Page Menu
Home
FreeBSD
Search
Configure Global Search
Log In
Files
F144935568
D55281.id.diff
No One
Temporary
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Mute Notifications
Flag For Later
Award Token
Size
1 KB
Referenced Files
None
Subscribers
None
D55281.id.diff
View Options
Index: share/man/man7/mitigations.7
===================================================================
--- share/man/man7/mitigations.7
+++ share/man/man7/mitigations.7
@@ -335,8 +335,14 @@
from the kernel.
This also provides effective protection against NULL pointer dereferences from
kernel.
+An additional technique,
+Linear Address Space Separation (LASS), is available on amd64.
+LASS prevents user-mode applications from accessing kernel-mode memory,
+and vice-versa, to additionally mitigate speculative-execution
+side-channel attacks.
.Bl -column -offset indent "Architecture" "Feature" "Access Type Prevented"
.It Sy Architecture Ta Sy Feature Ta Sy Access Type Prevented
+.It amd64 Ta LASS Ta All
.It amd64 Ta SMAP Ta Read / Write
.It amd64 Ta SMEP Ta Execute
.It arm64 Ta PAN Ta Read / Write
@@ -345,8 +351,11 @@
.It riscv Ta - Ta Execute
.El
.Pp
-These features are automatically used by the kernel.
-There is no user-facing configuration.
+Most of these features are automatically used by the kernel,
+with no user-facing configuration.
+LASS is controlled by the
+.Va hw.lass
+loader tunable.
.\"
.Ss Capsicum
Capsicum is a lightweight OS capability and sandbox framework.
File Metadata
Details
Attached
Mime Type
text/plain
Expires
Sun, Feb 15, 7:00 AM (12 h, 59 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
28715958
Default Alt Text
D55281.id.diff (1 KB)
Attached To
Mode
D55281: mitigations.7: Describe LASS
Attached
Detach File
Event Timeline
Log In to Comment