<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Arm on Rohit Jha</title><link>https://www.rohitjha.dev/tags/arm/</link><description>Recent content in Arm on Rohit Jha</description><generator>Hugo</generator><language>en-US</language><copyright>© Rohit Jha. Articles licensed under CC BY-SA 4.0 unless noted.</copyright><lastBuildDate>Fri, 09 Oct 2026 21:39:47 +0530</lastBuildDate><atom:link href="https://www.rohitjha.dev/tags/arm/index.xml" rel="self" type="application/rss+xml"/><item><title>Hardening a C Binary on Linux</title><link>https://www.rohitjha.dev/blog/hardening-a-binary/</link><pubDate>Fri, 09 Oct 2026 00:00:00 +0000</pubDate><guid>https://www.rohitjha.dev/blog/hardening-a-binary/</guid><description>&lt;p&gt;I opened &lt;a href="https://distrowatch.org/"&gt;DistroWatch&lt;/a&gt; after a long time and came across &lt;a href="https://hardenedbsd.org/"&gt;HardenedBSD&lt;/a&gt;. Comparing it with &lt;a href="https://www.freebsd.org/"&gt;FreeBSD&lt;/a&gt; and &lt;a href="https://www.openbsd.org/"&gt;OpenBSD&lt;/a&gt;, which I&amp;rsquo;m more familiar with, led me to explore the hardening techniques used by HardenedBSD and OpenBSD. I decided to document a few of those techniques through small experiments, following each defense from the build option that enables it to the change it makes in program behavior.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m using C because a small program lets me trace a memory operation into the generated instructions, making both an unsafe copy and the checks added to defend it visible. C is central to the &lt;a href="https://docs.kernel.org/process/programming-language.html"&gt;Linux kernel&lt;/a&gt;, &lt;a href="https://sqlite.org/about.html"&gt;SQLite&lt;/a&gt;, &lt;a href="https://github.com/redis/redis"&gt;Redis&lt;/a&gt;, &lt;a href="https://github.com/nginx/nginx"&gt;NGINX&lt;/a&gt;, and the &lt;a href="https://github.com/asterisk/asterisk"&gt;Asterisk&lt;/a&gt; telephony platform; it is also the native extension language for &lt;a href="https://docs.python.org/3/extending/extending.html"&gt;CPython&lt;/a&gt;. Understanding these mechanisms is therefore useful even when the application itself is written in another language.&lt;/p&gt;</description></item></channel></rss>