stack_guard hardening bsdinstall option in STABLE and 11.1

Vlad K. vlad-fbsd at acheronmedia.com
Mon Jul 17 13:47:14 UTC 2017


On 2017-07-17 15:33, Glen Barber wrote:
> 
> No, this is not available in the 11.1 installer.
> 
> Glen

Thanks but that's why I asked why's that. r320674 said MFC after 1 day. 
Is it too late for 11.1-RELEASE, so it'll be applied to 11-STABLE, or is 
there another reason?

If its' too late, does that mean it's too late for the installer, but 
the new stack_guard code is there in STABLE and I am guessing will be 
part of 11.1, so we can assume the sysctl to be an integer (as opposed 
to enable/disable semantics of the sysctl in 11.0)? In other words, is 
it safe to ramp up the gap size in 11.1?


-- 
Vlad K.


More information about the freebsd-stable mailing list