From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from sender4-op-o15.zoho.com (sender4-op-o15.zoho.com [136.143.188.15]) by sourceware.org (Postfix) with ESMTPS id AC60B3857807 for ; Tue, 25 Aug 2020 14:37:06 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.3.2 sourceware.org AC60B3857807 Authentication-Results: sourceware.org; dmarc=none (p=none dis=none) header.from=linuxandria.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=admin@linuxandria.com ARC-Seal: i=1; a=rsa-sha256; t=1598366222; cv=none; d=zohomail.com; s=zohoarc; b=h+7Qd8Y9RyvQyyYbtVxNOPkIbvZxAOkrLO+2krqal+YJdnoUceKv3npbqymCfmORpyZYQwJnKazOQn2ZVlpVH3eAVACSsFeZ/i1rbfGeQgdhpSmohKgreqM7yWpd4Zl09/8iDyct/+DBm1KlMVRR7J8zFUbp0PLUFyUQE8ZKIDA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1598366222; h=Content-Type:Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:MIME-Version:Message-ID:References:Subject:To; bh=msTv5XHMnf27FASXk/ZAWlQfP0eqQIGgKBGne+D3SgQ=; b=MyRAoZ7cdDDVq/lWKoordG2qU4DOMdhbOVPVFVMk2T35HIOiZAhzMWTpy358uXiEYjThKNtVKeOHQ506Ss1X+N7EHiHhvfhnrS7ZhnrDF4kRmi+jDstDiIkCjWHlPHZlZjRTV10kyeibiOcZRMOux5Q3YQLle2VuxBPCUjFqLaU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=linuxandria.com; spf=pass smtp.mailfrom=admin@linuxandria.com; dmarc=pass header.from= header.from= DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=linuxandria.com; h=from:to:cc:references:in-reply-to:subject:date:message-id:mime-version:content-type; b=izTwgwhd+KxAXXx0OYRhNORv9G6yfs0G+a9lj8DEzmMWj3eEUKbHNThRVAgy31wwhstfQuUsKtWG EUMtxdh7/slLE+pVwh9bLaM+MLcuKqZ7aYMV6WT3BrF/z3lZiAQLmuUjUZgTi9kviiRQiTJo56yT CFq8btNq6EnRF++WOGk= DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; t=1598366222; s=default; d=linuxandria.com; i=admin@linuxandria.com; h=From:To:Cc:References:In-Reply-To:Subject:Date:Message-ID:MIME-Version:Content-Type:Content-Transfer-Encoding; bh=msTv5XHMnf27FASXk/ZAWlQfP0eqQIGgKBGne+D3SgQ=; b=FXoDPkfb7hN49fSUfndZr+gBMANT+a9rMzjnG74Tm8o7g6Ii60ddH5RU7mPwBcBW xOa6JopzDq9CK8fjbEiHQZMQ/+jKNmcnZDYHMKF+05jKgk46GkP8b8r4/dsk1O+02yc 3gYYkZvhvvqpSMsSaCnetzYTPO9WEPaF8KL/QsIs= Received: from DESKTOP43BU6QD (168.91.2.9 [168.91.2.9]) by mx.zohomail.com with SMTPS id 1598366218814660.2083361373586; Tue, 25 Aug 2020 07:36:58 -0700 (PDT) From: "Alexandria Cortez" To: "'Eliot Moss'" Cc: References: <4AA035EB-1325-4C1B-B399-28FC9176F203@roc.cs.umass.edu> In-Reply-To: <4AA035EB-1325-4C1B-B399-28FC9176F203@roc.cs.umass.edu> Subject: RE: Mandatory ASLR breaks Cygwin - Windows 10 Date: Tue, 25 Aug 2020 10:36:55 -0400 Message-ID: <006c01d67aed$2f7f0660$8e7d1320$@linuxandria.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Mailer: Microsoft Outlook 16.0 Thread-Index: AQKHdN2I7RjeEs9XHVIuOgXE8fUDuQI8fs8Gp9UMWRA= Content-Language: en-us X-ZohoMailClient: External X-Spam-Status: No, score=0.3 required=5.0 tests=BAYES_20, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, KAM_NUMSUBJECT, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H4, RCVD_IN_MSPIKE_WL, SPF_HELO_NONE, SPF_PASS, TXREP autolearn=no autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on server2.sourceware.org X-BeenThere: cygwin@cygwin.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: General Cygwin discussions and problem reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 25 Aug 2020 14:37:09 -0000 That's unfortunate.=20 Is there any plans to implement a workaround in the future? Seeing as = Cygwin is only one of two programs I've noticed that are broken with it = on, it would be nice to be able to have it on from a security = perspective. -----Original Message----- From: Eliot Moss =20 Sent: Tuesday, August 25, 2020 10:35 AM To: Alexandria Cortez Cc: cygwin@cygwin.com Subject: Re: Mandatory ASLR breaks Cygwin - Windows 10 It=E2=80=99s intentional; too long to explain in detail on phone, but = fork requires each dll to load in the child at the same address as in = the parent, and ASLR interferes with achieving that. Sent from my iPhone > On Aug 25, 2020, at 10:17 AM, Alexandria Cortez = wrote: >=20 > =EF=BB=BFI was experimenting with security settings this morning on = windows, and > after changing Mandatory ASLR (Windows Security -> App and Browser = Control > -> Exploit Protection) to default on, no Cygwin programs that rely on = the > Cygwin dll would start, stating that a resource was temporarily = unavailable > and could not fork. Rebasell, bash, you name it crashed and would not = start. > After some investigation, turning off that setting allows Cygwin to = work. >=20 >=20 >=20 > Now the next question: why does this not work? Is this intended = behavior or > a bug? Having that setting turned on seems like a good idea from a = security > standpoint, and who knows it may eventually become default. >=20 >=20 >=20 > Regards, >=20 > Alexandria C. >=20 > > -- > Problem reports: https://cygwin.com/problems.html > FAQ: https://cygwin.com/faq/ > Documentation: https://cygwin.com/docs.html > Unsubscribe info: https://cygwin.com/ml/#unsubscribe-simple