Bug 208580

Summary: [EXP-RUN] ASLR check
Product: Ports & Packages Reporter: Konstantin Belousov <kib>
Component: Ports FrameworkAssignee: Konstantin Belousov <kib>
Status: In Progress ---    
Severity: Affects Only Me CC: bdrewery, emaste, op, portmgr, shawn.webb, tablosazi.farahan
Priority: ---    
Version: Latest   
Hardware: Any   
OS: Any   
Attachments:
Description Flags
aslr.8.patch (against HEAD r297617)
none
aslr.9.patch
none
sbcl memory mappings none

Description Konstantin Belousov freebsd_committer 2016-04-06 14:31:54 UTC
Created attachment 169039 [details]
aslr.8.patch (against HEAD r297617)

This is a request to perform exp-run for the ASLR patch.  As I understand, all ports build nodes run amd64 kernel.  The run is requested both for amd64 and i386 builds (on amd64 host).

No sysctl or tunables frobbing is required, the patch has everything set up for max aggressive level.
Comment 1 Antoine Brodin freebsd_committer 2016-04-06 18:06:42 UTC
There are lots of those errors,  before actual package building starts:

ELF interpreter /libexec/ld-elf.so.1 not found, error 22
Abort trap
ELF interpreter /libexec/ld-elf.so.1 not found, error 22
Abort trap

And I believe package23 just crashed,  need to check with clusteradm.
Comment 2 Konstantin Belousov freebsd_committer 2016-04-07 10:43:55 UTC
Created attachment 169071 [details]
aslr.9.patch

The original issue was manifested by the 'interpreter' messages.  The recursion on the vnode lock is the bug in existing code of ELF image activator when broken interpeter is on tmpfs. I fixed that as well, but hopefully neither of these two problems would reappear.

Some ports building and 32bit pypy build were successfull.
Comment 3 Antoine Brodin freebsd_committer 2016-04-09 18:22:38 UTC
Exp-run results for 10.1 amd64 jail:

http://package22.nyi.freebsd.org/build.html?mastername=101amd64-default-PR208580&build=2016-04-08_13h44m49s

New failures:

+ {"origin"=>"editors/emacs", "pkgname"=>"emacs24-24.5_3,3", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"editors/emacs-devel", "pkgname"=>"emacs-devel-25.0.92_1,2", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"editors/emacs-nox11", "pkgname"=>"emacs-nox11-24.5_3,3", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"java/classpath", "pkgname"=>"classpath-0.99_1", "phase"=>"configure", "errortype"=>"configure_error"}
+ {"origin"=>"java/openjdk6", "pkgname"=>"openjdk6-b38,1", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"java/openjdk6-jre", "pkgname"=>"openjdk6-jre-b38,1", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"java/openjdk7", "pkgname"=>"openjdk-7.95.00,1", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"java/openjdk7-jre", "pkgname"=>"openjdk-jre-7.95.00,1", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"lang/ecl", "pkgname"=>"ecl-15.3.7_1", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"lang/go14", "pkgname"=>"go14-1.4.3", "phase"=>"build", "errortype"=>"???"}
+ {"origin"=>"lang/rust", "pkgname"=>"rust-1.7.0", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"lang/rust-nightly", "pkgname"=>"rust-nightly-1.9.0.20160318", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"lang/sbcl", "pkgname"=>"sbcl-1.3.1,1", "phase"=>"build", "errortype"=>"termios"}
+ {"origin"=>"print/pdftk", "pkgname"=>"pdftk-2.02_3", "phase"=>"build", "errortype"=>"missing_header"}

