_long *);
int sv_minsigstksz; /* minimum signal stack size */
vm_offset_t sv_minuser; /* VM_MIN_ADDRESS */
vm_offset_t sv_maxuser; /* VM_MAXUSER_ADDRESS */
@@ -144,6 +145,7 @@
#define SV_CAPSICUM 0x020000 /* Force cap_enter() on startup. */
#define SV_TIMEKEEP 0x040000 /* Shared page timehands. */
#define SV_ASLR 0x080000 /* ASLR allowed. */
+#define SV_STACKGAP 0x100000 /* Randomized stack gap for main thr */
#define SV_ABI_MASK 0xff
#define SV_ABI_ERRNO(p, e) ((p)->p_sysent->sv_errsize <= 0 ? e : \
File Metadata
Details
Attached
Mime Type
text/plain
Expires
Thu, Jan 15, 7:34 AM (5 h, 46 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
27645442
Default Alt Text
D21081.id60179.diff (4 KB)
Attached To
Mode
D21081: Make randomized stack gap between strings and pointers to argv/envs.
Attached
Detach File
Event Timeline
Log In to Comment