Hi everyone!

Here is a new version of the hardening patch I sent earlier, after feedback on the original version. This adds the following options to mozilla ports, where available:

--enable-hardening

--enable-stl-hardening

--enable-rust-simd

the rust simd and stl hardening options can be toggled, in this new patch. i suppose a toggle could be added for --enable-hardening, but i didn't bother

Pros and cons of each is written inside the patch. I'll just paste here what's written in my patch:

    enable hardening flags in mozilla projects

    there is also a rust-sized easter egg.

    --enable-hardening appends these flags to CFLAGS, CXXFLAGS and LDFLAGS at
    build time:
    * -fstack-protector-strong or -fstack-protector-all depending on target
    * -D_FORTIFY_SOURCE=2 - useless on openbsd
    * fPIE - redundant here (forced by default on openbsd llvm/gcc)
    * -Wl,-z,relro/now: redundant on openbsd
    * -ftrapv or -fno-strict-overflow: treat signed integer overflow as UB

    OpenBSD will already do this by default, so this option is likely redundant,     but ensures that Mozilla's build system will not *clear* any such flags.

    --enable-stl-hardening turns on safe mode and assertions inside the C++
    standard template library (STL) and catched out of bound array/vector indexing,     iterator invalidation, null-pointer deref in stl containsers, and invalid     ranges at runtime, mitigating them before they can be exploited. specifically
    enables these flags:
    * for clang using libc++:
     * -D_LIBCPP_ENABLE_HARDENED_MODE=1
     * runtime bounds checks on std::vector::operator[], std::string,
       std::optional, std::variants and iterator bounds checking

    Enabling --enable-stl-hardening forces LLVM's libc++ to abort immediately
    if an STL container boundary violation occurs, e.g. calling
    std::vector::operator out of range. This mitigates errors pertaining to
    heap corruption, though OpenBSD will already do something for this at
    kernel level, e.g. pledge is basically the best thing ever.

    --enable-rust-simd is an interesting one:
    It can improve performance in some workloads by processing text, data
    and images using hardware acceleration (simd) depending on the machine.
    This can cause massive throughput gains in e.g. encoding_rs when decoding     web pages (converting raw html/js byte streams into utf/8/16). Normally,     html/js markup contain a lot of ascii, and so you have ascii/utf-8 validation;     with the simd extension enabled, your browser processes text e.g. 16 or 32
    bytes at a time instead of 1 byte at a time, via hardware features
    like sse/avx or neon. It's unknown whether this might negatively impact older
    systems, but this would have to be tested over time.

    image/media processing: lots of this in gecko now are written in rust, e.g.     png/jpg decoding, colour profile transformation, audio re-sampling. simd     lets rust run identical operations e.g. alpha blending, byte swapping, colour     conversion across entire blocks of pixels in a single cpu cycle, instead of     doing everything in software. this obviously depends on the user's machine.

    faster cryptography/hashing: rust crates used for crypto, https handshakes,     and internal structures e.g. fash hash tables, can use simd for parallel     bitwise operations and byte shifts, reducing cpu overhead when negotiating
    connections and such.

    Risks associated with --enable-rust-simd:

    This turns on RUSTC_BOOTSTRAP=1. Despite the name, this doesn't cause anything
    to be downloaded, but it does allow certain nightly features to be used
    in Rust, that have not yet been declared stable. Turning this option on will     bypass compiler safety checks to use experimental features, that may break     after updates (e.g. newer rustc/cargo on older mozilla codebase; disabling     simd on firefox/thunderbird ESR releases might be prudent). obviously this     means that code generation might be a bit buggier, potentially leading to     some UB. without this option enabled, rustc will be much more conservative,     only generating code that will run on virtually any CPU. one of the downsides     doesn't apply to openbsd: this option makes cross compilation less reliable,
    but openbsd doesn't use cross compilation anyway.

    enable hardening flags in mozilla projects

    there is also a rust-sized easter egg.

    --enable-hardening appends these flags to CFLAGS, CXXFLAGS and LDFLAGS at
    build time:
    * -fstack-protector-strong or -fstack-protector-all depending on target
    * -D_FORTIFY_SOURCE=2 - useless on openbsd
    * fPIE - redundant here (forced by default on openbsd llvm/gcc)
    * -Wl,-z,relro/now: redundant on openbsd
    * -ftrapv or -fno-strict-overflow: treat signed integer overflow as UB

    OpenBSD will already do this by default, so this option is likely redundant,     but ensures that Mozilla's build system will not *clear* any such flags.

