On Mon, Oct 06, 2008 at 09:26:41PM +0200, Andi Kleen wrote:Well, my ultimate intention was to put this into the stack protector guard value, so I did want something as strong as the ASLR. If I understand, you're suggesting that ASLR doesn't need to be strong, and that there should be something besides get_random* used to produce these values? If that's true, that has nothing to do with the patch I've suggested (i.e. we have an immediate need and I'm solving it using the current available solutions.) (Additionally, I think ASLR should be as strong as possible.) If instead, you're saying that the use of urandom has generally caused a drain on entropy, and ASLR is suffering, then does it matter that a few more bytes are used for the stack guard? I'm just not clear what direction you're trying to aim my patch. :) I'd really love to see this solved. My goal is to get a mainline glibc patch for a low-cost randomized stack guard value. Ulrich has a set of requirements, and it sounds like there's a growing new set of requirements from the kernel folks. What's needed to sort this out? -Kees -- Kees Cook Ubuntu Security Team --
| Greg Kroah-Hartman | [PATCH 006/196] Chinese: add translation of oops-tracing.txt |
| Andrew Morton | Re: -mm merge plans for 2.6.23 -- sys_fallocate |
| Eric W. Biederman | [PATCH] nfs lockd reclaimer: Convert to kthread API |
| James Bottomley | Re: Integration of SCST in the mainstream Linux kernel |
git: | |
| David Miller | [GIT]: Networking |
| Gerrit Renker | [PATCH 03/37] dccp: List management for new feature negotiation |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
