Page MenuHomeFreeBSD

The ops EL_SIGNAL, EL_EDITMODE, EL_UNBUFFERED, and EL_PREP_TERM all take an int, not an int*.
ClosedPublic

Authored by brooks on Nov 2 2015, 9:11 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sun, Sep 28, 10:54 PM
Unknown Object (File)
Sat, Sep 27, 10:17 AM
Unknown Object (File)
Sat, Sep 27, 7:33 AM
Unknown Object (File)
Sat, Sep 27, 7:07 AM
Unknown Object (File)
Sat, Sep 27, 7:04 AM
Unknown Object (File)
Sat, Sep 27, 1:20 AM
Unknown Object (File)
Sat, Sep 27, 1:18 AM
Unknown Object (File)
Sat, Sep 27, 1:16 AM
Subscribers

Details

Summary

Sponsored by: DARPA, AFRL
Discovered with: CHERI

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

brooks retitled this revision from to The ops EL_SIGNAL, EL_EDITMODE, EL_UNBUFFERED, and EL_PREP_TERM all take an int, not an int*..
brooks updated this object.
brooks edited the test plan for this revision. (Show Details)
brooks added a reviewer: bapt.

This bug is harmless in practice on current hardware because el_wget() is also a varargs function and va_arg(ap, int *) effectively copies the argument unmodified. On CHERI it causes a hardware trap because varargs are stored in a bounded array an reading 16-32 bytes out of an 8 byte array isn't allowed.

bapt edited edge metadata.

Looks good, but please upstream this change as well.

This revision is now accepted and ready to land.Nov 2 2015, 9:22 PM
This revision was automatically updated to reflect the committed changes.