2022-04-27 09:35:20 +00:00
|
|
|
{ lib
|
|
|
|
, stdenv
|
|
|
|
, fetchFromGitHub
|
|
|
|
, python3
|
|
|
|
, runCommand
|
|
|
|
, makeWrapper
|
|
|
|
, stress-ng
|
|
|
|
}:
|
2020-04-24 23:36:52 +00:00
|
|
|
|
2023-07-15 17:15:38 +00:00
|
|
|
stdenv.mkDerivation (finalAttrs: {
|
2020-04-24 23:36:52 +00:00
|
|
|
pname = "graphene-hardened-malloc";
|
2023-10-09 19:29:22 +00:00
|
|
|
version = "12";
|
2020-04-24 23:36:52 +00:00
|
|
|
|
2022-01-07 04:07:37 +00:00
|
|
|
src = fetchFromGitHub {
|
|
|
|
owner = "GrapheneOS";
|
|
|
|
repo = "hardened_malloc";
|
2023-07-15 17:15:38 +00:00
|
|
|
rev = finalAttrs.version;
|
2023-10-09 19:29:22 +00:00
|
|
|
sha256 = "sha256-ujwzr4njNsf/VTyEq7zKHWxoivU3feavSTx+MLIj1ZM=";
|
2020-04-24 23:36:52 +00:00
|
|
|
};
|
|
|
|
|
2021-08-18 13:19:15 +00:00
|
|
|
doCheck = true;
|
2023-02-02 18:25:31 +00:00
|
|
|
nativeCheckInputs = [ python3 ];
|
2021-08-18 13:19:15 +00:00
|
|
|
# these tests cover use as a build-time-linked library
|
2023-07-15 17:15:38 +00:00
|
|
|
checkTarget = "test";
|
2021-08-18 13:19:15 +00:00
|
|
|
|
2020-04-24 23:36:52 +00:00
|
|
|
installPhase = ''
|
2021-08-18 13:19:15 +00:00
|
|
|
install -Dm444 -t $out/include include/*
|
2022-04-27 09:35:20 +00:00
|
|
|
install -Dm444 -t $out/lib out/libhardened_malloc.so
|
2020-04-24 23:36:52 +00:00
|
|
|
|
|
|
|
mkdir -p $out/bin
|
|
|
|
substitute preload.sh $out/bin/preload-hardened-malloc --replace "\$dir" $out/lib
|
|
|
|
chmod 0555 $out/bin/preload-hardened-malloc
|
|
|
|
'';
|
|
|
|
|
|
|
|
separateDebugInfo = true;
|
|
|
|
|
2021-08-18 13:19:15 +00:00
|
|
|
passthru = {
|
|
|
|
ld-preload-tests = stdenv.mkDerivation {
|
2023-07-15 17:15:38 +00:00
|
|
|
name = "${finalAttrs.pname}-ld-preload-tests";
|
|
|
|
inherit (finalAttrs) src;
|
2020-04-24 23:36:52 +00:00
|
|
|
|
2021-08-18 13:19:15 +00:00
|
|
|
nativeBuildInputs = [ makeWrapper ];
|
2020-04-24 23:36:52 +00:00
|
|
|
|
2021-08-18 13:19:15 +00:00
|
|
|
# reuse the projects tests to cover use with LD_PRELOAD. we have
|
|
|
|
# to convince the test programs to build as though they're naive
|
|
|
|
# standalone executables. this includes disabling tests for
|
|
|
|
# malloc_object_size, which doesn't make sense to use via LD_PRELOAD.
|
|
|
|
buildPhase = ''
|
2022-04-27 09:35:20 +00:00
|
|
|
pushd test
|
2021-08-18 13:19:15 +00:00
|
|
|
make LDLIBS= LDFLAGS=-Wl,--unresolved-symbols=ignore-all CXXFLAGS=-lstdc++
|
|
|
|
substituteInPlace test_smc.py \
|
|
|
|
--replace 'test_malloc_object_size' 'dont_test_malloc_object_size' \
|
|
|
|
--replace 'test_invalid_malloc_object_size' 'dont_test_invalid_malloc_object_size'
|
2022-04-27 09:35:20 +00:00
|
|
|
popd # test
|
2021-08-18 13:19:15 +00:00
|
|
|
'';
|
2020-04-24 23:36:52 +00:00
|
|
|
|
2021-08-18 13:19:15 +00:00
|
|
|
installPhase = ''
|
|
|
|
mkdir -p $out/test
|
2022-04-27 09:35:20 +00:00
|
|
|
cp -r test $out/test
|
2020-04-24 23:36:52 +00:00
|
|
|
|
2021-08-18 13:19:15 +00:00
|
|
|
mkdir -p $out/bin
|
|
|
|
makeWrapper ${python3.interpreter} $out/bin/run-tests \
|
2022-04-27 09:35:20 +00:00
|
|
|
--add-flags "-I -m unittest discover --start-directory $out/test"
|
2021-08-18 13:19:15 +00:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
tests = {
|
2023-07-15 17:15:38 +00:00
|
|
|
ld-preload = runCommand "ld-preload-test-run" { } ''
|
|
|
|
${finalAttrs.finalPackage}/bin/preload-hardened-malloc ${finalAttrs.passthru.ld-preload-tests}/bin/run-tests
|
2021-08-18 13:19:15 +00:00
|
|
|
touch $out
|
|
|
|
'';
|
|
|
|
# to compensate for the lack of tests of correct normal malloc operation
|
2023-07-15 17:15:38 +00:00
|
|
|
stress = runCommand "stress-test-run" { } ''
|
|
|
|
${finalAttrs.finalPackage}/bin/preload-hardened-malloc ${stress-ng}/bin/stress-ng \
|
2021-08-18 13:19:15 +00:00
|
|
|
--no-rand-seed \
|
|
|
|
--malloc 8 \
|
|
|
|
--malloc-ops 1000000 \
|
|
|
|
--verify
|
|
|
|
touch $out
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
};
|
2020-04-24 23:36:52 +00:00
|
|
|
|
2021-02-05 17:12:51 +00:00
|
|
|
meta = with lib; {
|
2020-04-24 23:36:52 +00:00
|
|
|
homepage = "https://github.com/GrapheneOS/hardened_malloc";
|
|
|
|
description = "Hardened allocator designed for modern systems";
|
2024-04-21 15:54:59 +00:00
|
|
|
mainProgram = "preload-hardened-malloc";
|
2020-04-24 23:36:52 +00:00
|
|
|
longDescription = ''
|
|
|
|
This is a security-focused general purpose memory allocator providing the malloc API
|
|
|
|
along with various extensions. It provides substantial hardening against heap
|
|
|
|
corruption vulnerabilities yet aims to provide decent overall performance.
|
|
|
|
'';
|
|
|
|
license = licenses.mit;
|
|
|
|
maintainers = with maintainers; [ ris ];
|
|
|
|
platforms = [ "x86_64-linux" "aarch64-linux" ];
|
|
|
|
};
|
2021-08-18 13:19:15 +00:00
|
|
|
})
|