Integrating ProPolice/SSP into FreeBSD



Hi,

first sorry for cross-posting but I thought this patch might interest
-CURRENT users as well as people concerned by security.

I wrote a patch that integrates ProPolice/SSP into FreeBSD, one step
further than it has been realized so far.

It is available here :
http://tataz.chchile.org/~tataz/FreeBSD/SSP/

Everything is explained on the web page, but I will repeat some
informations here. The patchset is splitted in two parts to ease the
review of the patch. The -propolice patch is only the original
ProPolice patch for GCC 3.4.4 applied on FreeBSD source tree. The
-freebsd patch contains the glue I have written to make things neat.

The patch exists in both for CURRENT and RELENG_6. Both introduce a
new make.conf(5) (and src.conf(5)) knob to enable stack protection
on a per Makefile basis. It if of course possible to compile your
world with it. Please refer to the web page for more informations.

The patch has been tested and works pretty well. My laptop and my
workstation at work are compiled with SSP : world, kernel and ports,
including X.org.

I hope you will enjoy it.
Regards,
--
Jeremie Le Hen
< jeremie at le-hen dot org >< ttz at chchile dot org >
_______________________________________________
freebsd-current@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Integrating ProPolice/SSP into FreeBSD
    ... I wrote a patch that integrates ProPolice/SSP into FreeBSD, ... SSP-compied libraries with pre-SSP applications? ... applications with pre-SSP binaries? ...
    (FreeBSD-Security)
  • Re: Integrating ProPolice/SSP into FreeBSD
    ... I wrote a patch that integrates ProPolice/SSP into FreeBSD, ... SSP-compied libraries with pre-SSP applications? ... applications with pre-SSP binaries? ...
    (freebsd-current)
  • Re: Integrating ProPolice/SSP into FreeBSD
    ... I wrote a patch that integrates ProPolice/SSP into FreeBSD, ... applications with pre-SSP binaries? ... And with symbol versioning, they would always have to stay ...
    (freebsd-current)
  • Re: Integrating ProPolice/SSP into FreeBSD
    ... I wrote a patch that integrates ProPolice/SSP into FreeBSD, ... applications with pre-SSP binaries? ... And with symbol versioning, they would always have to stay ...
    (FreeBSD-Security)
  • Integrating ProPolice/SSP into FreeBSD
    ... I wrote a patch that integrates ProPolice/SSP into FreeBSD, ... ProPolice patch for GCC 3.4.4 applied on FreeBSD source tree. ... It if of course possible to compile your ...
    (FreeBSD-Security)