Failure logs:

http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/emacs24-24.5_3,3.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/emacs-devel-25.0.92_1,2.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/emacs-nox11-24.5_3,3.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/classpath-0.99_1.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/openjdk6-b38,1.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/openjdk6-jre-b38,1.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/openjdk-7.95.00,1.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/openjdk-jre-7.95.00,1.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/ecl-15.3.7_1.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/go14-1.4.3.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/rust-1.7.0.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/rust-nightly-1.9.0.20160318.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/sbcl-1.3.1,1.log
http://package22.nyi.freebsd.org/data/101amd64-default-PR208580/2016-04-08_13h44m49s/logs/errors/pdftk-2.02_3.log
Comment 4 Antoine Brodin freebsd_committer 2016-04-09 18:25:26 UTC
Exp-run results for 10.1 i386 jail:

http://package23.nyi.freebsd.org/build.html?mastername=101i386-default-PR208580&build=2016-04-08_13h04m47s

New failures:

+ {"origin"=>"editors/emacs", "pkgname"=>"emacs24-24.5_3,3", "phase"=>"build", "errortype"=>"clang"}
+ {"origin"=>"editors/emacs-nox11", "pkgname"=>"emacs-nox11-24.5_3,3", "phase"=>"build", "errortype"=>"clang"}
+ {"origin"=>"java/classpath", "pkgname"=>"classpath-0.99_1", "phase"=>"configure/runaway", "errortype"=>"runaway_process"}
+ {"origin"=>"java/openjdk6", "pkgname"=>"openjdk6-b38,1", "phase"=>"build/runaway", "errortype"=>"runaway_process"}
+ {"origin"=>"java/openjdk6-jre", "pkgname"=>"openjdk6-jre-b38,1", "phase"=>"build/runaway", "errortype"=>"runaway_process"}
+ {"origin"=>"java/openjdk7", "pkgname"=>"openjdk-7.95.00,1", "phase"=>"build/runaway", "errortype"=>"runaway_process"}
+ {"origin"=>"java/openjdk7-jre", "pkgname"=>"openjdk-jre-7.95.00,1", "phase"=>"build/runaway", "errortype"=>"runaway_process"}
+ {"origin"=>"lang/gprolog", "pkgname"=>"gprolog-1.4.4", "phase"=>"build", "errortype"=>"???"}
+ {"origin"=>"lang/nhc98", "pkgname"=>"nhc98-1.22_1", "phase"=>"build", "errortype"=>"makefile"}
+ {"origin"=>"lang/rust", "pkgname"=>"rust-1.7.0", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"lang/sbcl", "pkgname"=>"sbcl-1.3.1,1", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"print/pdftk", "pkgname"=>"pdftk-2.02_3", "phase"=>"build", "errortype"=>"missing_header"}
+ {"origin"=>"sysutils/terraform", "pkgname"=>"hashicorp-terraform-0.6.3", "phase"=>"build", "errortype"=>"???"}

Failure logs:

http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/emacs24-24.5_3,3.log
http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/emacs-nox11-24.5_3,3.log
http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/classpath-0.99_1.log
http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/openjdk6-b38,1.log
http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/openjdk6-jre-b38,1.log
http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/openjdk-7.95.00,1.log
http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/openjdk-jre-7.95.00,1.log
http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/gprolog-1.4.4.log
http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/nhc98-1.22_1.log
http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/rust-1.7.0.log
http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/sbcl-1.3.1,1.log
http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/pdftk-2.02_3.log
http://package23.nyi.freebsd.org/data/101i386-default-PR208580/2016-04-08_13h04m47s/logs/errors/hashicorp-terraform-0.6.3.log
Comment 5 Antoine Brodin freebsd_committer 2016-04-09 18:29:34 UTC
Exp-run results in 9.3 amd64 jail:

http://package22.nyi.freebsd.org/build.html?mastername=93amd64-default-PR208580&build=2016-04-07_12h44m09s

Extra failures (compared to 10.1 amd64):

