Hi everyone!Here is a new version of the hardening patch I sent earlier, after feedback on the original version. This adds the following options to mozilla ports, where available:
--enable-hardening --enable-stl-hardening --enable-rust-simdthe rust simd and stl hardening options can be toggled, in this new patch. i suppose a toggle could be added for --enable-hardening, but i didn't bother
Pros and cons of each is written inside the patch. I'll just paste here what's written in my patch:
enable hardening flags in mozilla projects there is also a rust-sized easter egg.--enable-hardening appends these flags to CFLAGS, CXXFLAGS and LDFLAGS at
build time: * -fstack-protector-strong or -fstack-protector-all depending on target * -D_FORTIFY_SOURCE=2 - useless on openbsd * fPIE - redundant here (forced by default on openbsd llvm/gcc) * -Wl,-z,relro/now: redundant on openbsd * -ftrapv or -fno-strict-overflow: treat signed integer overflow as UBOpenBSD will already do this by default, so this option is likely redundant, but ensures that Mozilla's build system will not *clear* any such flags.
--enable-stl-hardening turns on safe mode and assertions inside the C++standard template library (STL) and catched out of bound array/vector indexing, iterator invalidation, null-pointer deref in stl containsers, and invalid ranges at runtime, mitigating them before they can be exploited. specifically
enables these flags: * for clang using libc++: * -D_LIBCPP_ENABLE_HARDENED_MODE=1 * runtime bounds checks on std::vector::operator[], std::string, std::optional, std::variants and iterator bounds checkingEnabling --enable-stl-hardening forces LLVM's libc++ to abort immediately
if an STL container boundary violation occurs, e.g. calling std::vector::operator out of range. This mitigates errors pertaining to heap corruption, though OpenBSD will already do something for this at kernel level, e.g. pledge is basically the best thing ever. --enable-rust-simd is an interesting one: It can improve performance in some workloads by processing text, data and images using hardware acceleration (simd) depending on the machine.This can cause massive throughput gains in e.g. encoding_rs when decoding web pages (converting raw html/js byte streams into utf/8/16). Normally, html/js markup contain a lot of ascii, and so you have ascii/utf-8 validation; with the simd extension enabled, your browser processes text e.g. 16 or 32
bytes at a time instead of 1 byte at a time, via hardware featureslike sse/avx or neon. It's unknown whether this might negatively impact older
systems, but this would have to be tested over time.image/media processing: lots of this in gecko now are written in rust, e.g. png/jpg decoding, colour profile transformation, audio re-sampling. simd lets rust run identical operations e.g. alpha blending, byte swapping, colour conversion across entire blocks of pixels in a single cpu cycle, instead of doing everything in software. this obviously depends on the user's machine.
faster cryptography/hashing: rust crates used for crypto, https handshakes, and internal structures e.g. fash hash tables, can use simd for parallel bitwise operations and byte shifts, reducing cpu overhead when negotiating
connections and such. Risks associated with --enable-rust-simd:This turns on RUSTC_BOOTSTRAP=1. Despite the name, this doesn't cause anything
to be downloaded, but it does allow certain nightly features to be usedin Rust, that have not yet been declared stable. Turning this option on will bypass compiler safety checks to use experimental features, that may break after updates (e.g. newer rustc/cargo on older mozilla codebase; disabling simd on firefox/thunderbird ESR releases might be prudent). obviously this means that code generation might be a bit buggier, potentially leading to some UB. without this option enabled, rustc will be much more conservative, only generating code that will run on virtually any CPU. one of the downsides doesn't apply to openbsd: this option makes cross compilation less reliable,
but openbsd doesn't use cross compilation anyway. enable hardening flags in mozilla projects there is also a rust-sized easter egg.--enable-hardening appends these flags to CFLAGS, CXXFLAGS and LDFLAGS at
build time: * -fstack-protector-strong or -fstack-protector-all depending on target * -D_FORTIFY_SOURCE=2 - useless on openbsd * fPIE - redundant here (forced by default on openbsd llvm/gcc) * -Wl,-z,relro/now: redundant on openbsd * -ftrapv or -fno-strict-overflow: treat signed integer overflow as UBOpenBSD will already do this by default, so this option is likely redundant, but ensures that Mozilla's build system will not *clear* any such flags.
