Expand description
Kernel Address Space Layout Randomization (KASLR).
Generates per-boot random offsets for:
- Userspace mmap base address
- Userspace stack base address
- ELF PIE loading base address
Offsets are generated once at boot from the entropy pool and remain constant for the lifetime of the boot. Each process receives its own randomized layout derived from these base offsets.
ยงEntropy requirements
init() calls entropy::fill_random() which blocks until the pool
has accumulated at least 64 bytes of entropy. On a live system with
keyboard/timer interrupts this takes < 1 ms. On QEMU without RDRAND
the pool seeds from TSC and accumulates quickly via IRQ noise.
Staticsยง
- INITIALIZED ๐
- Whether KASLR has been initialized.
- MMAP_
BASE_ ๐OFFSET - Randomized mmap base offset (added to MMAP_BASE).
- PIE_
BASE_ ๐OFFSET - Randomized PIE base offset (added to PIE_BASE_ADDR).
- STACK_
BASE_ ๐OFFSET - Randomized user stack base offset (added to USER_STACK_BASE).
Functionsยง
- draw_
stack_ jitter - Draw a fresh per-image stack jitter: a page-aligned offset in
0..=255pages (0..~1 MiB). - init
- Initialize KASLR offsets from the entropy pool. Called once at boot.
- mmap_
base - Get the randomized mmap base address.
- pie_
base - Get the randomized PIE base address for ELF loading.
- stack_
base - Get the randomized user stack base address.
- stack_
base_ with_ jitter - Stack base for a specific process, adding its own jitter on top of the
boot-randomized base. Use with
draw_stack_jitter. - stack_
guard - Get the guard page address below the user stack.
- stack_
top - Get the randomized user stack top address.
- stack_
top_ for - Get the top of a stack of
pages4 KiB pages starting atbase.