    --enable-stl-hardening turns on safe mode and assertions inside the C++
    standard template library (STL) and catched out of bound array/vector indexing,     iterator invalidation, null-pointer deref in stl containsers, and invalid     ranges at runtime, mitigating them before they can be exploited. specifically
    enables these flags:
    * for clang using libc++:
     * -D_LIBCPP_ENABLE_HARDENED_MODE=1
     * runtime bounds checks on std::vector::operator[], std::string,
       std::optional, std::variants and iterator bounds checking

    Enabling --enable-stl-hardening forces LLVM's libc++ to abort immediately
    if an STL container boundary violation occurs, e.g. calling
    std::vector::operator out of range. This mitigates errors pertaining to
    heap corruption, though OpenBSD will already do something for this at
    kernel level, e.g. pledge is basically the best thing ever.

    --enable-rust-simd is an interesting one:
    It can improve performance in some workloads by processing text, data
    and images using hardware acceleration (simd) depending on the machine.
    This can cause massive throughput gains in e.g. encoding_rs when decoding     web pages (converting raw html/js byte streams into utf/8/16). Normally,     html/js markup contain a lot of ascii, and so you have ascii/utf-8 validation;     with the simd extension enabled, your browser processes text e.g. 16 or 32
    bytes at a time instead of 1 byte at a time, via hardware features
    like sse/avx or neon. It's unknown whether this might negatively impact older
    systems, but this would have to be tested over time.

    image/media processing: lots of this in gecko now are written in rust, e.g.     png/jpg decoding, colour profile transformation, audio re-sampling. simd     lets rust run identical operations e.g. alpha blending, byte swapping, colour     conversion across entire blocks of pixels in a single cpu cycle, instead of     doing everything in software. this obviously depends on the user's machine.

    faster cryptography/hashing: rust crates used for crypto, https handshakes,     and internal structures e.g. fash hash tables, can use simd for parallel     bitwise operations and byte shifts, reducing cpu overhead when negotiating
    connections and such.

    Risks associated with --enable-rust-simd:

    This turns on RUSTC_BOOTSTRAP=1. Despite the name, this doesn't cause anything
    to be downloaded, but it does allow certain nightly features to be used
    in Rust, that have not yet been declared stable. Turning this option on will     bypass compiler safety checks to use experimental features, that may break     after updates (e.g. newer rustc/cargo on older mozilla codebase; disabling     simd on firefox/thunderbird ESR releases might be prudent). obviously this     means that code generation might be a bit buggier, potentially leading to     some UB. without this option enabled, rustc will be much more conservative,     only generating code that will run on virtually any CPU. one of the downsides     doesn't apply to openbsd: this option makes cross compilation less reliable,
    but openbsd doesn't use cross compilation anyway.

--
Company director, Minifree Ltd
Registered in England, No. 9361826 | VAT No. GB202190462
Registered Office: 19 Hilton Road, Canvey Island, Essex SS8 9QA, UK

From 0fdb6f5d3e5530a2f218141e2a5f7b8dda968206 Mon Sep 17 00:00:00 2001
From: Leah Rowe <[email protected]>
Date: Sat, 5 Sep 2026 16:33:55 +0100
Subject: [PATCH 1/1] enable hardening flags in mozilla projects

there is also a rust-sized easter egg.

--enable-hardening appends these flags to CFLAGS, CXXFLAGS and LDFLAGS at
build time:
* -fstack-protector-strong or -fstack-protector-all depending on target
* -D_FORTIFY_SOURCE=2 - useless on openbsd
* fPIE - redundant here (forced by default on openbsd llvm/gcc)
* -Wl,-z,relro/now: redundant on openbsd
* -ftrapv or -fno-strict-overflow: treat signed integer overflow as UB

OpenBSD will already do this by default, so this option is likely redundant,
but ensures that Mozilla's build system will not *clear* any such flags.

--enable-stl-hardening turns on safe mode and assertions inside the C++
standard template library (STL) and catched out of bound array/vector indexing,
iterator invalidation, null-pointer deref in stl containsers, and invalid
ranges at runtime, mitigating them before they can be exploited. specifically
enables these flags:
* for clang using libc++:
 * -D_LIBCPP_ENABLE_HARDENED_MODE=1
 * runtime bounds checks on std::vector::operator[], std::string,
   std::optional, std::variants and iterator bounds checking

Enabling --enable-stl-hardening forces LLVM's libc++ to abort immediately
if an STL container boundary violation occurs, e.g. calling
std::vector::operator out of range. This mitigates errors pertaining to
heap corruption, though OpenBSD will already do something for this at
kernel level, e.g. pledge is basically the best thing ever.

--enable-rust-simd is an interesting one:
It can improve performance in some workloads by processing text, data
and images using hardware acceleration (simd) depending on the machine.
This can cause massive throughput gains in e.g. encoding_rs when decoding
web pages (converting raw html/js byte streams into utf/8/16). Normally,
html/js markup contain a lot of ascii, and so you have ascii/utf-8 validation;
with the simd extension enabled, your browser processes text e.g. 16 or 32
bytes at a time instead of 1 byte at a time, via hardware features
like sse/avx or neon. It's unknown whether this might negatively impact older
systems, but this would have to be tested over time.

image/media processing: lots of this in gecko now are written in rust, e.g.
png/jpg decoding, colour profile transformation, audio re-sampling. simd
lets rust run identical operations e.g. alpha blending, byte swapping, colour
conversion across entire blocks of pixels in a single cpu cycle, instead of
doing everything in software. this obviously depends on the user's machine.

faster cryptography/hashing: rust crates used for crypto, https handshakes,
and internal structures e.g. fash hash tables, can use simd for parallel
bitwise operations and byte shifts, reducing cpu overhead when negotiating
connections and such.

Risks associated with --enable-rust-simd:

This turns on RUSTC_BOOTSTRAP=1. Despite the name, this doesn't cause anything
to be downloaded, but it does allow certain nightly features to be used
in Rust, that have not yet been declared stable. Turning this option on will
bypass compiler safety checks to use experimental features, that may break
after updates (e.g. newer rustc/cargo on older mozilla codebase; disabling
simd on firefox/thunderbird ESR releases might be prudent). obviously this
means that code generation might be a bit buggier, potentially leading to
some UB. without this option enabled, rustc will be much more conservative,
only generating code that will run on virtually any CPU. one of the downsides
doesn't apply to openbsd: this option makes cross compilation less reliable,
but openbsd doesn't use cross compilation anyway.

Personally, I think --enable-rust-simd is worthwhile. -current updates rustc
and cargo all the time, ditto mozilla browsers, and the ESR browsers get
built once. We also have pledge/unveil enabled. I have this option enabled
in my librewolf port.

Signed-off-by: Leah Rowe <[email protected]>
---
 mail/mozilla-thunderbird/Makefile |  7 +------
 www/firefox-esr/Makefile          |  7 +------
 www/librewolf/Makefile            |  6 ------
 www/mozilla-firefox/Makefile      |  7 +------
 www/mozilla/mozilla.port.mk       | 23 +++++++++++++++++++++++
 www/seamonkey/Makefile            |  5 ++++-
 www/tor-browser/browser/Makefile  |  4 ++++
 7 files changed, 34 insertions(+), 25 deletions(-)

diff --git a/mail/mozilla-thunderbird/Makefile b/mail/mozilla-thunderbird/Makefile
index 83673286271..1fa32206248 100644
--- a/mail/mozilla-thunderbird/Makefile
+++ b/mail/mozilla-thunderbird/Makefile
@@ -10,6 +10,7 @@ MOZILLA_CODENAME =	comm/mail
 EXTRACT_SUFX =		.tar.xz
 DEBUG_PACKAGES =	${BUILD_PACKAGES}
 PKGNAME =	${MOZILLA_PROJECT}-${MOZILLA_VERSION:S/esr//:S/b/beta/}
+REVISION = 0
 
 # XXX badly formed debug in libxul ?
 DWZ = :
@@ -72,12 +73,6 @@ CONFIGURE_ARGS +=	--disable-debug-symbols
 DEBUG_CONFIGURE_ARGS +=	--enable-debug-symbols \
 			--disable-install-strip
 MAKE_ENV +=		BUILD_VERBOSE_LOG="1" CARGOFLAGS="-j${MAKE_JOBS}"
-.if ${MACHINE_ARCH} == aarch64
-# retguard leads to segfault at startup on arm64, cf #1973016
-CONFIGURE_ENV +=	CPPFLAGS="-fno-ret-protector -Wno-backend-plugin"
-.else
-CONFIGURE_ENV +=	CPPFLAGS=-Wno-backend-plugin
-.endif
 CONFIGURE_ENV +=	LDFLAGS="-Wl,--threads=5 --ld-path=${WRKDIR}/bin/ld"
 
