How does the PAX implementation differ from what is being proposed here?
http://marc.info/?l=linux-kernel&m=117888696419153&w=2
Maybe the PAX team should chime in and save some people alot of work?
that PaX actually works? more seriously, the proper approach is what PaX does, that is, randomize the main executable around the (arch specific) normal executable base address, instead of as a regular mmap mapping.zakalwe wrote:How does the PAX implementation differ from what is being proposed here?
http://marc.info/?l=linux-kernel&m=117888696419153&w=2
i actually talked to a SuSE security guy many months ago and suggested to just take the PaX bits, instead of cooking up their own, but to no avail apparently. other than that, i can't send email to lkml since last june or so (some spam filtering stuff i think, but both mail admins ignored my requests to resolve the problem), nor does Linus take anonymous contributions anymore.Maybe the PAX team should chime in and save some people alot of work?