• Kees Cook's avatar
    stackprotector: Introduce CONFIG_CC_STACKPROTECTOR_STRONG · 8779657d
    Kees Cook authored
    This changes the stack protector config option into a choice of
    "None", "Regular", and "Strong":
    
       CONFIG_CC_STACKPROTECTOR_NONE
       CONFIG_CC_STACKPROTECTOR_REGULAR
       CONFIG_CC_STACKPROTECTOR_STRONG
    
    "Regular" means the old CONFIG_CC_STACKPROTECTOR=y option.
    
    "Strong" is a new mode introduced by this patch. With "Strong" the
    kernel is built with -fstack-protector-strong (available in
    gcc 4.9 and later). This option increases the coverage of the stack
    protector without the heavy performance hit of -fstack-protector-all.
    
    For reference, the stack protector options available in gcc are:
    
    -fstack-protector-all:
      Adds the stack-canary saving prefix and stack-canary checking
      suffix to _all_ function entry and exit. Results in substantial
      use of stack space for saving the canary for deep stack users
      (e.g. historically xfs), and measurable (though shockingly still
      low) performance hit due to all the saving/checking. Really not
      suitable for sa...
    8779657d
Makefile 48.8 KB