Page MenuHomeFreeBSD

amd64: Avoid enabling interrupts when handling kernel mode prot faults
ClosedPublic

Authored by markj on May 31 2021, 4:19 PM.
Tags
None
Referenced Files
F170686219: D30578.id.diff
Sun, Sep 6, 12:51 AM
F170650061: D30578.id90218.diff
Sat, Sep 5, 7:47 PM
F170650017: D30578.id90218.diff
Sat, Sep 5, 7:47 PM
F170582700: D30578.id.diff
Sat, Sep 5, 12:34 PM
F170582093: D30578.id90189.diff
Sat, Sep 5, 12:29 PM
Unknown Object (File)
Thu, Sep 3, 11:48 AM
Unknown Object (File)
Tue, Sep 1, 11:44 PM
Unknown Object (File)
Tue, Sep 1, 11:07 PM
Subscribers

Details

Summary

When PTI is enabled, we may have been on the trampoline stack when iret
faults. So, we have to switch back to the regular stack before
re-entering trap().

trap() has the somewhat strange behaviour of re-enabling interrupts when
handling certain kernel-mode execeptions. In particular, it was doing
this for exceptions raised during execution of iret. When switching
away from the trampoline stack, however, the thread must not be migrated
to a different CPU. Fix the problem by simply leaving interrupts
disabled during the window.

Reported by: syzkaller

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable