security(7): fix copy/paste error and correct aslr oids

Submitted by:	Mina Galić <me_igalic.co>
Differential Revision:	https://reviews.freebsd.org/D27408
This commit is contained in:
Yuri Pankov 2020-11-29 16:29:40 +00:00
parent e0870cd468
commit c5426ce3a6
Notes: svn2git 2020-12-20 02:59:44 +00:00
svn path=/head/; revision=368157

View File

@ -28,7 +28,7 @@
.\" .\"
.\" $FreeBSD$ .\" $FreeBSD$
.\" .\"
.Dd June 11, 2020 .Dd November 28, 2020
.Dt SECURITY 7 .Dt SECURITY 7
.Os .Os
.Sh NAME .Sh NAME
@ -1061,7 +1061,7 @@ position-independent (PIE) 32bit binaries.
.It Dv kern.elf32.aslr.honor_sbrk .It Dv kern.elf32.aslr.honor_sbrk
Makes ASLR less aggressive and more compatible with old binaries Makes ASLR less aggressive and more compatible with old binaries
relying on the sbrk area. relying on the sbrk area.
.It Dv kern.elf32.aslr.aslr_stack_gap .It Dv kern.elf32.aslr.stack_gap
If ASLR is enabled for a binary, a non-zero value creates a randomized If ASLR is enabled for a binary, a non-zero value creates a randomized
stack gap between strings and the end of the aux vector. stack gap between strings and the end of the aux vector.
The value is the maximum percentage of main stack to waste on the gap. The value is the maximum percentage of main stack to waste on the gap.
@ -1072,7 +1072,7 @@ Cannot be greater than 50, i.e., at most half of the stack.
64bit PIE binaries ASLR control. 64bit PIE binaries ASLR control.
.It Dv kern.elf64.aslr.honor_sbrk .It Dv kern.elf64.aslr.honor_sbrk
64bit binaries ASLR sbrk compatibility control. 64bit binaries ASLR sbrk compatibility control.
.It Dv kern.elf32.aslr.aslr_stack_gap .It Dv kern.elf64.aslr.stack_gap
Controls stack gap for 64bit binaries. Controls stack gap for 64bit binaries.
.It Dv kern.elf32.nxstack .It Dv kern.elf32.nxstack
Enables non-executable stack for 32bit processes. Enables non-executable stack for 32bit processes.