 # #2026497
diff --git a/www/firefox-esr/Makefile b/www/firefox-esr/Makefile
index 5c3b79b6e2b..d8cd26e3f3c 100644
--- a/www/firefox-esr/Makefile
+++ b/www/firefox-esr/Makefile
@@ -7,6 +7,7 @@ MOZILLA_PROJECT =	firefox-esr
 MOZILLA_CODENAME =	browser
 MOZILLA_DIST =		firefox
 MOZILLA_PROFDATA_TASKID = BG92wx2xQXCqzNWrQPYftA
+REVISION = 0
 
 WRKDIST =	${WRKDIR}/${MOZILLA_DIST}-${MOZILLA_DIST_VERSION:C/esr//}
 HOMEPAGE =	https://www.mozilla.org/firefox/organizations/
@@ -52,12 +53,6 @@ CONFIGURE_SCRIPT =	${MODPY_BIN} ${WRKSRC}/configure.py
 CONFIGURE_ARGS +=	--prefix=${PREFIX}
 CONFIGURE_ARGS +=	--enable-official-branding
 MAKE_ENV +=		BUILD_VERBOSE_LOG="1" CARGOFLAGS="-j${MAKE_JOBS}"
-.if ${MACHINE_ARCH} == aarch64
-# retguard leads to segfault at startup on arm64, cf #1973016
-CONFIGURE_ENV +=	CPPFLAGS="-fno-ret-protector -Wno-backend-plugin"
-.else
-CONFIGURE_ENV +=	CPPFLAGS=-Wno-backend-plugin
-.endif
 NCPU !!=		sysctl -n hw.ncpuonline
 .if ${NCPU} > 4
 CONFIGURE_ENV +=	LDFLAGS="-Wl,--threads=5 --ld-path=${WRKDIR}/bin/ld"
diff --git a/www/librewolf/Makefile b/www/librewolf/Makefile
index b892a47885f..37221d7b1c1 100644
--- a/www/librewolf/Makefile
+++ b/www/librewolf/Makefile
@@ -71,12 +71,6 @@ WANTLIB += Xrandr
 CONFIGURE_STYLE =	simple
 CONFIGURE_SCRIPT =	${MODPY_BIN} ${WRKSRC}/configure.py
 MAKE_ENV +=		BUILD_VERBOSE_LOG="1" CARGOFLAGS="-j${MAKE_JOBS}"
-.if ${MACHINE_ARCH} == aarch64
-# retguard leads to segfault at startup on arm64, cf #1973016
-CONFIGURE_ENV +=	CPPFLAGS="-fno-ret-protector -Wno-backend-plugin"
-.else
-CONFIGURE_ENV +=	CPPFLAGS=-Wno-backend-plugin
-.endif
 CONFIGURE_ENV +=	LDFLAGS="-Wl,--threads=4 --ld-path=${WRKDIR}/bin/ld"
 # 2026497
 CONFIGURE_ENV +=       MACH_BUILD_PYTHON_NATIVE_PACKAGE_SOURCE=none
diff --git a/www/mozilla-firefox/Makefile b/www/mozilla-firefox/Makefile
index 38a20b37577..b779c5312f8 100644
--- a/www/mozilla-firefox/Makefile
+++ b/www/mozilla-firefox/Makefile
@@ -8,6 +8,7 @@ MOZILLA_BRANCH =	release
 MOZILLA_PROJECT =	firefox
 MOZILLA_CODENAME =	browser
 MOZILLA_PROFDATA_TASKID =	SedGEwU-Q5qw_Uw5wT7XHw
+REVISION = 0
 
 WRKDIST =	${WRKDIR}/${MOZILLA_DIST}-${MOZILLA_DIST_VERSION:C/b[0-9]*//}
 HOMEPAGE =	https://www.mozilla.org/firefox/
@@ -51,12 +52,6 @@ CONFIGURE_SCRIPT =	${MODPY_BIN} ${WRKSRC}/configure.py
 CONFIGURE_ARGS +=	--prefix=${PREFIX}
 CONFIGURE_ARGS +=	--enable-official-branding
 MAKE_ENV +=		BUILD_VERBOSE_LOG="1" CARGOFLAGS="-j${MAKE_JOBS}"
-.if ${MACHINE_ARCH} == aarch64
-# retguard leads to segfault at startup on arm64, cf #1973016
-CONFIGURE_ENV +=	CPPFLAGS="-fno-ret-protector -Wno-backend-plugin"
-.else
-CONFIGURE_ENV +=	CPPFLAGS=-Wno-backend-plugin
-.endif
 CONFIGURE_ENV +=	LDFLAGS="-Wl,--threads=4 --ld-path=${WRKDIR}/bin/ld"
 # 2026497
 CONFIGURE_ENV +=	MACH_BUILD_PYTHON_NATIVE_PACKAGE_SOURCE=none
diff --git a/www/mozilla/mozilla.port.mk b/www/mozilla/mozilla.port.mk
index 68e7bc78668..c32dc54279f 100644
--- a/www/mozilla/mozilla.port.mk
+++ b/www/mozilla/mozilla.port.mk
@@ -153,6 +153,29 @@ CONFIGURE_ARGS +=	--with-system-zlib	\
 		--enable-optimize="${CFLAGS}"	\
 		--disable-updater
 
