From owner-freebsd-security@freebsd.org Thu Mar 10 15:29:58 2016 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 515B6ACBC56 for ; Thu, 10 Mar 2016 15:29:58 +0000 (UTC) (envelope-from carpeddiem@gmail.com) Received: from mail-ig0-x22c.google.com (mail-ig0-x22c.google.com [IPv6:2607:f8b0:4001:c05::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 1FB1B1D00 for ; Thu, 10 Mar 2016 15:29:58 +0000 (UTC) (envelope-from carpeddiem@gmail.com) Received: by mail-ig0-x22c.google.com with SMTP id vs8so19650169igb.1 for ; Thu, 10 Mar 2016 07:29:58 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to; bh=Bl2oY7VVB+A6gHwylXjN71efy8eHgQ0nadBlrXLzw5w=; b=SHyDXaaBTBib+8uNahpJG6PW0VSuL3ZCYuCubcdTSY56lMkxwUfOt/fVfgXm/qyPZI 5hG3Far3rth514gQbUDZ8U7zzehXdao+oTs37ZjK35DKldDJLTtDA9kZ0yxrJnx0cPTn dumaMvZhuidhPO+vpPQVqjlYYYBV0stpN9ON9XE5oZi3jo7E5Mu19xfOTMJbxhnKKtWh +Ua0R+nl7FvotTHWfrbi14LN7vn0zZqdkeIIRBCxAl7GXB2BQ4l7A02HXDDAeAx0mJJF 7Kbb864xrW54hBTuP6jfmlRcniWsBPW2Z2/FTDfcKQRL9xjfp+pWXQvwPWqoaeIy5TLK DntA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to; bh=Bl2oY7VVB+A6gHwylXjN71efy8eHgQ0nadBlrXLzw5w=; b=Gyjqt3TgiflptDUwumooA6VvqB57muwitIcprpKi8g/P1sWj+aV3DrXk8+DsP80VTv s0yzgvxbumia/XmkdKAK3yOn6xmwVrxGl3IRY5zWljh1q4MIcKJagWcFdafjlVgRJGCn PsnURyVTqicjCDWmsv70HJoa6GxLti9f+4o6lF8haznX2yw6wXTEb12U/YiVgAM0ErVB Cn1tbWOLYAxXwFZe5FYLHeGjQK6kOG8t576GAsNnfN22326GVu4JsaGsPTAj4uCGV9IT 1qyO4q+QhEtRBsH//atsnDNTaOb1l78JTUHai9RAYOpRNsTOV0JhyTK6Wh2mOKzKocoH JQLQ== X-Gm-Message-State: AD7BkJKTxse0UcXcGiYvE6OjmWCnGBr5QL1/nsPQPDcyZ/D1IXUWtjghtBOeMdpWd6JPDby/+1CB9r9GgYWETQ== X-Received: by 10.50.12.8 with SMTP id u8mr4207352igb.33.1457623797553; Thu, 10 Mar 2016 07:29:57 -0800 (PST) MIME-Version: 1.0 Sender: carpeddiem@gmail.com Received: by 10.107.39.66 with HTTP; Thu, 10 Mar 2016 07:29:38 -0800 (PST) In-Reply-To: <56E02D95.9020303@anongoth.pl> References: <56E02D95.9020303@anongoth.pl> From: Ed Maste Date: Thu, 10 Mar 2016 10:29:38 -0500 X-Google-Sender-Auth: J6PfW7s0M9VyisqR8kz6So4OTJY Message-ID: Subject: Re: Will 11.0-RELEASE include ASLR? To: freebsd-security@freebsd.org Content-Type: text/plain; charset=UTF-8 X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 10 Mar 2016 15:29:58 -0000 > There are patches ready for FreeBSD to use and it's ready to be shipped > in FreeBSD. However, for some reason FreeBSD developers do not want to > ship ASLR in FreeBSD. Why can't it be included at least as non-default > src.conf option and marked as experimental? A little while ago I asked kib@ to look at the ASLR situation. He implemented a small, more general solution. We planned to post it for review, testing and discussion soon, but given the renewed interest in this topic we'll put it on Phabricator today. I look forward to feedback on the patch from Shawn and the HardenedBSD folks and everyone else with an interest in ASLR on FreeBSD.