Source-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[src/trunk]: src/sys/arch/amd64/amd64 Mmh, don't forget to clear the TLS gdt ...



details:   https://anonhg.NetBSD.org/src/rev/a1280cf94adc
branches:  trunk
changeset: 827124:a1280cf94adc
user:      maxv <maxv%NetBSD.org@localhost>
date:      Sun Oct 15 13:34:24 2017 +0000

description:
Mmh, don't forget to clear the TLS gdt slots on Xen. Otherwise, when doing
a lwp32->lwp64 context switch, the new lwp can use the slots to reconstruct
the address of the previous lwp's TLS space (and defeat ASLR?).

diffstat:

 sys/arch/amd64/amd64/machdep.c |  7 +++++--
 1 files changed, 5 insertions(+), 2 deletions(-)

diffs (35 lines):

diff -r 90e46a7b69c7 -r a1280cf94adc sys/arch/amd64/amd64/machdep.c
--- a/sys/arch/amd64/amd64/machdep.c    Sun Oct 15 12:49:53 2017 +0000
+++ b/sys/arch/amd64/amd64/machdep.c    Sun Oct 15 13:34:24 2017 +0000
@@ -1,4 +1,4 @@
-/*     $NetBSD: machdep.c,v 1.266 2017/10/15 12:49:53 maxv Exp $       */
+/*     $NetBSD: machdep.c,v 1.267 2017/10/15 13:34:24 maxv Exp $       */
 
 /*
  * Copyright (c) 1996, 1997, 1998, 2000, 2006, 2007, 2008, 2011
@@ -110,7 +110,7 @@
  */
 
 #include <sys/cdefs.h>
-__KERNEL_RCSID(0, "$NetBSD: machdep.c,v 1.266 2017/10/15 12:49:53 maxv Exp $");
+__KERNEL_RCSID(0, "$NetBSD: machdep.c,v 1.267 2017/10/15 13:34:24 maxv Exp $");
 
 /* #define XENDEBUG_LOW  */
 
@@ -431,6 +431,7 @@
        struct cpu_info *ci = curcpu();
        struct pcb *pcb = lwp_getpcb(l);
        struct trapframe *tf = l->l_md.md_regs;
+       uint64_t zero = 0;
 
        /*
         * Raise the IPL to IPL_HIGH.
@@ -453,6 +454,8 @@
                setfs(tf->tf_fs);
                HYPERVISOR_set_segment_base(SEGBASE_GS_USER_SEL, tf->tf_gs);
        } else {
+               update_descriptor(&curcpu()->ci_gdt[GUFS_SEL], &zero);
+               update_descriptor(&curcpu()->ci_gdt[GUGS_SEL], &zero);
                setfs(0);
                HYPERVISOR_set_segment_base(SEGBASE_GS_USER_SEL, 0);
                HYPERVISOR_set_segment_base(SEGBASE_FS, pcb->pcb_fs);



Home | Main Index | Thread Index | Old Index