git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] mingw: enable DEP and ASLR

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Apr 30, 2019, 22:41 UTC
Message-ID
<nycvar.QRO.7.76.6.1904301838400.45@tvgsbejvaqbjf.bet>
In-Reply-To
<8e59dbf6-a339-74f3-4e60-e56b3817aea5@kdbg.org>
Hi Hannes,
On Tue, 30 Apr 2019, Johannes Sixt wrote:
> [had to add Dscho as recipient manually, mind you]

I usually pick up responses to GitGitGadget patch series even if I am not on explicit Cc: (but it might take a couple of days when I am too busy elsewhere to read the Git mailing list).

Show 42 quoted lines
> Am 29.04.19 um 23:56 schrieb İsmail Dönmez via GitGitGadget:
> > From: =?UTF-8?q?=C4=B0smail=20D=C3=B6nmez?= <ismail@i10z.com>
> >
> > Enable DEP (Data Execution Prevention) and ASLR (Address Space Layout
> > Randomization) support. This applies to both 32bit and 64bit builds
> > and makes it substantially harder to exploit security holes in Git by
> > offering a much more unpredictable attack surface.
> >
> > ASLR interferes with GDB's ability to set breakpoints. A similar issue
> > holds true when compiling with -O2 (in which case single-stepping is
> > messed up because GDB cannot map the code back to the original source
> > code properly). Therefore we simply enable ASLR only when an
> > optimization flag is present in the CFLAGS, using it as an indicator
> > that the developer does not want to debug in GDB anyway.
> >
> > Signed-off-by: İsmail Dönmez <ismail@i10z.com>
> > Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
> > ---
> >  config.mak.uname | 6 ++++++
> >  1 file changed, 6 insertions(+)
> >
> > diff --git a/config.mak.uname b/config.mak.uname
> > index e7c7d14e5f..a9edcc5f0b 100644
> > --- a/config.mak.uname
> > +++ b/config.mak.uname
> > @@ -570,6 +570,12 @@ else
> >  	ifeq ($(shell expr "$(uname_R)" : '2\.'),2)
> >  		# MSys2
> >  		prefix = /usr/
> > +		# Enable DEP
> > +		BASIC_LDFLAGS += -Wl,--nxcompat
> > +		# Enable ASLR (unless debugging)
> > +		ifneq (,$(findstring -O,$(CFLAGS)))
> > +			BASIC_LDFLAGS += -Wl,--dynamicbase
> > +		endif
> >  		ifeq (MINGW32,$(MSYSTEM))
> >  			prefix = /mingw32
> >  			HOST_CPU = i686
> >
>
> I'm a bit concerned that this breaks my debug sessions where I use -O0.
> But I'll test without -O0 before I really complain.

Weird. Jameson Miller also mentioned this very concern in an internal review.

I guess I'll do something like
	ifneq (,$(findstring -O,$(filter-out -O0,$(CFLAGS))))
Does that work for you?

Ciao, Dscho

Previous: Johannes SixtNext: Johannes Sixt
Message 4 of 16 in “Enable Data Execution Protection and Address Space Layout Randomization on Windows”
  1. 0/2 Enable Data Execution Protection and Address Space Layout Randomization on WindowsJohannes Schindelin via GitGitGadget, Apr 29, 2019
  2. 2/2 mingw: enable DEP and ASLRİsmail Dönmez via GitGitGadget, Apr 29, 2019
  3. Johannes SixtApr 30, 2019
  4. Johannes SchindelinApr 30, 2019
  5. Johannes SixtApr 30, 2019
  6. Alban GruinMay 1, 2019
  7. brian m. carlsonMay 1, 2019
  8. Johannes SchindelinMay 8, 2019
  9. Johannes SchindelinMay 8, 2019
  10. Jeff KingMay 1, 2019
  11. Jonathan NiederMay 1, 2019
  12. Johannes SchindelinMay 8, 2019
  13. 1/2 mingw: do not let ld strip relocationsİsmail Dönmez via GitGitGadget, Apr 29, 2019
  14. 0/2 Enable Data Execution Protection and Address Space Layout Randomization on WindowsJohannes Schindelin via GitGitGadget, May 8, 2019
  15. 2/2 mingw: enable DEP and ASLRİsmail Dönmez via GitGitGadget, May 8, 2019
  16. 1/2 mingw: do not let ld strip relocationsİsmail Dönmez via GitGitGadget, May 8, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.