Kernel support for control-flow enforcement
Kernel support for control-flow enforcement
Posted Jun 26, 2018 5:41 UTC (Tue) by Lionel_Debroux (subscriber, #30014)In reply to: Kernel support for control-flow enforcement by pabs
Parent article: Kernel support for control-flow enforcement
What's more, RAP is (much) more powerful than CET and doesn't require special, architecture-specific hardware support available on very few real-world processors at the time of this writing.
Likewise for PaX's KERNEXEC and MEMORY_UDEREF, which Intel and ARM eventually implemented years later as SMEP / PXN and SMAP / PAN . In PaX, these took advantage of PCID / INVPCID years before mainline integrated support for these to reduce the performance impact of KPTI.
Likewise for PaX's KERNEXEC and MEMORY_UDEREF, which Intel and ARM eventually implemented years later as SMEP / PXN and SMAP / PAN . In PaX, these took advantage of PCID / INVPCID years before mainline integrated support for these to reduce the performance impact of KPTI.
But hey, CET will probably be implemented, because it's *something* to raise the low baseline of Linux to a slightly higher level, for a minority of computers :)
An alternative version of the grsecurity.net link posted at the end of the article should be https://forums.grsecurity.net/viewtopic.php?f=7&t=4490 .