git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 0/2] Enable Data Execution Protection and Address Space Layout Randomization on Windows

From
Johannes Schindelin via GitGitGadget <gitgitgadget@gmail.com>
Date
May 8, 2019, 11:30 UTC
Message-ID
<pull.134.v2.git.gitgitgadget@gmail.com>
In-Reply-To
<pull.134.git.gitgitgadget@gmail.com>

These two techniques make it harder to come up with exploits, by reducing what is commonly called the "attack surface" in security circles: by making the addresses less predictable, and by making it harder to inject data that is then (mis-)interpreted as code, this hardens Git's executables on Windows.

These patches have been carried in Git for Windows for over 3 years, and should therefore be considered battle-tested.

Changes since v1:
 * When determining whether we build with optimization, -O0 and -Og are
   explicitly ignored.
İsmail Dönmez (2):
  mingw: do not let ld strip relocations
  mingw: enable DEP and ASLR
 config.mak.uname | 8 ++++++++
 1 file changed, 8 insertions(+)
base-commit: 83232e38648b51abbcbdb56c94632b6906cc85a6
Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-134%2Fdscho%2Faslr-v2
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-134/dscho/aslr-v2
Pull-Request: https://github.com/gitgitgadget/git/pull/134
Range-diff vs v1:
 1:  e6acdba586 = 1:  828913e96c mingw: do not let ld strip relocations
 2:  e142c1396e ! 2:  9f1da73829 mingw: enable DEP and ASLR
     @@ -21,13 +21,13 @@
       --- a/config.mak.uname
       +++ b/config.mak.uname
      @@
     - 	ifeq ($(shell expr "$(uname_R)" : '2\.'),2)
     + 	ifneq ($(shell expr "$(uname_R)" : '1\.'),2)
       		# MSys2
       		prefix = /usr/
      +		# Enable DEP
      +		BASIC_LDFLAGS += -Wl,--nxcompat
      +		# Enable ASLR (unless debugging)
     -+		ifneq (,$(findstring -O,$(CFLAGS)))
     ++		ifneq (,$(findstring -O,$(filter-out -O0 -Og,$(CFLAGS))))
      +			BASIC_LDFLAGS += -Wl,--dynamicbase
      +		endif
       		ifeq (MINGW32,$(MSYSTEM))
-- 
gitgitgadget
Previous: İsmail Dönmez via GitGitGadgetNext: İsmail Dönmez via GitGitGadget
Message 14 of 16 in “Enable Data Execution Protection and Address Space Layout Randomization on Windows”
  1. 0/2 Enable Data Execution Protection and Address Space Layout Randomization on WindowsJohannes Schindelin via GitGitGadget, Apr 29, 2019
  2. 2/2 mingw: enable DEP and ASLRİsmail Dönmez via GitGitGadget, Apr 29, 2019
  3. Johannes SixtApr 30, 2019
  4. Johannes SchindelinApr 30, 2019
  5. Johannes SixtApr 30, 2019
  6. Alban GruinMay 1, 2019
  7. brian m. carlsonMay 1, 2019
  8. Johannes SchindelinMay 8, 2019
  9. Johannes SchindelinMay 8, 2019
  10. Jeff KingMay 1, 2019
  11. Jonathan NiederMay 1, 2019
  12. Johannes SchindelinMay 8, 2019
  13. 1/2 mingw: do not let ld strip relocationsİsmail Dönmez via GitGitGadget, Apr 29, 2019
  14. 0/2 Enable Data Execution Protection and Address Space Layout Randomization on WindowsJohannes Schindelin via GitGitGadget, May 8, 2019
  15. 2/2 mingw: enable DEP and ASLRİsmail Dönmez via GitGitGadget, May 8, 2019
  16. 1/2 mingw: do not let ld strip relocationsİsmail Dönmez via GitGitGadget, May 8, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.