freebsd kernel with SKQ
Go to file
Konstantin Belousov ecc6c515ab Apply noexec mount option for mmap(PROT_EXEC).
Right now the noexec mount option disallows image activators to try
execve the files on the mount point.  Also, after r127187, noexec
also limits max_prot map entries permissions for mappings of files
from such mounts, but not the actual mapping permissions.

As result, the API behaviour is inconsistent.  The files from noexec
mount can be mapped with PROT_EXEC, but if mprotect(2) drops execution
permission, it cannot be re-enabled later.  Make this consistent
logically and aligned with behaviour of other systems, by disallowing
PROT_EXEC for mmap(2).

Note that this change only ensures aligned results from mmap(2) and
mprotect(2), it does not prevent actual code execution from files
coming from noexec mount.  Such files can always be read into
anonymous executable memory and executed from there.

Reported by:	shamaz.mazum@gmail.com
PR:	217062
Reviewed by:	alc
Sponsored by:	The FreeBSD Foundation
MFC after:	1 week
2017-02-19 20:51:04 +00:00
bin Use uintmax_t to print st_nlink. 2017-02-16 06:32:39 +00:00
cddl When patching USDT probes, use non-unique names for aliases of weak symbols. 2017-02-10 02:01:32 +00:00
contrib Import mandoc 1.4.1rc2 2017-02-19 17:46:37 +00:00
crypto Only notify blacklistd for successful logins in auth.c 2017-02-19 20:35:39 +00:00
etc improve PBKDF2 performance 2017-02-19 19:30:31 +00:00
gnu Use SRCTOP/OBJTOP and simplify output using :H instead of "../" for directory 2017-02-11 20:12:54 +00:00
include Import libucl snapshot 20170219 2017-02-19 17:31:53 +00:00
kerberos5 Conditionalize adding ${KRB5DIR}/lib/gssapi/krb5/gkrb5_err.et to ETSRCS 2017-01-02 19:03:01 +00:00
lib Publish fp[get][set]sticky() for ARMv6. 2017-02-17 13:49:46 +00:00
libexec Handle protected symbols in rtld. 2017-02-09 23:33:06 +00:00
release Fix the hardware.html build. 2017-02-16 22:29:37 +00:00
rescue Remove pc98 support completely. 2017-01-28 02:22:15 +00:00
sbin Make savecore(8) output nicer by specifying the maximum field width 2017-02-19 16:59:00 +00:00
secure Remove bdes(1) 2017-02-06 08:27:19 +00:00
share Document r313854 (kern.cam.ctl.iscsi.maxtags). 2017-02-19 19:46:47 +00:00
sys Apply noexec mount option for mmap(PROT_EXEC). 2017-02-19 20:51:04 +00:00
targets Remove pc98 support completely. 2017-01-28 02:22:15 +00:00
tests improve PBKDF2 performance 2017-02-19 19:30:31 +00:00
tools Update OLD_DIRS for various targets so that some of the branches of 2017-02-17 20:02:40 +00:00
usr.bin bsdgrep: document ignored option -u 2017-02-19 17:40:24 +00:00
usr.sbin Add 0-8 as shortcuts for jumping to menu items in the hardening menu. 2017-02-16 19:58:02 +00:00
.arcconfig callsign isn't required anymore 2016-09-29 06:19:45 +00:00
.arclint phabricator related changes: 2015-04-20 20:33:22 +00:00
COPYRIGHT Bump copyright year. 2016-12-31 12:41:42 +00:00
LOCKS
MAINTAINERS Remove myself from kern_timeout.c yeah! 2016-07-27 20:37:32 +00:00
Makefile Import mandoc 1.4.1rc2 2017-02-19 17:41:20 +00:00
Makefile.inc1 Include ${LOCALBASE}/bin in $PATH when running "make checkworld" 2017-02-18 21:47:32 +00:00
Makefile.libcompat Use cross-NM (XNM) in compat32 build 2017-01-27 03:43:18 +00:00
ObsoleteFiles.inc Add ObsoleteFiles entries for bdes(1) missed in r313329 2017-02-06 10:51:53 +00:00
README Vendor import of libpcap 1.8.1. 2017-02-12 07:04:44 +00:00
UPDATING Note EISA and MCA bus removal 2017-02-17 06:22:00 +00:00

This is the top level of the FreeBSD source directory.  This file
was last revised on:
$FreeBSD$

For copyright information, please see the file COPYRIGHT in this
directory (additional copyright information also exists for some
sources in this tree - please see the specific source directories for
more information).

The Makefile in this directory supports a number of targets for
building components (or all) of the FreeBSD source tree.  See build(7)
and http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/makeworld.html
for more information, including setting make(1) variables.

The `buildkernel` and `installkernel` targets build and install
the kernel and the modules (see below).  Please see the top of
the Makefile in this directory for more information on the
standard build targets and compile-time flags.

Building a kernel is a somewhat more involved process.  See build(7), config(8),
and http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/kernelconfig.html
for more information.

Note: If you want to build and install the kernel with the
`buildkernel` and `installkernel` targets, you might need to build
world before.  More information is available in the handbook.

The kernel configuration files reside in the sys/<arch>/conf
sub-directory.  GENERIC is the default configuration used in release builds.
NOTES contains entries and documentation for all possible
devices, not just those commonly used.


Source Roadmap:
---------------

bin		System/user commands.

cddl		Various commands and libraries under the Common Development
		and Distribution License.

contrib		Packages contributed by 3rd parties.

crypto		Cryptography stuff (see crypto/README).

etc		Template files for /etc.

gnu		Various commands and libraries under the GNU Public License.
		Please see gnu/COPYING* for more information.

include		System include files.

kerberos5	Kerberos5 (Heimdal) package.

lib		System libraries.

libexec		System daemons.

release		Release building Makefile & associated tools.

rescue		Build system for statically linked /rescue utilities.

sbin		System commands.

secure		Cryptographic libraries and commands.

share		Shared resources.

sys		Kernel sources.

tests		Regression tests which can be run by Kyua.  See tests/README
		for additional information.

tools		Utilities for regression testing and miscellaneous tasks.

usr.bin		User commands.

usr.sbin	System administration commands.


For information on synchronizing your source tree with one or more of
the FreeBSD Project's development branches, please see:

  http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/synching.html