On Fri, Dec 19, 2014 at 02:11:37PM -0800, Andy Lutomirski wrote: ... > > > > Therefore, I can fix the current implementation (maintaining the > > randomize_va_space=2) by moving the PIE executable from the mmap base > > area to another one for x86*, ARM* and MIPS (as s390 and PowerPC do). > > But we shall agree that this increment in the page table is not a > > issue. Otherwise, the randomize_va_space=3 shall be considered. > > Wrt the vdso itself, though, there is an extra consideration: CRIU. I > *think* that the CRIU vdso proxying scheme will work even if the vdso > changes sizes and is adjacent to other mappings. Cyrill and/or Pavel, > am I right?
At least that was the idea. I've been testing old vdso from rhel5 proxified to 3.x series where vvar segment is present, worked well. > I'm not fundamentally opposed to mapping the vdso just like any other > shared library. I still think that we should have an extra-strong > randomization mode in which all the libraries are randomized wrt each > other, though. For many applications, the extra page table cost will > be negligible. -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [email protected] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/