+ {"origin"=>"benchmarks/wrk", "pkgname"=>"wrk-4.0.1_3", "phase"=>"build", "errortype"=>"???"}
+ {"origin"=>"devel/efl", "pkgname"=>"efl-1.16.1_1", "phase"=>"build", "errortype"=>"???"}
+ {"origin"=>"lang/racket", "pkgname"=>"racket-6.2", "phase"=>"build", "errortype"=>"process_failed"}
+ {"origin"=>"lang/racket-minimal", "pkgname"=>"racket-minimal-6.2", "phase"=>"build", "errortype"=>"process_failed"}
+ {"origin"=>"lang/yap", "pkgname"=>"yap-6.2.2_1", "phase"=>"stage", "errortype"=>"install_error"}
+ {"origin"=>"print/tex-luatex", "pkgname"=>"tex-luatex-0.80.0_4", "phase"=>"package", "errortype"=>"PLIST"}

Failure logs:

http://package22.nyi.freebsd.org/data/93amd64-default-PR208580/2016-04-07_12h44m09s/logs/errors/wrk-4.0.1_3.log
http://package22.nyi.freebsd.org/data/93amd64-default-PR208580/2016-04-07_12h44m09s/logs/errors/efl-1.16.1_1.log
http://package22.nyi.freebsd.org/data/93amd64-default-PR208580/2016-04-07_12h44m09s/logs/errors/racket-6.2.log
http://package22.nyi.freebsd.org/data/93amd64-default-PR208580/2016-04-07_12h44m09s/logs/errors/racket-minimal-6.2.log
http://package22.nyi.freebsd.org/data/93amd64-default-PR208580/2016-04-07_12h44m09s/logs/errors/yap-6.2.2_1.log
http://package22.nyi.freebsd.org/data/93amd64-default-PR208580/2016-04-07_12h44m09s/logs/errors/tex-luatex-0.80.0_4.log
Comment 6 Antoine Brodin freebsd_committer 2016-04-09 18:32:20 UTC
Exp-run results in 9.3 i386 jail:

http://package23.nyi.freebsd.org/build.html?mastername=93i386-default-PR208580&build=2016-04-07_11h57m22s

Extra failures (compared to 10.1 i386 jail):

+ {"origin"=>"lang/ecl", "pkgname"=>"ecl-15.3.7_1", "phase"=>"build", "errortype"=>"coredump"}
+ {"origin"=>"lang/fsharp", "pkgname"=>"fsharp-3.1.2.5", "phase"=>"build", "errortype"=>"???"}

Failure logs:

http://package23.nyi.freebsd.org/data/93i386-default-PR208580/2016-04-07_11h57m22s/logs/errors/ecl-15.3.7_1.log
http://package23.nyi.freebsd.org/data/93i386-default-PR208580/2016-04-07_11h57m22s/logs/errors/fsharp-3.1.2.5.log
Comment 8 Shawn Webb 2016-04-12 19:19:01 UTC
sbcl compiles fine with HardenedBSD's ASLR, which is based off of PaX ASLR.
Comment 9 Antoine Brodin freebsd_committer 2016-04-23 09:17:44 UTC
Reassign the PR to portmgr@ when you need a 2nd run.
Comment 10 Ed Maste freebsd_committer 2016-06-21 15:56:03 UTC
> sbcl compiles fine with HardenedBSD's ASLR, which is based off of PaX ASLR.

Note that bugs have been filed against sbcl with PaX ASLR on Linux (possibly with more aggressive randomization?) so it appears there is a legitimate problem here. It may well fail intermittently (to build or pass tests).
Comment 11 Shawn Webb 2016-06-21 16:08:34 UTC
(In reply to Ed Maste from comment #10)

It's important to keep in mind that HardenedBSD's ASLR implementation is based off of PaX's documentation, not PaX's implementation. So HardenedBSD's ASLR implementation may not have the same issues as PaX's, especially given the differences in the virtual memory manager between the two operating systems.
Comment 12 Ed Maste freebsd_committer 2016-06-21 16:17:55 UTC
The point is that having it build successfully is not sufficient to claim that there are no possible issues. There is ample evidence that at least some versions of sbcl have trouble on at least some ASR and ASLR implementations.
Comment 13 Shawn Webb 2016-06-21 16:20:02 UTC
(In reply to Ed Maste from comment #12)

