nodejs / nodejs/node

Windows build: node.exe missing Control Flow Guard (CFG) and DYNAMICBASE mitigations

オープン
#64,212 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

主要言語
JavaScript
スター
122k
フォーク
37.3k
平均マージ
4日 2時間
マージ済み PR(30日)
283

説明

Version

24.16.0

Platform
error BA2008: 'node.exe' does not enable the control flow guard (CFG) mitigation.
To resolve this issue, pass /guard:cf on both the compiler and linker command lines. Binaries also require the /DYNAMICBASE linker option in order to enable CFG.
For VC projects use ItemDefinitionGroup - ClCompile - ControlFlowGuard property with 'Guard' value, link CFG property will be set automatically.
Subsystem

Windows11

What steps will reproduce the bug?

https://github.com/microsoft/binskim

BinSkim.exe analyze C:\path\to\node.exe --config binskim_config_no_pdb.xml --kind Fail

binskim_config_no_pdb.xml is:

<?xml version="1.0" encoding="utf-8"?>
<Properties>
  <Properties Key="BinaryParsers.Options">
    <Property Key="IgnorePdbLoadError" Value="True" Type="System.Boolean" />
    <Property Key="DisableTelemetry" Value="True" Type="System.Boolean" />
  </Properties>

  <!-- Disabled rules that need a PDB file -->
  <Properties Key="BA2002.DoNotIncorporateVulnerableDependencies.Options">
    <Property Key="RuleEnabled" Value="Disabled" Type="Driver.RuleEnabledState" />
  </Properties>
  <Properties Key="BA2006.BuildWithSecureTools.Options">
    <Property Key="RuleEnabled" Value="Disabled" Type="Driver.RuleEnabledState" />
  </Properties>
  <Properties Key="BA2007.EnableCriticalCompilerWarnings.Options">
    <Property Key="RuleEnabled" Value="Disabled" Type="Driver.RuleEnabledState" />
  </Properties>
  <Properties Key="BA2011.EnableStackProtection.Options">
    <Property Key="RuleEnabled" Value="Disabled" Type="Driver.RuleEnabledState" />
  </Properties>
  <Properties Key="BA2013.InitializeStackProtection.Options">
    <Property Key="RuleEnabled" Value="Disabled" Type="Driver.RuleEnabledState" />
  </Properties>
  <Properties Key="BA2014.DoNotDisableStackProtectionForFunctions.Options">
    <Property Key="RuleEnabled" Value="Disabled" Type="Driver.RuleEnabledState" />
  </Properties>
  <Properties Key="BA2024.EnableSpectreMitigations.Options">
    <Property Key="RuleEnabled" Value="Disabled" Type="Driver.RuleEnabledState" />
  </Properties>
  <Properties Key="BA2025.EnableShadowStack.Options">
    <Property Key="RuleEnabled" Value="Disabled" Type="Driver.RuleEnabledState" />
  </Properties>
  <Properties Key="BA2026.EnableMicrosoftCompilerSdlSwitch.Options">
    <Property Key="RuleEnabled" Value="Disabled" Type="Driver.RuleEnabledState" />
  </Properties>
  <Properties Key="BA2027.EnableSourceLink.Options">
    <Property Key="RuleEnabled" Value="Disabled" Type="Driver.RuleEnabledState" />
  </Properties>
</Properties>
How often does it reproduce? Is there a required condition?
What is the expected behavior? Why is that the expected behavior?

No exploit is found

What do you see instead?
Additional information

There was already prior work on this topic see (#42100)

PR #42126 was closed in favor of https://github.com/nodejs/node/pull/56605

However, #42126 also handled the missing /DYNAMICBASE flag, which was not addressed in the newer discussions. As a result, node.exe still lacks both CFG and DYNAMICBASE, and BinSkim continues to report BA2008 and BA2009.

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

まず、提供された binskim_config_no_pdb.xml を使用してビルド済みの node.exe に対する BinSkim 分析を再現し、次に Windows のビルド構成でコンパイラとリンカーのセキュリティ設定を調査します。再ビルドした node.exe で CFG と DYNAMICBASE が有効になり、BinSkim のルール BA2008 と BA2009 が報告されなくなれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
javascript, node.js
領域
build-system, operating-systems, security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
45/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。