--enable-stl-hardening turns on safe mode and assertions inside the C++standard template library (STL) and catched out of bound array/vector indexing, iterator invalidation, null-pointer deref in stl containsers, and invalid ranges at runtime, mitigating them before they can be exploited. specifically
enables these flags: * for clang using libc++: * -D_LIBCPP_ENABLE_HARDENED_MODE=1 * runtime bounds checks on std::vector::operator[], std::string, std::optional, std::variants and iterator bounds checkingEnabling --enable-stl-hardening forces LLVM's libc++ to abort immediately
if an STL container boundary violation occurs, e.g. calling std::vector::operator out of range. This mitigates errors pertaining to heap corruption, though OpenBSD will already do something for this at kernel level, e.g. pledge is basically the best thing ever. --enable-rust-simd is an interesting one: It can improve performance in some workloads by processing text, data and images using hardware acceleration (simd) depending on the machine.This can cause massive throughput gains in e.g. encoding_rs when decoding web pages (converting raw html/js byte streams into utf/8/16). Normally, html/js markup contain a lot of ascii, and so you have ascii/utf-8 validation; with the simd extension enabled, your browser processes text e.g. 16 or 32
bytes at a time instead of 1 byte at a time, via hardware featureslike sse/avx or neon. It's unknown whether this might negatively impact older
systems, but this would have to be tested over time.image/media processing: lots of this in gecko now are written in rust, e.g. png/jpg decoding, colour profile transformation, audio re-sampling. simd lets rust run identical operations e.g. alpha blending, byte swapping, colour conversion across entire blocks of pixels in a single cpu cycle, instead of doing everything in software. this obviously depends on the user's machine.
faster cryptography/hashing: rust crates used for crypto, https handshakes, and internal structures e.g. fash hash tables, can use simd for parallel bitwise operations and byte shifts, reducing cpu overhead when negotiating
connections and such. Risks associated with --enable-rust-simd:This turns on RUSTC_BOOTSTRAP=1. Despite the name, this doesn't cause anything
to be downloaded, but it does allow certain nightly features to be usedin Rust, that have not yet been declared stable. Turning this option on will bypass compiler safety checks to use experimental features, that may break after updates (e.g. newer rustc/cargo on older mozilla codebase; disabling simd on firefox/thunderbird ESR releases might be prudent). obviously this means that code generation might be a bit buggier, potentially leading to some UB. without this option enabled, rustc will be much more conservative, only generating code that will run on virtually any CPU. one of the downsides doesn't apply to openbsd: this option makes cross compilation less reliable,
but openbsd doesn't use cross compilation anyway. -- Company director, Minifree Ltd Registered in England, No. 9361826 | VAT No. GB202190462 Registered Office: 19 Hilton Road, Canvey Island, Essex SS8 9QA, UK
