Page MenuHomeFreeBSD

The ops EL_SIGNAL, EL_EDITMODE, EL_UNBUFFERED, and EL_PREP_TERM all take an int, not an int*.
ClosedPublic

Authored by brooks on Nov 2 2015, 9:11 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Apr 27, 10:12 AM
Unknown Object (File)
Sat, Apr 27, 10:12 AM
Unknown Object (File)
Sat, Apr 27, 9:06 AM
Unknown Object (File)
Sat, Apr 27, 8:43 AM
Unknown Object (File)
Mar 30 2024, 10:32 AM
Unknown Object (File)
Mar 28 2024, 6:14 AM
Unknown Object (File)
Mar 22 2024, 3:20 PM
Unknown Object (File)
Mar 22 2024, 3:20 PM
Subscribers

Details

Summary

Sponsored by: DARPA, AFRL
Discovered with: CHERI

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

brooks retitled this revision from to The ops EL_SIGNAL, EL_EDITMODE, EL_UNBUFFERED, and EL_PREP_TERM all take an int, not an int*..
brooks updated this object.
brooks edited the test plan for this revision. (Show Details)
brooks added a reviewer: bapt.

This bug is harmless in practice on current hardware because el_wget() is also a varargs function and va_arg(ap, int *) effectively copies the argument unmodified. On CHERI it causes a hardware trap because varargs are stored in a bounded array an reading 16-32 bytes out of an 8 byte array isn't allowed.

bapt edited edge metadata.

Looks good, but please upstream this change as well.

This revision is now accepted and ready to land.Nov 2 2015, 9:22 PM
This revision was automatically updated to reflect the committed changes.