+# depending on rustc/cargo version, it may be
+# necessary to omit --enable-rust-simd on some ports as
+# this option is sensitive to toolchain updates; ESR
+# releases of firefox and thunderbird for example
+.if !defined(MOZILLA_DISABLE_RUST_SIMD)
+CONFIGURE_ARGS +=	--enable-rust-simd
+.endif
+
+# hardened build flags
+CONFIGURE_ARGS +=	--enable-hardening
+.if !defined(MOZILLA_DISABLE_STL_HARDENING)
+# not all ports have this build option
+CONFIGURE_ARGS +=	--enable-stl-hardening
+.endif
+HARDFLAGS =	-ftrivial-auto-var-init=zero -Wno-backend-plugin
+.if ${MACHINE_ARCH} == aarch64
+# retguard can lead to segfault at startup on arm64, cf #1973016
+HARDFLAGS +=	-fno-ret-protector
+.endif
+CONFIGURE_ENV +=	CFLAGS="${HARDFLAGS}"
+CONFIGURE_ENV +=	CXXFLAGS="${HARDFLAGS}"
+CONFIGURE_ENV +=	CPPFLAGS="${HARDFLAGS}"
+
 # firefox >= 46 defaults to gtk+3
 CONFIGURE_ARGS +=	--enable-default-toolkit=cairo-gtk3
 MODMOZ_LIB_DEPENDS +=	x11/gtk+3
diff --git a/www/seamonkey/Makefile b/www/seamonkey/Makefile
index 0c7756c9e48..dac7237077c 100644
--- a/www/seamonkey/Makefile
+++ b/www/seamonkey/Makefile
@@ -10,7 +10,7 @@ MOZILLA_PROJECT =	seamonkey
 MOZILLA_CODENAME =	comm/suite
 SITES =	https://archive.seamonkey-project.org/releases/${MOZILLA_DIST_VERSION}/source/
 
-REVISION-main =		0
+REVISION-main =		1
 
 # unbreaks build with modern rust cf #1896958
 SITES.p =	https://bugzilla.mozilla.org/
@@ -61,6 +61,9 @@ CONFIGURE_ARGS +=	--prefix=${PREFIX}
 CONFIGURE_ARGS +=	--enable-official-branding
 CONFIGURE_ARGS +=	--enable-linker=lld
 
+# --enable-stl-hardening unavailable in seamonkey
+MOZILLA_DISABLE_STL_HARDENING = Yes
+
 BUILD_DEPENDS +=	devel/cbindgen>=0.6.1
 # autoconf-2.13 isnt a real dependency since a while, but configure still checks for it
 BUILD_DEPENDS +=	devel/autoconf/2.13
diff --git a/www/tor-browser/browser/Makefile b/www/tor-browser/browser/Makefile
index fad4ce8d13b..fb2f866465a 100644
--- a/www/tor-browser/browser/Makefile
+++ b/www/tor-browser/browser/Makefile
@@ -7,6 +7,7 @@ COMMENT =		modified version of Firefox ESR for browsing over Tor
 MOZILLA_VERSION =	${TB_VERSION}
 MOZILLA_PROJECT =	${BROWSER_NAME}
 MOZILLA_CODENAME =	browser
+REVISION = 0
 
 EXTRACT_SUFX =		.tar.xz
 
@@ -83,6 +84,9 @@ CONFIGURE_ARGS +=	--prefix=${PREFIX}
 MAKE_ENV +=		BUILD_VERBOSE_LOG="1" CARGOFLAGS="-j${MAKE_JOBS}"
 CONFIGURE_ENV +=	LDFLAGS="-Wl,--threads=${MAKE_JOBS} --ld-path=${WRKDIR}/bin/ld"
 
+# --enable-stl-hardening unavailable in tor-browser
+MOZILLA_DISABLE_STL_HARDENING = Yes
+
 # app-name etc. for tor-browser
 CONFIGURE_ARGS +=	--with-app-name=${BROWSER_NAME}			\
 			--with-base-browser-version=${TB_VERSION}	\
-- 
2.47.3

Attachment: OpenPGP_0x5C654067D383B1FF.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to