Received: by 10.223.185.116 with SMTP id b49csp5446815wrg; Tue, 27 Feb 2018 13:32:57 -0800 (PST) X-Google-Smtp-Source: AH8x2271vF6ewfHMOALg0BANJQKfiknKPeDZJrtpqgPUrXXoZFPX2itYZBWMCdVk5haAlETpdsVV X-Received: by 10.98.8.219 with SMTP id 88mr15445582pfi.4.1519767177570; Tue, 27 Feb 2018 13:32:57 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1519767177; cv=none; d=google.com; s=arc-20160816; b=xfHW3xHqP9/WE7NweEW9Sft0mcJShW39o6qCvRcrkjJwrBBIDII5kNB+IKueEhWRNH hC4ZxrTzOFU/GeFoWE1vaBYX9Sjyj2M6mfONcoKb795SXC6yGLmgmXuhJACCuR+zpE0C 2lJ8i/L/NOyFNb5DeJy57PTIimhdR8xDIqeCwrzhFotyC+dGnp0jQXMsRZc0TEWF3522 B1jsshZjcaBCFgPEjhsXJhFxeUMGMfrIlH7ZfdNdL2A8zmHA15759Vo7qvYMSA0yymRh 28lDolYRhbFKOKHHot9RMoNJPNTolkt5MqQsSb3+fhEHw6cMwDuHbyXRjnA7E+sevQhH Vc9Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-language :content-transfer-encoding:in-reply-to:mime-version:user-agent:date :message-id:from:references:cc:to:subject:dkim-signature :arc-authentication-results; bh=C6DUV3Xur5W/2Gy9pZsGtZ8LDjmfQy+Cn+R1468izEo=; b=CSgb3VtVQhDN34goJczR6jyMY+/vr8kvuxeODnsm9FoXZK7iVENGQ7qCgDIgFcawNn IKUXDF0lOz8LYnzpAmzzTqZEU8/tA16lxMKWMxbqTTAfmvG0TKdHRz140l4liy3ghWkf 8SxMibkSVeOJ0jERNTZHePVY2rY+ltUR1NPQ+0Bqe2mjDyizrURv07nANRvN9wCFACwa v8qms1MJFWVTXqWCT+wCzwe9PUlGDSGPWyA265Z6t0xzXRSWsoWb7d7d1LiTN89Z8g5i ITC5kx2wZfVQmw4996z3hQ3T5MBW+0hTuuf8olge1gku0gZpdfj1uDA2fjmLvNMu4A2i eQ8g== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=O95p1lcn; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id z80si83629pff.42.2018.02.27.13.32.43; Tue, 27 Feb 2018 13:32:57 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=O95p1lcn; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751722AbeB0Vbo (ORCPT + 99 others); Tue, 27 Feb 2018 16:31:44 -0500 Received: from mail-wr0-f179.google.com ([209.85.128.179]:45233 "EHLO mail-wr0-f179.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751139AbeB0Vbn (ORCPT ); Tue, 27 Feb 2018 16:31:43 -0500 Received: by mail-wr0-f179.google.com with SMTP id p104so253127wrc.12 for ; Tue, 27 Feb 2018 13:31:42 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:cc:references:from:message-id:date:user-agent :mime-version:in-reply-to:content-transfer-encoding:content-language; bh=C6DUV3Xur5W/2Gy9pZsGtZ8LDjmfQy+Cn+R1468izEo=; b=O95p1lcnRwZHtVhjCuQiptZhP3/UfXwaZPzRW5kc+rosqx53YKDWpINln6VbzQc5Wk 8oICO53EU31Ubo0xjLva2K9u8rvlI7Frj9VUUeFP14IJkFlHmIEPgY+PDPZtHcFOxdOD 5sy9+JoHmIv02HY69OZo3T4TDe53zygZ4G/2JJbk3+1BD9Ylx7DT4BTQH8EKxMFXdpWd e7qExF0FI09ft7Ah8qC/TjfuM/f0hsOJ38P1JeKy7SZOjCMEaVBls1PQytGBbf/prGHj Slx8AGjRPVM5u0uB1p8trmscGMS+AJ5CGp9wN5wfHEcAaSOMsS1rn25scfS7n4j2gF4S rNIA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding :content-language; bh=C6DUV3Xur5W/2Gy9pZsGtZ8LDjmfQy+Cn+R1468izEo=; b=D5WcMXeLYyeLC3fHw9Xv/XwaCZxM2KGV0mctBxYx3950XC5vG6JGooLcyTEQ5F0GQT mHZ+XE0S7zrlc18o4QxPhBJONLAxACHtsQ8iF6smYVISlndJoIBLjVppURbZ3fTL5Tpf L3UCaRoNaAkTYlEVDdP6gwrRVLuxbNdmRpxHbfT18odPuWcJUTNigabkedXgCkRNyl6T I7CnqWNcoGg0BZk7mhKvZd3kjHzuxmpHPO4y3guft2B8aLLguViH2DVKfgXmbY5VQvIA WEmJVoIJ3i9eeHx1oBOyZeiDOeTcF9tN6pbw0U/6SO2V2fq+8QqKEBolq8m7tY6fyFQ9 Loqg== X-Gm-Message-State: APf1xPCEOu9jVx7ukfzMgDfy6NmN1YUu78mrjv8VE4EgERL/U0yjsvRK aD3dRIC82hQ/stdvfDXOym4= X-Received: by 10.223.177.138 with SMTP id q10mr12861515wra.132.1519767101857; Tue, 27 Feb 2018 13:31:41 -0800 (PST) Received: from [192.168.0.14] (host238-230-dynamic.54-79-r.retail.telecomitalia.it. [79.54.230.238]) by smtp.gmail.com with ESMTPSA id h50sm117457wrf.65.2018.02.27.13.31.39 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 27 Feb 2018 13:31:41 -0800 (PST) Subject: Re: [RFC PATCH] Randomization of address chosen by mmap. To: Kees Cook , Ilya Smith Cc: Andrew Morton , Dan Williams , Michal Hocko , "Kirill A. Shutemov" , Jan Kara , Jerome Glisse , Hugh Dickins , Matthew Wilcox , Helge Deller , Andrea Arcangeli , Oleg Nesterov , Linux-MM , LKML , Kernel Hardening References: <20180227131338.3699-1-blackzert@gmail.com> From: lazytyped Message-ID: <089e9c52-f623-085a-4d8b-d91cfc6a3608@gmail.com> Date: Tue, 27 Feb 2018 22:31:38 +0100 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:52.0) Gecko/20100101 Thunderbird/52.6.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit Content-Language: en-US Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 2/27/18 9:52 PM, Kees Cook wrote: > I'd like more details on the threat model here; if it's just a matter > of .so loading order, I wonder if load order randomization would get a > comparable level of uncertainty without the memory fragmentation, This also seems to assume that leaking the address of one single library isn't enough to mount a ROP attack to either gain enough privileges or generate a primitive that can leak further information. Is this really the case? Do you have some further data around this?        -  twiz