From 0fdb6f5d3e5530a2f218141e2a5f7b8dda968206 Mon Sep 17 00:00:00 2001 From: Leah Rowe <[email protected]> Date: Sat, 5 Sep 2026 16:33:55 +0100 Subject: [PATCH 1/1] enable hardening flags in mozilla projects there is also a rust-sized easter egg. --enable-hardening appends these flags to CFLAGS, CXXFLAGS and LDFLAGS at build time: * -fstack-protector-strong or -fstack-protector-all depending on target * -D_FORTIFY_SOURCE=2 - useless on openbsd * fPIE - redundant here (forced by default on openbsd llvm/gcc) * -Wl,-z,relro/now: redundant on openbsd * -ftrapv or -fno-strict-overflow: treat signed integer overflow as UB OpenBSD will already do this by default, so this option is likely redundant, but ensures that Mozilla's build system will not *clear* any such flags. --enable-stl-hardening turns on safe mode and assertions inside the C++ standard template library (STL) and catched out of bound array/vector indexing, iterator invalidation, null-pointer deref in stl containsers, and invalid ranges at runtime, mitigating them before they can be exploited. specifically enables these flags: * for clang using libc++: * -D_LIBCPP_ENABLE_HARDENED_MODE=1 * runtime bounds checks on std::vector::operator[], std::string, std::optional, std::variants and iterator bounds checking Enabling --enable-stl-hardening forces LLVM's libc++ to abort immediately if an STL container boundary violation occurs, e.g. calling std::vector::operator out of range. This mitigates errors pertaining to heap corruption, though OpenBSD will already do something for this at kernel level, e.g. pledge is basically the best thing ever. --enable-rust-simd is an interesting one: It can improve performance in some workloads by processing text, data and images using hardware acceleration (simd) depending on the machine. This can cause massive throughput gains in e.g. encoding_rs when decoding web pages (converting raw html/js byte streams into utf/8/16). Normally, html/js markup contain a lot of ascii, and so you have ascii/utf-8 validation; with the simd extension enabled, your browser processes text e.g. 16 or 32 bytes at a time instead of 1 byte at a time, via hardware features like sse/avx or neon. It's unknown whether this might negatively impact older systems, but this would have to be tested over time. image/media processing: lots of this in gecko now are written in rust, e.g. png/jpg decoding, colour profile transformation, audio re-sampling. simd lets rust run identical operations e.g. alpha blending, byte swapping, colour conversion across entire blocks of pixels in a single cpu cycle, instead of doing everything in software. this obviously depends on the user's machine. faster cryptography/hashing: rust crates used for crypto, https handshakes, and internal structures e.g. fash hash tables, can use simd for parallel bitwise operations and byte shifts, reducing cpu overhead when negotiating connections and such. Risks associated with --enable-rust-simd: This turns on RUSTC_BOOTSTRAP=1. Despite the name, this doesn't cause anything to be downloaded, but it does allow certain nightly features to be used in Rust, that have not yet been declared stable. Turning this option on will bypass compiler safety checks to use experimental features, that may break after updates (e.g. newer rustc/cargo on older mozilla codebase; disabling simd on firefox/thunderbird ESR releases might be prudent). obviously this means that code generation might be a bit buggier, potentially leading to some UB. without this option enabled, rustc will be much more conservative, only generating code that will run on virtually any CPU. one of the downsides doesn't apply to openbsd: this option makes cross compilation less reliable, but openbsd doesn't use cross compilation anyway. Personally, I think --enable-rust-simd is worthwhile. -current updates rustc and cargo all the time, ditto mozilla browsers, and the ESR browsers get built once. We also have pledge/unveil