Page MenuHomeFreeBSD

The ops EL_SIGNAL, EL_EDITMODE, EL_UNBUFFERED, and EL_PREP_TERM all take an int, not an int*.
ClosedPublic

Authored by brooks on Nov 2 2015, 9:11 PM.
Tags
None
Referenced Files
Unknown Object (File)
Fri, Nov 29, 11:41 AM
Unknown Object (File)
Nov 14 2024, 9:31 AM
Unknown Object (File)
Nov 7 2024, 3:42 AM
Unknown Object (File)
Nov 7 2024, 3:42 AM
Unknown Object (File)
Nov 7 2024, 3:42 AM
Unknown Object (File)
Nov 7 2024, 3:26 AM
Unknown Object (File)
Oct 4 2024, 11:48 AM
Unknown Object (File)
Sep 23 2024, 1:47 AM
Subscribers

Details

Summary

Sponsored by: DARPA, AFRL
Discovered with: CHERI

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

brooks retitled this revision from to The ops EL_SIGNAL, EL_EDITMODE, EL_UNBUFFERED, and EL_PREP_TERM all take an int, not an int*..
brooks updated this object.
brooks edited the test plan for this revision. (Show Details)
brooks added a reviewer: bapt.

This bug is harmless in practice on current hardware because el_wget() is also a varargs function and va_arg(ap, int *) effectively copies the argument unmodified. On CHERI it causes a hardware trap because varargs are stored in a bounded array an reading 16-32 bytes out of an 8 byte array isn't allowed.

bapt edited edge metadata.

Looks good, but please upstream this change as well.

This revision is now accepted and ready to land.Nov 2 2015, 9:22 PM
This revision was automatically updated to reflect the committed changes.