From 9485052d98ba055be3355565e23630de8f8c4ef8 Mon Sep 17 00:00:00 2001 From: Mikhail Koliada <88318005+mikhailkoliada@users.noreply.github.com> Date: Fri, 15 Mar 2024 11:06:43 +0100 Subject: [PATCH] [Ubuntu] Decrease vm.mmap_rnd_bit to prevent ASLR ASAN issues (#9513) --- images/ubuntu/scripts/build/configure-environment.sh | 3 +++ 1 file changed, 3 insertions(+) diff --git a/images/ubuntu/scripts/build/configure-environment.sh b/images/ubuntu/scripts/build/configure-environment.sh index 7ffbe60d8..5e3781578 100644 --- a/images/ubuntu/scripts/build/configure-environment.sh +++ b/images/ubuntu/scripts/build/configure-environment.sh @@ -41,6 +41,9 @@ echo 'vm.max_map_count=262144' | tee -a /etc/sysctl.conf echo 'fs.inotify.max_user_watches=655360' | tee -a /etc/sysctl.conf echo 'fs.inotify.max_user_instances=1280' | tee -a /etc/sysctl.conf +# https://github.com/actions/runner-images/issues/9491 +echo 'vm.mmap_rnd_bits=28' | tee -a /etc/sysctl.conf + # https://github.com/actions/runner-images/pull/7860 netfilter_rule='/etc/udev/rules.d/50-netfilter.rules' rules_directory="$(dirname "${netfilter_rule}")"