4 ms·
Thanks for the info. I'm not particularly familiar with common JIT applications, but I suspect that this use-case is actually more niche than may think. The pr
by Nyan 6y ago
Thanks for the info. I'm not particularly familiar with common JIT applications, but I suspect that this use-case is actually more niche than may think.
The problem is that the example presented requires a memory page with write + execute permissions (at the same time). I suspect many JITs don't do this for security reasons (and to deal with OSes which don't allow it), as it may make it easier for an attacker to gain arbitrary code execution.
It's likely that many JITs toggle between write and execute permissions, rather than have both enabled at the same time. Whilst this reduces attack surface, changing permissions on allocated memory requires syscalls, which are quite expensive in terms of performance.
The scenario presented in the article avoids the impact of syscalls, to maximize performance, leaving only the impact caused by the processor itself. If a JIT isn't overly concerned with this type of security, using write+execute memory could be a way to avoid syscall overhead. On the other hand, if a JIT does toggle permissions, the syscall overhead is likely much more significant than overheads caused by the processor (although the techniques shown might still help depending on how the JIT engine works).
- vardump 6y agoYeah, the security implications are obvious, R+W+X should not be used with untrusted inputs. Not that I'd recommend this, but alternatively you could also map exact same memory twice, one with R+X and the other with R+W. The attacker would need to figure out the writable address. Unfortunately there are probably a lot of ways to accidentally leak this information to the attacker... There are still plenty of use cases where inputs can be trusted.
- deleted 6y ago[deleted]
- saagarjha 6y agoFor performance I think this scheme is fairly common for W^X JITs.
- cat199 6y ago> many JITs don't do this for security reasons would be nice, but historically it's more been: - all JITs do this - OpenBSD creates W^X - open source JITs and other OS's start to incorporate W^X - things are now either W^X compatible or haven't been ported to a W^X OS yet.
- Nyan 6y agoAh good point, thanks for the info!