That could very well be true. sbcl might have runtime issues regardless of ASR or ASLR implementation.
Comment 14 Shawn Webb 2016-06-22 20:25:55 UTC
Created attachment 171693 [details]
sbcl memory mappings

The attached sbcl.txt shows sbcl working with HardenedBSD ASLR. I've verified that a simple "Hello World" lisp application runs. I ran sbcl without any arguments, then typed this into the interpreter: (print "hello world")

I have no real-world lisp applications to test sbcl with. But hello world is running perfectly wth HardenedBSD's ASLR implementation.
Comment 15 op 2016-06-22 23:27:23 UTC
Correction:

I can reproduce one build time error on our implementation too:

; SYS:SRC;CODE;RUN-PROGRAM.FASL.NEWEST written
; compilation finished in 0:00:00.374
T
* //doing warm init - load and dump phase
load: 2.51  cmd: sbcl 52277 [running] 52.18r 0.34u 1.92s 2% 694812k
make: Working in: /usr/ports/lang/sbcl
make[1]: Working in: /usr/ports/lang/sbcl
       67.30 real         0.00 user         0.00 sys
load: 2.48  cmd: sbcl 52277 [biowr] 83.36r 0.34u 3.13s 2% 995236k
make[1]: Working in: /usr/ports/lang/sbcl
make: Working in: /usr/ports/lang/sbcl
       98.49 real         0.00 user         0.00 sys
load: 2.48  cmd: sbcl 52277 [running] 84.90r 0.34u 3.18s 2% 1009024k
make: Working in: /usr/ports/lang/sbcl
      100.02 real         0.00 user         0.00 sys
make[1]: Working in: /usr/ports/lang/sbcl
load: 2.48  cmd: sbcl 52277 [biowr] 86.07r 0.34u 3.21s 2% 1018128k
make[1]: Working in: /usr/ports/lang/sbcl
make: Working in: /usr/ports/lang/sbcl
      101.19 real         0.00 user         0.00 sys
Segmentation fault (core dumped)
      107.96 real        14.86 user         4.08 sys
*** Error code 139

Stop.
make[1]: stopped in /usr/ports/lang/sbcl
*** Error code 1

Stop.
make: stopped in /usr/ports/lang/sbcl
op has logged on pts/4 from :0.
op@opn sbcl# make clean
===>  Cleaning for sbcl-1.3.1,1
op@opn sbcl# sysctl hardening.
hardening.procfs_harden: 1
hardening.log.ulog: 0
hardening.log.log: 1
hardening.version: 46
hardening.pax.hbsdcontrol.status: 1
hardening.pax.segvguard.max_crashes: 5
hardening.pax.segvguard.suspend_timeout: 600
hardening.pax.segvguard.expiry_timeout: 120
hardening.pax.segvguard.status: 1
hardening.pax.mprotect.status: 1
hardening.pax.pageexec.status: 1
hardening.pax.disallow_map32bit.status: 2
hardening.pax.aslr.status: 2

Here the last line means a fully enabled ASLR and enabled MAP_32BIT restriction. Other mitigations are opt-in, and not enabled by default.

And this is on:
op@opn sbcl# uname -a
FreeBSD opn 11.0-CURRENT-HBSD FreeBSD 11.0-CURRENT-HBSD #2 c1cada9(op/hardenedbsd/current/master): Wed May 18 17:11:47 CEST 2016     root@opn:/usr/obj/usr/src/sys/OP-HBSD  amd64

Which contains the same ASLR implementation, what the recent HardenedBSD HEAD has.
Comment 16 vali gholami 2017-12-17 07:12:26 UTC
MARKED AS SPAM