W^X stands for "writable xor executable":
> What this means is that each page holding JIT code is either executable or writable, never both at the same time.
For anybody, like me, who didn't already know :)
> What this means is that each page holding JIT code is either executable or writable, never both at the same time.
For anybody, like me, who didn't already know :)
It's a solid security enhancement.
See also, Theo de Raadt's recent comment on why OSes can't enforce W^X on userland (yet): https://marc.info/?l=openbsd-misc&m=145943630726937&w=2
Each layer of protection fends off another class of attackers.
An attacker with infinite determination, money, or time will always push past your defenses.