From: "Johannes Schindelin via GitGitGadget" <gitgitgadget@gmail.com>
To: git@vger.kernel.org
Cc: Junio C Hamano <gitster@pobox.com>
Subject: [PATCH v2 0/2] Enable Data Execution Protection and Address Space Layout Randomization on Windows
Date: Wed, 08 May 2019 04:30:57 -0700 (PDT) [thread overview]
Message-ID: <pull.134.v2.git.gitgitgadget@gmail.com> (raw)
In-Reply-To: <pull.134.git.gitgitgadget@gmail.com>
These two techniques make it harder to come up with exploits, by reducing
what is commonly called the "attack surface" in security circles: by making
the addresses less predictable, and by making it harder to inject data that
is then (mis-)interpreted as code, this hardens Git's executables on
Windows.
These patches have been carried in Git for Windows for over 3 years, and
should therefore be considered battle-tested.
Changes since v1:
* When determining whether we build with optimization, -O0 and -Og are
explicitly ignored.
İsmail Dönmez (2):
mingw: do not let ld strip relocations
mingw: enable DEP and ASLR
config.mak.uname | 8 ++++++++
1 file changed, 8 insertions(+)
base-commit: 83232e38648b51abbcbdb56c94632b6906cc85a6
Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-134%2Fdscho%2Faslr-v2
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-134/dscho/aslr-v2
Pull-Request: https://github.com/gitgitgadget/git/pull/134
Range-diff vs v1:
1: e6acdba586 = 1: 828913e96c mingw: do not let ld strip relocations
2: e142c1396e ! 2: 9f1da73829 mingw: enable DEP and ASLR
@@ -21,13 +21,13 @@
--- a/config.mak.uname
+++ b/config.mak.uname
@@
- ifeq ($(shell expr "$(uname_R)" : '2\.'),2)
+ ifneq ($(shell expr "$(uname_R)" : '1\.'),2)
# MSys2
prefix = /usr/
+ # Enable DEP
+ BASIC_LDFLAGS += -Wl,--nxcompat
+ # Enable ASLR (unless debugging)
-+ ifneq (,$(findstring -O,$(CFLAGS)))
++ ifneq (,$(findstring -O,$(filter-out -O0 -Og,$(CFLAGS))))
+ BASIC_LDFLAGS += -Wl,--dynamicbase
+ endif
ifeq (MINGW32,$(MSYSTEM))
--
gitgitgadget
next prev parent reply other threads:[~2019-05-08 11:31 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-04-29 21:56 [PATCH 0/2] Enable Data Execution Protection and Address Space Layout Randomization on Windows Johannes Schindelin via GitGitGadget
2019-04-29 21:56 ` [PATCH 1/2] mingw: do not let ld strip relocations İsmail Dönmez via GitGitGadget
2019-04-29 21:56 ` [PATCH 2/2] mingw: enable DEP and ASLR İsmail Dönmez via GitGitGadget
2019-04-30 6:26 ` Johannes Sixt
2019-04-30 22:41 ` Johannes Schindelin
2019-04-30 22:59 ` Johannes Sixt
2019-05-01 18:39 ` Alban Gruin
2019-05-01 23:36 ` brian m. carlson
2019-05-08 11:33 ` Johannes Schindelin
2019-05-08 11:33 ` Johannes Schindelin
2019-05-01 20:46 ` Jeff King
2019-05-01 22:02 ` Jonathan Nieder
2019-05-08 11:27 ` Johannes Schindelin
2019-05-08 11:30 ` Johannes Schindelin via GitGitGadget [this message]
2019-05-08 11:30 ` [PATCH v2 1/2] mingw: do not let ld strip relocations İsmail Dönmez via GitGitGadget
2019-05-08 11:30 ` [PATCH v2 2/2] mingw: enable DEP and ASLR İsmail Dönmez via GitGitGadget
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=pull.134.v2.git.gitgitgadget@gmail.com \
--to=gitgitgadget@gmail.com \
--cc=git@vger.kernel.org \
--cc=gitster@pobox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.