Files
ports/Mk/Features/zeroregs.mk
Alexander Leidinger 7a489e95c5 Mk/Features: Add features for fortify, zeroregs and stack autoinit.
Those 3 features for ports go along with the cooresponding features from
the basesystem (some only availabe in -current).

The options you can put into make.conf for the ports collections are:

WITH_FORTIFY=yes
    This enables mitigations of common memory safety issues, such as buffer
    overflows, by adding checks to functions like memcpy, strcpy, sprintf,
    and others when the compiler can determine the size of the destination
    buffer at compile time.

WITH_STACK_AUTOINIT=yes
    This enables a compiler specific option to automatically initialize
    local (automatic) variables to prevent the use of uninitialized memory.

WITH_ZEROREGS=yes
    Zero call-used registers at function return to increase program
    security by either mitigating Return-Oriented Programming (ROP)
    attacks or preventing information leakage through registers.
    This depends upon support from the compiler for a given architecture.
    This is disabled for python ports, currently there are issues.

Approved by:	portmgr (mat)
PR:		284270
2025-05-24 20:21:13 +02:00

29 lines
981 B
Makefile

# Zero call-used registers at function return to increase program
# security by either mitigating Return-Oriented Programming (ROP)
# attacks or preventing information leakage through registers.
# This depends upon support from the compiler for a given architecture.
#
# Variables that can be used:
#
# WITH_ZEROREGS Enable for all ports.
# WITH_ZEROREGS_PORTS Enable for specified category/port-name
# ZEROREGS_TYPE See
# https://gcc.gnu.org/onlinedocs/gcc/Common-Function-Attributes.html#index-zero_005fcall_005fused_005fregs-function-attribute
# for options
# Default: used
#
.if !defined(_ZEROREGS_MK_INCLUDED)
_ZEROREGS_MK_INCLUDED= yes
ZEROREGS_Include_MAINTAINER= netchild@FreeBSD.org
ZEROREGS_TYPE?= used
#. if !defined(ZEROREGS_UNSAFE) && !empty(${ARCH:Mriscv*}) && \
# !empty(${ARCH:Mpower*}) && !empty(${ARCH:Marmv7*})
CFLAGS+= -fzero-call-used-regs=${ZEROREGS_TYPE}
CXXFLAGS+= -fzero-call-used-regs=${ZEROREGS_TYPE}
#. endif
.endif