[tor-bugs] #10599 [Tor bundles/installation]: Investigate building TBB with SoftBound or AddressSanitizer (was: Investigate building TBB with SoftBound)

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu May 1 17:33:27 UTC 2014


#10599: Investigate building TBB with SoftBound or AddressSanitizer
------------------------------------------+--------------------------------
     Reporter:  mikeperry                 |      Owner:  erinn
         Type:  enhancement               |     Status:  new
     Priority:  major                     |  Milestone:
    Component:  Tor bundles/installation  |    Version:
   Resolution:                            |   Keywords:  gitian, tbb-
Actual Points:                            |  security
       Points:                            |  Parent ID:
------------------------------------------+--------------------------------

Comment (by mikeperry):

 It seems like most of the SoftBounds+CETS functionality has actually been
 folded into a GCC+CLang project called 'AddressSanitizer':
 https://code.google.com/p/address-sanitizer/wiki/AddressSanitizer

 GCC 4.8+ and CLang 3.1+ support this out of the box with
 -fsanitize=address. It may be a while before our cross-compilers pick this
 up, but we could build a special "TBB-Hardened" release for Linux-only, as
 an alpha perhaps?

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10599#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list