4 ms·
I guess I've never understood this. The W^X is a response to one of the classic Multics paper attacks, but doesn't actually work well in a world where JavaScr
by CharlesMerriam2 10y ago
I guess I've never understood this. The W^X is a response to one of the classic Multics paper attacks, but doesn't actually work well in a world where JavaScript, JVM byte code, and other non-native code is "sort-of executable". Why not put the effort into a great MMU so that every allocation is its own "page" for the purpose of triggering page faults on overruns?
- nickpsecurity 10y agoThere's already work on that sort of thing with crash-safe.org and Cambridge's CHERI. SVA-OS by Criswell et al to a degree. These kind of protections are for widespread use protecting legacy codebases they don't want to straight up fix or take performance hit of tools like Softbound+CETS. Incidentally, tradeoffs like that usually fail. ;)
- epistasis 10y agoWon't it still work well for all that code that isn't actively translated code, which is probably the vast majority of software that's run on OpenBSD? >Why not put the effort into a great MMU The people who are writing for OpenBSD can not "put their effort" into hardware changes to entire platforms. They can do something to improve their own OS, however.
- amelius 10y ago> Why not put the effort into a great MMU so that every allocation is its own "page" for the purpose of triggering page faults on overruns? Do you perhaps mean "every allocation is its own address space"? I guess that would require pointers that are double the size of regular pointers (the first half pointing to the address space, and the second half being an index into that space).
- khedoros 10y agoDon't most of those end up JIT'd into native binary code, anyhow? The compiler would output code into a W page, then flip it to an X page and jump in. If it's just an interpreter, then the "sort-of executable" is just data being read, and the page can stay write-only.
- stepvhen 10y agoIs this why JavaScript is deathly slow on my OpenBSD install and no the previous Arch Linux install?
- dchest 10y agoNo http://jandemooij.nl/blog/2015/12/29/wx-jit-code-enabled-in-firefox/ http://jandemooij.nl/blog/2015/12/29/wx-jit-code-enabled-in-...
- monocasa 10y ago> Why not put the effort into a great MMU so that every allocation is its own "page" for the purpose of triggering page faults on overruns? We used to have that, they're called segments.
- twic 10y agoOnly one processor did it like it really meant it: https://en.wikipedia.org/wiki/Intel_iAPX_432#Object-oriented_memory_and_capabilities https://en.wikipedia.org/wiki/Intel_iAPX_432#Object-oriented...
- nickpsecurity 10y agoLook up i960. Had most key parts with otherwise normal RISC.
- twic 10y agoIt seems to have been the i960MX and i960MC which had the funky object-oriented memory; they have long since been discontinued, and i can't find any documentation about them online, sadly. EDIT: There's a passing mention in a book [1] > The Intel i960 extended architecture processor used a tagged architecture with a bit on each memory word that marked the word as a "capability", not as an ordinary location for data or instructions. A capability controlled access to a variable-sized memory block or segment. The large number of possible tag values supported memory segments that ranged in size from 64 to 4 billion bytes, with a potential 2^256 different protection domains. [1] https://books.google.co.uk/books?id=O3VB-zspJo4C&pg=PA189#v=onepage&q&f=false https://books.google.co.uk/books?id=O3VB-zspJo4C&pg=PA189#v=...
- nickpsecurity 10y agoType i960 wikipedia into Google. It has a description plus a link to ISA datasheet in references section. About enough info to recreate it. EDIT: Now that I'm on a PC I've added the link here for you. Copy and paste of PDF's is a b on my mobile. ;) https://en.wikipedia.org/wiki/Intel_i960 https://en.wikipedia.org/wiki/Intel_i960 http://bitsavers.org/pdf/biin/BiiN_CPU_Architecture_Reference_Man_Jul88.pdf http://bitsavers.org/pdf/biin/BiiN_CPU_Architecture_Referenc...
- csirac2 10y agoFWIW Firefox manages to use W^X in their JIT (the experimental patch back in 2011 had a very interesting idea: one process w writing out to memory mapped RW, another process with the same mapped executable): http://jandemooij.nl/blog/2015/12/29/wx-jit-code-enabled-in-firefox/ http://jandemooij.nl/blog/2015/12/29/wx-jit-code-enabled-in-...