From nobody Tue Jul 19 09:57:54 2022 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4LnDm31TYyz4Wvf8; Tue, 19 Jul 2022 09:57:55 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4LnDm30zWvz461s; Tue, 19 Jul 2022 09:57:55 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1658224675; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=IJFaQShN7S0sFiKGrYcYQHTzRgfTKz4MmwQVLDpIBjs=; b=RXvhkUwdTiqV0TS27Mka0kfRytHpE3Vj5m/RnejMbGWW89KXAVoso4lDhZvnjgVwIC6Su9 OSKuHfX0ONvQqTSj/fK/dzlor9DTk5WMrfSEBtaJF7CLR3HM9eehMs43GeIxnpv8jcg/KM f0jnOaQKFoTWIBaX1E+G8CZU6BxBvtE/rMl6ul1rucDQtS5BldibCR/KRyo/4gImxlVZaw XtMr90Vua6mM8V91wA+zo2afbLd4hpC8zhj8MfP+sBr0/9hK4BRVWL14l5QrwVhbx9rrIC qLbh0ak0s0Mk4HmT64MDNKX1isM7/lUWZuMOCky+Y+9DrN+WFzwggkyW6nlpDw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4LnDm301cHzFcT; Tue, 19 Jul 2022 09:57:55 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 26J9vs4o013140; Tue, 19 Jul 2022 09:57:54 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 26J9vsLD013139; Tue, 19 Jul 2022 09:57:54 GMT (envelope-from git) Date: Tue, 19 Jul 2022 09:57:54 GMT Message-Id: <202207190957.26J9vsLD013139@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: =?utf-8?Q?Kornel=20Dul=C4=99ba?= Subject: git: fec5791f9846 - stable/13 - Revert "bsdinstall: add knob to set ASLR sysctls" List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-all@freebsd.org X-BeenThere: dev-commits-src-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kd X-Git-Repository: src X-Git-Refname: refs/heads/stable/13 X-Git-Reftype: branch X-Git-Commit: fec5791f98468672ca3e37ea357238e29e1f8a50 Auto-Submitted: auto-generated ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1658224675; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=IJFaQShN7S0sFiKGrYcYQHTzRgfTKz4MmwQVLDpIBjs=; b=fW6s3b6F86IGFmmQ2iCFQaBkOLvXdmHiFxs/yTv/Bn0X2cEc+5BeSc6NX9FSPgUgGLxYeT IVoBZXd2um7OzPY9Prx4yXJFhtLc3PmZ6B8tlZdSRuPhNiG4O+W7tN/Ulexmn59pZ9aDXK eA667NckGuAyi3CCJbXlMpi/Pg+oeT9a861EtE07Rvtlwl/9DXnPMaB1EBzByU14X1TCPj WBYb1EXv1/lF+HzUM7ZprcYNW5BrIzOcEFl9yGzKBzx1w7u6dd6k48uTlKxU2tcT2L1AzS TrijeQJC730vHxkYXjiFhVsp1mGyhFgjj/LhP2aVQ7EIcCSjUHu3I50rLuQqwg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1658224675; a=rsa-sha256; cv=none; b=nJHMP8ylw5PlvtSMVvs68pCQY79RxaidKeVo9pMR981Lms9BQcYonQcRtfCzAQBfndctp4 Mq5y8IPZIj6SW6goQdM1JmpRCf1TzOHyzqOhk37C5+lEYGmcNjAu8Lxu5D51jxCcBDYjF6 OsQD4+26zUrgsU4erSWQgOltPvdt3LBHXPRfCa8yII/5n7cC+cPVVGMhfNQh0uuSgFOeis z0Qf8M7fs2AXjhF8TH5OuycXJwMHwgaUzqEfYu6IwflpZH9/7HqkJ+IdIq94fna54zE+qR XHMMiR6a+4PIkLs30o76d4TBBcMK/9Bra9VaLwCmyV2a7nqcqMrBbovmMj4D+g== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N The branch stable/13 has been updated by kd: URL: https://cgit.FreeBSD.org/src/commit/?id=fec5791f98468672ca3e37ea357238e29e1f8a50 commit fec5791f98468672ca3e37ea357238e29e1f8a50 Author: Marcin Wojtas AuthorDate: 2021-11-12 19:32:57 +0000 Commit: Kornel Dulęba CommitDate: 2022-07-19 09:37:31 +0000 Revert "bsdinstall: add knob to set ASLR sysctls" This reverts commit 020f4112559ebf7e94665c9a69f89d21929ce82a. Because now ASLR is enabled by default for 64-bit architectures and the purpose of the installation menu is to allow choosing additional 'mitigation'/'hardening' options that are originally disabled, remove the ASLR knob from bsdinstall. Discussed with: emaste Obtained from: Semihalf Sponsored by: Stormshield (cherry picked from commit bf410c6eda515364db5f6ed74b765efdec0595ae) --- usr.sbin/bsdinstall/scripts/hardening | 18 ------------------ 1 file changed, 18 deletions(-) diff --git a/usr.sbin/bsdinstall/scripts/hardening b/usr.sbin/bsdinstall/scripts/hardening index 67ee3672712d..58ea0a112e26 100755 --- a/usr.sbin/bsdinstall/scripts/hardening +++ b/usr.sbin/bsdinstall/scripts/hardening @@ -28,20 +28,6 @@ : ${DIALOG_OK=0} -set_aslr_sysctls() -{ - for bit in 32 64; do - if ! sysctl -Nq kern.elf$bit.aslr.enable >/dev/null; then - continue - fi - cat >> $BSDINSTALL_TMPETC/sysctl.conf.hardening <<-EOF - kern.elf$bit.aslr.enable=1 - kern.elf$bit.aslr.pie_enable=1 - kern.elf$bit.aslr.honor_sbrk=0 - EOF - done -} - echo -n > $BSDINSTALL_TMPETC/rc.conf.hardening echo -n > $BSDINSTALL_TMPETC/sysctl.conf.hardening echo -n > $BSDINSTALL_TMPBOOT/loader.conf.hardening @@ -62,7 +48,6 @@ FEATURES=$( dialog --backtitle "FreeBSD Installer" \ "8 disable_sendmail" "Disable Sendmail service" ${disable_sendmail:-off} \ "9 secure_console" "Enable console password prompt" ${secure_console:-off} \ "10 disable_ddtrace" "Disallow DTrace destructive-mode" ${disable_ddtrace:-off} \ - "11 enable_aslr" "Enable address layout randomization" ${enable_aslr:-off} \ 2>&1 1>&3 ) exec 3>&- @@ -101,9 +86,6 @@ for feature in $FEATURES; do disable_ddtrace) echo 'security.bsd.allow_destructive_dtrace=0' >> $BSDINSTALL_TMPBOOT/loader.conf.hardening ;; - enable_aslr) - set_aslr_sysctls - ;; esac done