security(7): fix copy/paste error and correct aslr oids

Submitted by:	Mina Galić <me_igalic.co>
Differential Revision:	https://reviews.freebsd.org/D27408
This commit is contained in:
Yuri Pankov 2020-11-29 16:29:40 +00:00
parent e0870cd468
commit c5426ce3a6

View File

@ -28,7 +28,7 @@
.\"
.\" $FreeBSD$
.\"
.Dd June 11, 2020
.Dd November 28, 2020
.Dt SECURITY 7
.Os
.Sh NAME
@ -1061,7 +1061,7 @@ position-independent (PIE) 32bit binaries.
.It Dv kern.elf32.aslr.honor_sbrk
Makes ASLR less aggressive and more compatible with old binaries
relying on the sbrk area.
.It Dv kern.elf32.aslr.aslr_stack_gap
.It Dv kern.elf32.aslr.stack_gap
If ASLR is enabled for a binary, a non-zero value creates a randomized
stack gap between strings and the end of the aux vector.
The value is the maximum percentage of main stack to waste on the gap.
@ -1072,7 +1072,7 @@ Cannot be greater than 50, i.e., at most half of the stack.
64bit PIE binaries ASLR control.
.It Dv kern.elf64.aslr.honor_sbrk
64bit binaries ASLR sbrk compatibility control.
.It Dv kern.elf32.aslr.aslr_stack_gap
.It Dv kern.elf64.aslr.stack_gap
Controls stack gap for 64bit binaries.
.It Dv kern.elf32.nxstack
Enables non-executable stack for 32bit processes.