Skip to content

Making C Less Dangerous in the Linux kernel

2019 45 min linux.conf.au en-us YouTube

Kees Cook https://2019.linux.conf.au/schedule/presentation/178/ With the Linux kernel written in C, it comes with some worrisome baggage, "undefined" behaviors, and other weaknesses that lead to security flaws and vulnerable infrastructure. Some of these weaknesses related to the design of chipsets and how close C is to machine code, but others are less specific. This presentation will explore the areas where the kernel is changing the C standard, defining undefined behaviors, or otherwise reorganizing things to make C itself less of a hazard. Specifically this will cover removing (and enforcing the lack of) Variable Length Arrays in kernel code, forcing all stack variables to be initialized with a GCC plugin, performing implicit bounds checking with overloaded builtins, handling arithmetic overflows safely, and protecting forward (call) and reverse (return) indirect function calls with CFI under Clang. linux.conf.au is a conference about the Linux operating system, and all aspects of the thriving ecosystem of Free and Open Source Software that has grown up around it. Run since 1999, in a different Australian or New Zealand city each year, by a team of local volunteers, LCA invites more than 500 people to learn from the people who shape the future of Open Source. For more information on the conference see https://linux.conf.au/ #linux.conf.au #linux #foss #opensource

Chapters

  1. 0:00 Intro
  2. 0:41 Making C Less Dangerous in the Linux kernel
  3. 1:47 Kernel Self Protection Project
  4. 3:24 C as a fancy assembler: almost machine code
  5. 4:14 C as a fancy assembler: undefined behavior
  6. 5:49 Variable Length Arrays and alloca () are bad
  7. 8:02 Variable Length Arrays are slow
  8. 8:55 Variable Length Arrays: stop it
  9. 11:24 Switch case fall-through: new "statement"
  10. 12:22 Always-initialized local variables: just do it
  11. 15:21 Always-initialized local variables: switch gotcha
  12. 16:31 Arithmetic overflow detection: gcc?
  13. 18:35 Arithmetic overflow detection: Clang :
  14. 19:21 Bounds checking: explicit checking is slow
  15. 23:46 Instead of sprintf(): scnprintf()
  16. 26:06 Instead of memcpy: uhhh ... be ... careful?
  17. 26:57 Bounds checking: memory tagging :
  18. 29:59 Control Flow Integrity: indirect calls
  19. 30:56 CFI, forward edges: just call pointers
  20. 31:24 CFI, forward edges: enforce prototype :
  21. 31:54 CFI, backward edges: two stacks
  22. 32:28 CFI, backward edges: shadow call stack
  23. 32:59 CFI, backward edges: hardware support
  24. 33:46 Where is the Linux kernel now?
  25. 37:29 Challenges in Kernel Security Development
Channel
linux.conf.au
Tags
LinuxTalk
Views
125

More like this