Hi Byran,

Am 04.09.26 um 12:40 schrieb Bryan Steele:
-fwrapv at least is already the default on OpenBSD, for all compilers.

https://man.openbsd.org/clang-local
If that is true, then that flag can be ommitted when merging the patch. that's fine.

  --enable-hardening

I actually didn't know the answer to this question, so I looked it up.

It's a high-level wrapper in mozilla build systems that enables a bunch of C/C++ mitigations by appending specific flags to the compiler (CFLAGS / CXXFLAGS) and linker (LDFLAGS). Depending on the compiler and OS, it might inject things like:

-D_FORTIFY_SOURCE=2, which will replace vulnerable libc calls like strcpy, memcpy, memset, sprintf etc with more secure, length-checked variants. So, boundary checks and such. It will also introduce behaviour e.g. when a write exceeds a target buffer's size, the process may abort rather than permitting a stack/heap overflow. I know OpenBSD does some of this at kernel level too, but this is implemented at the application layer.

It will harden flags pertaining to stack and memory layout e.g. add -fstack-protector-strong (or -all on some targets). More overflow protection.

It will add flags like -Wl, -z (relro/now), forcing the linker to mark internal data sections read-only after relocation, also eliminates lazy binding and marks the global offset table read-only to prevent overwrite exploits. Also does things e.g. mark stack segments non-executable - again, OpenBSD already does things like this at kernel level e.g. w^x, though I'm aware that there are some complications with this already with mozilla due to the fact that it heavily uses dynamic recompilation for things like javascript.

Depending on platform, it might inject e.g. /guard:cf compiler and linker flags to perform runtime checks on indirect call targets - in other words, mitigate certain ROP attacks.

The --stl-hardening one does more: it turns on runtime bounds checks into the C++ library. So, basically like above but for C++. On LLVM it will enable things like _LIBCPP_HARDENING_MODE=_LIBCPP_HARDENING_MODE_EXTENSIVE

Out of bounds indexing: array uses like e.g. vec[i] or str[i] will have boundary checks also (presumably abort if violating it).

According to my research, it also has a negligible speed impact. Yeah, tl;dr runtime bounds checks enforced by the compiler. Of course, the source code itself should do checks on itself, but no two programmers are made equal are they?+

Look it up yourself. I recommend turning these on by default. Though, given that the context here is OpenBSD, openbsd itself probably turns a bunch of this stuff on by default anyway. In my mind, it certainly can't hurt to turn on these flags anyway.

Basically these flags will make the program abort if it misbehaves, due to memory bugs.

--
Company director, Minifree Ltd
Registered in England, No. 9361826 | VAT No. GB202190462
Registered Office: 19 Hilton Road, Canvey Island, Essex SS8 9QA, UK

Attachment: OpenPGP_0x5C654067D383B1FF.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to