enabled. I have this option enabled in my librewolf port. Signed-off-by: Leah Rowe <[email protected]> --- mail/mozilla-thunderbird/Makefile | 7 +------ www/firefox-esr/Makefile | 7 +------ www/librewolf/Makefile | 6 ------ www/mozilla-firefox/Makefile | 7 +------ www/mozilla/mozilla.port.mk | 23 +++++++++++++++++++++++ www/seamonkey/Makefile | 5 ++++- www/tor-browser/browser/Makefile | 4 ++++ 7 files changed, 34 insertions(+), 25 deletions(-) diff --git a/mail/mozilla-thunderbird/Makefile b/mail/mozilla-thunderbird/Makefile index 83673286271..1fa32206248 100644 --- a/mail/mozilla-thunderbird/Makefile +++ b/mail/mozilla-thunderbird/Makefile @@ -10,6 +10,7 @@ MOZILLA_CODENAME = comm/mail EXTRACT_SUFX = .tar.xz DEBUG_PACKAGES = ${BUILD_PACKAGES} PKGNAME = ${MOZILLA_PROJECT}-${MOZILLA_VERSION:S/esr//:S/b/beta/} +REVISION = 0 # XXX badly formed debug in libxul ? DWZ = : @@ -72,12 +73,6 @@ CONFIGURE_ARGS += --disable-debug-symbols DEBUG_CONFIGURE_ARGS += --enable-debug-symbols \ --disable-install-strip MAKE_ENV += BUILD_VERBOSE_LOG="1" CARGOFLAGS="-j${MAKE_JOBS}" -.if ${MACHINE_ARCH} == aarch64 -# retguard leads to segfault at startup on arm64, cf #1973016 -CONFIGURE_ENV += CPPFLAGS="-fno-ret-protector -Wno-backend-plugin" -.else -CONFIGURE_ENV += CPPFLAGS=-Wno-backend-plugin -.endif CONFIGURE_ENV += LDFLAGS="-Wl,--threads=5 --ld-path=${WRKDIR}/bin/ld" # #2026497 diff --git a/www/firefox-esr/Makefile b/www/firefox-esr/Makefile index 5c3b79b6e2b..d8cd26e3f3c 100644 --- a/www/firefox-esr/Makefile +++ b/www/firefox-esr/Makefile @@ -7,6 +7,7 @@ MOZILLA_PROJECT = firefox-esr MOZILLA_CODENAME = browser MOZILLA_DIST = firefox MOZILLA_PROFDATA_TASKID = BG92wx2xQXCqzNWrQPYftA +REVISION = 0 WRKDIST = ${WRKDIR}/${MOZILLA_DIST}-${MOZILLA_DIST_VERSION:C/esr//} HOMEPAGE = https://www.mozilla.org/firefox/organizations/ @@ -52,12 +53,6 @@ CONFIGURE_SCRIPT = ${MODPY_BIN} ${WRKSRC}/configure.py CONFIGURE_ARGS += --prefix=${PREFIX} CONFIGURE_ARGS += --enable-official-branding MAKE_ENV += BUILD_VERBOSE_LOG="1" CARGOFLAGS="-j${MAKE_JOBS}" -.if ${MACHINE_ARCH} == aarch64 -# retguard leads to segfault at startup on arm64, cf #1973016 -CONFIGURE_ENV += CPPFLAGS="-fno-ret-protector -Wno-backend-plugin" -.else -CONFIGURE_ENV += CPPFLAGS=-Wno-backend-plugin -.endif NCPU !!= sysctl -n hw.ncpuonline .if ${NCPU} > 4 CONFIGURE_ENV += LDFLAGS="-Wl,--threads=5 --ld-path=${WRKDIR}/bin/ld" diff --git a/www/librewolf/Makefile b/www/librewolf/Makefile index b892a47885f..37221d7b1c1 100644 --- a/www/librewolf/Makefile +++ b/www/librewolf/Makefile @@ -71,12 +71,6 @@ WANTLIB += Xrandr CONFIGURE_STYLE = simple CONFIGURE_SCRIPT = ${MODPY_BIN} ${WRKSRC}/configure.py MAKE_ENV += BUILD_VERBOSE_LOG="1" CARGOFLAGS="-j${MAKE_JOBS}" -.if ${MACHINE_ARCH} == aarch64 -# retguard leads to segfault at startup on arm64, cf #1973016 -CONFIGURE_ENV += CPPFLAGS="-fno-ret-protector -Wno-backend-plugin" -.else -CONFIGURE_ENV += CPPFLAGS=-Wno-backend-plugin -.endif CONFIGURE_ENV += LDFLAGS="-Wl,--threads=4 --ld-path=${WRKDIR}/bin/ld" # 2026497 CONFIGURE_ENV += MACH_BUILD_PYTHON_NATIVE_PACKAGE_SOURCE=none diff --git a/www/mozilla-firefox/Makefile b/www/mozilla-firefox/Makefile index 38a20b37577..b779c5312f8 100644 --- a/www/mozilla-firefox/Makefile +++ b/www/mozilla-firefox/Makefile @@ -8,6 +8,7 @@ MOZILLA_BRANCH = release MOZILLA_PROJECT = firefox MOZILLA_CODENAME = browser MOZILLA_PROFDATA_TASKID = SedGEwU-Q5qw_Uw5wT7XHw +REVISION = 0 WRKDIST = ${WRKDIR}/${MOZILLA_DIST}-${MOZILLA_DIST_VERSION:C/b[0-9]*//} HOMEPAGE = https://www.mozilla.org/firefox/ @@ -51,12 +52,6 @@ CONFIGURE_SCRIPT = ${MODPY_BIN} ${WRKSRC}/configure.py CONFIGURE_ARGS += --prefix=${PREFIX} CONFIGURE_ARGS += --enable-official-branding MAKE_ENV += BUILD_VERBOSE_LOG="1" CARGOFLAGS="-j${MAKE_JOBS}" -.if ${MACHINE_ARCH} == aarch64 -# retguard leads to segfault at startup on arm64, cf #1973016 -CONFIGURE_ENV += CPPFLAGS="-fno-ret-protector -Wno-backend-plugin" -.else -CONFIGURE_ENV += CPPFLAGS=-Wno-backend-plugin -.endif CONFIGURE_ENV += LDFLAGS="-Wl,--threads=4 --ld-path=${WRKDIR}/bin/ld" # 2026497 CONFIGURE_ENV += MACH_BUILD_PYTHON_NATIVE_PACKAGE_SOURCE=none diff --git a/www/mozilla/mozilla.port.mk b/www/mozilla/mozilla.port.mk index 68e7bc78668..c32dc54279f 100644 --- a/www/mozilla/mozilla.port.mk +++ b/www/mozilla/mozilla.port.mk @@ -153,6 +153,29 @@ CONFIGURE_ARGS += --with-system-zlib \ --enable-optimize="${CFLAGS}" \ --disable-updater +# depending on rustc/cargo version, it may be +# necessary to omit --enable-rust-simd on some ports as +# this option is sensitive to toolchain updates; ESR +# releases of firefox and thunderbird for example +.if !defined(MOZILLA_DISABLE_RUST_SIMD) +CONFIGURE_ARGS += --enable-rust-simd +.endif + +# hardened build flags +CONFIGURE_ARGS += --enable-hardening +.if !defined(MOZILLA_DISABLE_STL_HARDENING) +# not all ports have this build option +CONFIGURE_ARGS += --enable-stl-hardening +.endif +HARDFLAGS = -ftrivial-auto-var-init=zero -Wno-backend-plugin +.if ${MACHINE_ARCH} == aarch64 +# retguard can lead to segfault at startup on arm64, cf #1973016 +HARDFLAGS += -fno-ret-protector +.endif +CONFIGURE_ENV += CFLAGS="${HARDFLAGS}" +CONFIGURE_ENV += CXXFLAGS="${HARDFLAGS}" +CONFIGURE_ENV += CPPFLAGS="${HARDFLAGS}" + # firefox >= 46 defaults to gtk+3 CONFIGURE_ARGS += --enable-default-toolkit=cairo-gtk3 MODMOZ_LIB_DEPENDS += x11/gtk+3 diff --git a/www/seamonkey/Makefile b/www/seamonkey/Makefile index 0c7756c9e48..dac7237077c 100644 --- a/www/seamonkey/Makefile +++ b/www/seamonkey/Makefile @@ -10,7 +10,7 @@ MOZILLA_PROJECT = seamonkey MOZILLA_CODENAME = comm/suite SITES = https://archive.seamonkey-project.org/releases/${MOZILLA_DIST_VERSION}/source/ -REVISION-main = 0 +REVISION-main = 1 # unbreaks build with modern rust cf #1896958 SITES.p = https://bugzilla.mozilla.org/ @@ -61,6 +61,9 @@ CONFIGURE_ARGS += --prefix=${PREFIX} CONFIGURE_ARGS += --enable-official-branding CONFIGURE_ARGS += --enable-linker=lld +# --enable-stl-hardening unavailable in seamonkey +MOZILLA_DISABLE_STL_HARDENING = Yes + BUILD_DEPENDS += devel/cbindgen>=0.6.1 # autoconf-2.13 isnt a real dependency since a while, but configure still checks for it BUILD_DEPENDS += devel/autoconf/2.13 diff --git a/www/tor-browser/browser/Makefile b/www/tor-browser/browser/Makefile index fad4ce8d13b..fb2f866465a 100644 --- a/www/tor-browser/browser/Makefile +++ b/www/tor-browser/browser/Makefile @@ -7,6 +7,7 @@ COMMENT = modified version of Firefox ESR for browsing over Tor MOZILLA_VERSION = ${TB_VERSION} MOZILLA_PROJECT = ${BROWSER_NAME} MOZILLA_CODENAME = browser +REVISION = 0 EXTRACT_SUFX = .tar.xz @@ -83,6 +84,9 @@ CONFIGURE_ARGS += --prefix=${PREFIX} MAKE_ENV += BUILD_VERBOSE_LOG="1" CARGOFLAGS="-j${MAKE_JOBS}" CONFIGURE_ENV += LDFLAGS="-Wl,--threads=${MAKE_JOBS} --ld-path=${WRKDIR}/bin/ld" +# --enable-stl-hardening unavailable in tor-browser +MOZILLA_DISABLE_STL_HARDENING = Yes + # app-name etc. for tor-browser CONFIGURE_ARGS += --with-app-name=${BROWSER_NAME} \ --with-base-browser-version=${TB_VERSION} \ -- 2.47.3
OpenPGP_0x5C654067D383B1FF.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
