FAQ Search Today's Posts Mark Forums Read
» Video Reviews

» Linux Archive

Linux-archive is a website aiming to archive linux email lists and to make them easily accessible for linux users/developers.

» Sponsor

» Partners

» Sponsor

Go Back   Linux Archive > Gentoo > Gentoo Hardened

LinkBack Thread Tools
Old 12-18-2011, 09:48 PM
Magnus Granberg
Default Meeting 2011-12-14 20:00UTC log

Here is the meeting log.

/Magnus (Zorry)
Old 12-20-2011, 10:01 PM
Default Meeting 2011-12-14 20:00UTC log

On 18 Dec 2011 at 23:48, Magnus Granberg wrote:

> [21:30:59] <blueness> also, there is a new kernel feature for PaX
> [21:31:12] <blueness> it will be related to the gcc plugin to constify kernel pointers

it's actually for KERNEXEC/amd64, not constification . what the KERNEXEC gcc plugin does is
simple, it ensures that kernel function pointers point to the kernel's part of the address
space. the two methods differ in the low-level asm insn sequences used in the instrumentation
of function pointer dereferences and have a different performance impact (vs. usability).

the BTS method has a higher impact but it's compatible with binary modules (as in, they'll
continue to work but obviously without the extra protection offered by the plugin) whereas
the OR method has a lower impact however it cannot coexist with binary modules (due to the
low-level function call ABI change). so the safe (but less secure) default should probably
be BTS and let the users explicitly switch to OR if they know they won't need binary modules
(there's a runtime check against the module license to ensure some minimum safety against
bad user choice .

Thread Tools

All times are GMT. The time now is 09:42 AM.

VBulletin, Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.
Copyright 2007 - 2008, www.linux-archive.org