Making C Less Dangerous in the Linux kernel
Kees Cook https://2019.linux.conf.au/schedule/presentation/178/ With the Linux kernel written in C, it comes with some worrisome baggage, "undefined" behaviors, and other weaknesses that lead to security flaws and vulnerable infrastructure. Some of these weaknesses related to the design of chipsets and how close C is to machine code, but others are less specific. This presentation will explore the areas where the kernel is changing the C standard, defining undefined behaviors, or otherwise reorganizing things to make C itself less of a hazard. Specifically this will cover removing (and enforcing the lack of) Variable Length Arrays in kernel code, forcing all stack variables to be initialized with a GCC plugin, performing implicit bounds checking with overloaded builtins, handling arithmetic overflows safely, and protecting forward (call) and reverse (return) indirect function calls with CFI under Clang. linux.conf.au is a conference about the Linux operating system, and all aspects of the thriving ecosystem of Free and Open Source Software that has grown up around it. Run since 1999, in a different Australian or New Zealand city each year, by a team of local volunteers, LCA invites more than 500 people to learn from the people who shape the future of Open Source. For more information on the conference see https://linux.conf.au/ #linux.conf.au #linux #foss #opensource
Chapters
- 0:00 Intro
- 0:41 Making C Less Dangerous in the Linux kernel
- 1:47 Kernel Self Protection Project
- 3:24 C as a fancy assembler: almost machine code
- 4:14 C as a fancy assembler: undefined behavior
- 5:49 Variable Length Arrays and alloca () are bad
- 8:02 Variable Length Arrays are slow
- 8:55 Variable Length Arrays: stop it
- 11:24 Switch case fall-through: new "statement"
- 12:22 Always-initialized local variables: just do it
- 15:21 Always-initialized local variables: switch gotcha
- 16:31 Arithmetic overflow detection: gcc?
- 18:35 Arithmetic overflow detection: Clang :
- 19:21 Bounds checking: explicit checking is slow
- 23:46 Instead of sprintf(): scnprintf()
- 26:06 Instead of memcpy: uhhh ... be ... careful?
- 26:57 Bounds checking: memory tagging :
- 29:59 Control Flow Integrity: indirect calls
- 30:56 CFI, forward edges: just call pointers
- 31:24 CFI, forward edges: enforce prototype :
- 31:54 CFI, backward edges: two stacks
- 32:28 CFI, backward edges: shadow call stack
- 32:59 CFI, backward edges: hardware support
- 33:46 Where is the Linux kernel now?
- 37:29 Challenges in Kernel Security Development
- Channel
- linux.conf.au
- Views
- 125