Re: [RFC] Enable nxstack by default

2011-11-16 Thread Kostik Belousov
On Wed, Nov 16, 2011 at 01:09:18AM +0100, Oliver Pinter wrote: > On 11/15/11, Jeremie Le Hen wrote: > > Hi, > > > > On Wed, Oct 19, 2011 at 12:37:44AM +0200, Oliver Pinter wrote: > >> In NetBSD has been some PaX feature [0] implemented. (ASLR, W^X > >> (~nxstack), mprotect restriction, veriexec, m

Re: [RFC] Enable nxstack by default

2011-11-15 Thread Oliver Pinter
On 11/15/11, Jeremie Le Hen wrote: > Hi, > > On Wed, Oct 19, 2011 at 12:37:44AM +0200, Oliver Pinter wrote: >> In NetBSD has been some PaX feature [0] implemented. (ASLR, W^X >> (~nxstack), mprotect restriction, veriexec, mmap randomization[2]...) >> >> [0] http://pax.grsecurity.net/docs/index.htm

Re: [RFC] Enable nxstack by default

2011-11-15 Thread Jeremie Le Hen
Hi, On Wed, Oct 19, 2011 at 12:37:44AM +0200, Oliver Pinter wrote: > In NetBSD has been some PaX feature [0] implemented. (ASLR, W^X > (~nxstack), mprotect restriction, veriexec, mmap randomization[2]...) > > [0] http://pax.grsecurity.net/docs/index.html > [1] http://www.netbsd.org/~elad/recent/m

Re: [RFC] Enable nxstack by default

2011-10-18 Thread Oliver Pinter
In NetBSD has been some PaX feature [0] implemented. (ASLR, W^X (~nxstack), mprotect restriction, veriexec, mmap randomization[2]...) [0] http://pax.grsecurity.net/docs/index.html [1] http://www.netbsd.org/~elad/recent/man/security.8.html [2] http://people.freebsd.org/~ssouhlal/testing/stackgap-20

Re: [RFC] Enable nxstack by default

2011-10-18 Thread Arnaud Lacombe
Hi, 2011/10/18 Kostik Belousov : > On Tue, Oct 18, 2011 at 01:06:27PM -0400, Arnaud Lacombe wrote: >> Hi, >> >> On Tue, Oct 18, 2011 at 12:53 PM, Oliver Pinter >> wrote: >> > On 10/18/11, Arnaud Lacombe wrote: >> >> Hi, >> >> >> >> On Tue, Oct 18, 2011 at 11:44 AM, Garrett Cooper >> >> wrote:

Re: [RFC] Enable nxstack by default

2011-10-18 Thread Kostik Belousov
On Tue, Oct 18, 2011 at 01:06:27PM -0400, Arnaud Lacombe wrote: > Hi, > > On Tue, Oct 18, 2011 at 12:53 PM, Oliver Pinter wrote: > > On 10/18/11, Arnaud Lacombe wrote: > >> Hi, > >> > >> On Tue, Oct 18, 2011 at 11:44 AM, Garrett Cooper > >> wrote: > >>> On Tue, 18 Oct 2011, Arnaud Lacombe wrot

Re: [RFC] Enable nxstack by default

2011-10-18 Thread Arnaud Lacombe
Hi, On Tue, Oct 18, 2011 at 12:53 PM, Oliver Pinter wrote: > On 10/18/11, Arnaud Lacombe wrote: >> Hi, >> >> On Tue, Oct 18, 2011 at 11:44 AM, Garrett Cooper wrote: >>> On Tue, 18 Oct 2011, Arnaud Lacombe wrote: >>> Hi, On Tue, Oct 18, 2011 at 5:07 AM, Kostik Belousov wrote

Re: [RFC] Enable nxstack by default

2011-10-18 Thread Oliver Pinter
On 10/18/11, Arnaud Lacombe wrote: > Hi, > > On Tue, Oct 18, 2011 at 11:44 AM, Garrett Cooper wrote: >> On Tue, 18 Oct 2011, Arnaud Lacombe wrote: >> >>> Hi, >>> >>> On Tue, Oct 18, 2011 at 5:07 AM, Kostik Belousov >>> wrote: On Mon, Oct 17, 2011 at 09:30:56PM +0200, Oliver Pinter wrot

Re: [RFC] Enable nxstack by default

2011-10-18 Thread Garrett Cooper
On Oct 18, 2011, at 9:26 AM, Arnaud Lacombe wrote: > Hi, > > On Tue, Oct 18, 2011 at 11:44 AM, Garrett Cooper wrote: >> On Tue, 18 Oct 2011, Arnaud Lacombe wrote: >> >>> Hi, >>> >>> On Tue, Oct 18, 2011 at 5:07 AM, Kostik Belousov >>> wrote: On Mon, Oct 17, 2011 at 09:30:56PM +0200

Re: [RFC] Enable nxstack by default

2011-10-18 Thread Arnaud Lacombe
Hi, On Tue, Oct 18, 2011 at 11:44 AM, Garrett Cooper wrote: > On Tue, 18 Oct 2011, Arnaud Lacombe wrote: > >> Hi, >> >> On Tue, Oct 18, 2011 at 5:07 AM, Kostik Belousov >> wrote: >>> >>> On Mon, Oct 17, 2011 at 09:30:56PM +0200, Oliver Pinter wrote: Hi all! I think, it's the

Re: [RFC] Enable nxstack by default

2011-10-18 Thread Garrett Cooper
On Tue, 18 Oct 2011, Arnaud Lacombe wrote: Hi, On Tue, Oct 18, 2011 at 5:07 AM, Kostik Belousov wrote: On Mon, Oct 17, 2011 at 09:30:56PM +0200, Oliver Pinter wrote: Hi all! I think, it's the time to enable the nxstack feature. Any comments, pros, cons? I dragged the change long enough fo

Re: [RFC] Enable nxstack by default

2011-10-18 Thread Arnaud Lacombe
Hi, On Tue, Oct 18, 2011 at 5:07 AM, Kostik Belousov wrote: > On Mon, Oct 17, 2011 at 09:30:56PM +0200, Oliver Pinter wrote: >> Hi all! >> >> I think, it's the time to enable the nxstack feature. Any comments, >> pros, cons? > > I dragged the change long enough for it to miss the 9.0. > After the

Re: [RFC] Enable nxstack by default

2011-10-18 Thread Oliver Pinter
Looks good to me. On 10/18/11, Kostik Belousov wrote: > On Mon, Oct 17, 2011 at 09:30:56PM +0200, Oliver Pinter wrote: >> Hi all! >> >> I think, it's the time to enable the nxstack feature. Any comments, >> pros, cons? > > I dragged the change long enough for it to miss the 9.0. > After the 9.0 i

Re: [RFC] Enable nxstack by default

2011-10-18 Thread Kostik Belousov
On Mon, Oct 17, 2011 at 09:30:56PM +0200, Oliver Pinter wrote: > Hi all! > > I think, it's the time to enable the nxstack feature. Any comments, > pros, cons? I dragged the change long enough for it to miss the 9.0. After the 9.0 is released, I will flip the switch with the following change. dif

[RFC] Enable nxstack by default

2011-10-17 Thread Oliver Pinter
Hi all! I think, it's the time to enable the nxstack feature. Any comments, pros, cons? From 2641987c35b025fa92adba402535a71aa1a4f7ce Mon Sep 17 00:00:00 2001 From: Oliver Pinter Date: Mon, 17 Oct 2011 21:14:58 +0200 Subject: [PATCH] enable nxstack by default Signed-off-by: Oliver Pinter diff