rop is a utility that can act as an optimization pass for
GCC
to remove potential polymorphic ROP gadgets on x86_64 CPUs.
rop is conceptually similar to an
LLVM
fixup pass
pioneered by Todd Mortimer (mortimer@) in
OpenBSD
as
presented
at
AsiaBSDCon 2019
and the -mmitigate-rop flag that used to exist in GCC.
rop is written in
D.
The configure script will find a suitable D compiler
automatically.
$ ./configure
$ make
$ sudo make installYou can modify your make rules to insert an invocation of
rop in the appropriate place.
For example, for C files:
.c.o:
${CC} ${CFLAGS} ${CPPFLAGS} -o- -S $< | rop | ${CC} -o $@ -c -x assembler -Alternatively, you must modify your copy of GCC to insert
an invocation of rop between the output of the compiler
pass (cc1, cc1plus, etc.) and the assembler. A patch to
do that for GCC 15.2.0 is
available.
GCC 15.2.0 is able to complete a 3-stage compiler build of
itself on FreeBSD/amd64 15.0-RELEASE with rop having appiled
the above patch using the following compiler invocation:
../gcc-15.2.0/configure --prefix=/opt/rop --enable-languages=c,c++,d --with-included-gettext --with-as=/usr/local/bin/as --with-ld=/usr/local/bin/ld --enable-gnu-indirect-function --disable-libssp --disable-multilibISC License. See LICENSE for more information.