Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1381255
| From | "H. Peter Anvin" <hpa@zytor.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH] x86/entry/x32: Check top 32 bits of syscall number on the fast path |
| Date | 2016-04-18 07:30 +0200 |
| Message-ID | <rp9UZ-94-1@gated-at.bofh.it> (permalink) |
| References | <rp5y1-4CY-7@gated-at.bofh.it> <rp5y1-4CY-9@gated-at.bofh.it> <rp9rY-863-5@gated-at.bofh.it> <rp9Lk-8w6-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 04/17/16 22:18, Andy Lutomirski wrote: > On Sun, Apr 17, 2016 at 9:50 PM, H. Peter Anvin <hpa@zytor.com> wrote: >> On 04/17/16 17:47, Ben Hutchings wrote: >>> We've always masked off the top 32 bits when x32 is enabled, but >>> hopefully no-one relies on that. Now that the slow path is in C, we >>> check all the bits there, regardless of whether x32 is enabled. Let's >>> make the fast path consistent with it. >> >> We have always masked off the top 32 bits *period*. >> >> We have had some bugs where we haven't, because someone has tried to >> "optimize" the code and they have been quite serious. The system call >> number is an int, which means the upper 32 bits are undefined on call >> entry: we HAVE to mask them. > > I'm reasonably confident that normal kernels (non-x32) have not masked > those bits since before I started hacking on the entry code. > > So the type of the syscall nr is a bit confused. If there was an > installed base of programs that leaved garbage in the high bits, we > would have noticed *years* ago. On the other hand, the 32-bit ptrace > ABI and the seccomp ABI both think it's 32-bits. > > If we were designing the x86_64 ABI and everything around it from > scratch, I'd suggest that that either the high bits must be zero or > that the number actually be 64 bits (which are more or less the same > thing). That would let us use the high bits for something interesting > in the future. > > In practice, we can probably still declare that the thing is a 64-bit > number, given that most kernels in the wild currently fail syscalls > that have the high bits set. > For the record, I changed the range comparison from cmpl to cmpq so if someone re-introduced this bug *again* it would be a functionality problem as opposed to a security hole a mile wide. -hpa
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: System call number masking Ben Hutchings <ben@decadent.org.uk> - 2016-04-18 02:50 +0200
[PATCH] x86/entry/x32: Check top 32 bits of syscall number on the fast path Ben Hutchings <ben@decadent.org.uk> - 2016-04-18 02:50 +0200
Re: [PATCH] x86/entry/x32: Check top 32 bits of syscall number on the fast path "H. Peter Anvin" <hpa@zytor.com> - 2016-04-18 07:00 +0200
Re: [PATCH] x86/entry/x32: Check top 32 bits of syscall number on the fast path Andy Lutomirski <luto@amacapital.net> - 2016-04-18 07:20 +0200
Re: [PATCH] x86/entry/x32: Check top 32 bits of syscall number on the fast path "H. Peter Anvin" <hpa@zytor.com> - 2016-04-18 07:30 +0200
Re: [PATCH] x86/entry/x32: Check top 32 bits of syscall number on the fast path "H. Peter Anvin" <hpa@zytor.com> - 2016-04-18 07:30 +0200
Re: [PATCH] x86/entry/x32: Check top 32 bits of syscall number on the fast path Andy Lutomirski <luto@amacapital.net> - 2016-04-18 07:40 +0200
Re: [PATCH] x86/entry/x32: Check top 32 bits of syscall number on the fast path "H. Peter Anvin" <hpa@zytor.com> - 2016-04-18 07:50 +0200
Re: [PATCH] x86/entry/x32: Check top 32 bits of syscall number on the fast path Andy Lutomirski <luto@amacapital.net> - 2016-04-18 07:50 +0200
Re: [PATCH] x86/entry/x32: Check top 32 bits of syscall number on the fast path "H. Peter Anvin" <hpa@zytor.com> - 2016-04-18 08:10 +0200
Re: [PATCH] x86/entry/x32: Check top 32 bits of syscall number on the fast path "H. Peter Anvin" <hpa@zytor.com> - 2016-04-18 08:20 +0200
Re: [PATCH] x86/entry/x32: Check top 32 bits of syscall number on the fast path Andy Lutomirski <luto@amacapital.net> - 2016-04-18 08:20 +0200
csiph-web