tree c03b25ece303ac12c267953ee340b134ee55294d
parent 785bb12634b0d2fd39b1e34609bc50366443b67e
author David Benjamin <davidben@google.com> 1670516437 -0500
committer Boringssl LUCI CQ <boringssl-scoped@luci-project-accounts.iam.gserviceaccount.com> 1670552042 +0000

Add a tool to check whether a binary has an executable stack

Plan is:

1. This CL

2. Update the CI/CQ recipe to be able to run this

3. Update the CI/CQ config to enable this on ELF platforms

4. Do not land, but patch out the .note.GNU-stack annotations and
   -Wa,--noexecstack and confirm CI/CQ fails. Based on manual testing
   and https://crbug.com/boringssl/292#c4, I anticipate we'll only have
   coverage on x86 and x86_64 Linux. Currently, our only Arm Linux
   builders are Android, which use the LLVM linker. The LLVM linker
   doesn't have this design flaw, so it doesn't need .note.GNU-stack in
   the first place. It also sounds like GNU ld will make this moot in a
   future release.

5. Remove -Wa,--noexecstack from crypto/CMakeLists.txt and confirm CI/CQ
   still passes.

Other than generally wanting to test things, the immediate motivation is
https://boringssl-review.googlesource.com/c/boringssl/+/55626/1/crypto/perlasm/arm-xlate.pl#b246

Bug: 292
Change-Id: Id1c049bfc2b4e8b7e2c8c32ea6456733a588dfe1
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/55645
Auto-Submit: David Benjamin <davidben@google.com>
Commit-Queue: Bob Beck <bbe@google.com>
Reviewed-by: Bob Beck <bbe@google.com>
