From nobody Wed Aug 24 19:25:10 2022 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4MCbdy6Dskz4Zfhy; Wed, 24 Aug 2022 19:25:10 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4MCbdy5gbKz3PdN; Wed, 24 Aug 2022 19:25:10 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1661369110; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=5hdDJFJvhKmrCchMtsCROOuIbK2oQkWpzhbxAXwF/so=; b=QSWmhsuNB9M+jZz3mNC28BiJmDcDHUFjpLK+WRyeAIYHyH+v6ZhnwcbKp7PLE9uQ6r9Flr 9G0pi7KAKSn3msNeCY5hmwGagQ7W2DFNRsjLZrVFGXZ6zOQHd3f0VmquHJ7Pr+4IugLzix xr6hDMVUV/YVX64wfBrfCqIoHzu5V0BEfftgH9nHpFMQmovhTTyJtfjtxzf8m0zfynjCLI d0+D8Vwi+5/DjAa2veiejGPtP5oZq8dkWGTXXHTCYhR1exCqztQQDH8CbIr3I4XnhgfpJG PX6rgjlDZnD3DDz1m5SLyYidph/98/KmdhwSKbR1sRnB4h3ZFbPcp/B4rG5B9w== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4MCbdy4kNnzLFG; Wed, 24 Aug 2022 19:25:10 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 27OJPAPu069125; Wed, 24 Aug 2022 19:25:10 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 27OJPAL1069124; Wed, 24 Aug 2022 19:25:10 GMT (envelope-from git) Date: Wed, 24 Aug 2022 19:25:10 GMT Message-Id: <202208241925.27OJPAL1069124@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Konstantin Belousov Subject: git: a03e4799e76b - main - irettraps: i386 does not push %ss/%esp when exception does not switch rings List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-main@freebsd.org X-BeenThere: dev-commits-src-main@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kib X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: a03e4799e76bdfe432f560d96448895ba6ee6133 Auto-Submitted: auto-generated ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1661369110; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=5hdDJFJvhKmrCchMtsCROOuIbK2oQkWpzhbxAXwF/so=; b=IIeugD+6NXGWn9tuQQ+QbW7wxfCdWxXQ0heMY2FNajp3PVRNM2tol9Ti8Xuu+S7KflJw9G NQql46L56nap3wNwERRIKu3b2yXvNT/KbKTKb7pwXY3QmPnP8BYphjRXkRGf8ClFu+hVHK RJl1AXUTk5w9Qpx59ibtBLhx23HQHIN9dEvkm1f0UCIg/XnNQvAscQsDa9c+HbDVBm9iSZ 6jaCP+drDNWjUoa7RK3i38FlmfbNYAElyFB/kCjufnc6XG6kiVwfv03RPhkDfEWk4leTgE 9+oNCzn5GhdCRxORHUqER7bt2NrbfPqX9T//4vRlX11TaJE2vHddM4c8zmSKEg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1661369110; a=rsa-sha256; cv=none; b=BgHBVwTxQLXRVmFACb6X2jQgfPCFI0bzTtUDPf1LRekC9a6t8vmyVjkUk/ih8mco6xMfX8 nCeDpOKj2KoRnGT3LU/wnyoZ1Tow8Z5G1j9N4dzq1fRFs3dPrhyG0/G3QUEGTa4hjPi0W3 LaeCE11HymokY7E2BQhQQkaKRNFvYMSIUEhV0P/Edygiq9zeqVDV9RXTiC3ymEc4zd1l0q oE1lmFCUB7Mk6b3AHsSpLFaMO4bVoLUz5v2TIp1UeY/T1xVf2Azh6HFTEmUTGPOSE74wKC fjBAeLRzR8lHfXAq5gq+QMbqoENX8fwAgMCc8+rJxvWmk2UI9CIOla8N4tLgHg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by kib: URL: https://cgit.FreeBSD.org/src/commit/?id=a03e4799e76bdfe432f560d96448895ba6ee6133 commit a03e4799e76bdfe432f560d96448895ba6ee6133 Author: Konstantin Belousov AuthorDate: 2022-08-22 01:20:28 +0000 Commit: Konstantin Belousov CommitDate: 2022-08-24 19:11:49 +0000 irettraps: i386 does not push %ss/%esp when exception does not switch rings Which means that we must not copy top 8 bytes from the trampoline stack for the exception frame to the regular thread kstack. As consequence, this stops corruption of the pcb. The visible effect was often a broken fork(2) on the CPU where corruption occured. Account for the detail by substracting 8 from the copy byte count when moving exception frames from trampoline to the regular stack. [irettraps handles segmentation/stack/protection faults which could occur on the doreti path, where we might already switched stack and address space] Reported and tested by: pho Reviewed by: jhb Sponsored by: The FreeBSD Foundation MFC after: 1 week Differential revision: https://reviews.freebsd.org/D36302 --- sys/i386/i386/exception.s | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/sys/i386/i386/exception.s b/sys/i386/i386/exception.s index 42e9c474c3cd..5eef9c1d512c 100644 --- a/sys/i386/i386/exception.s +++ b/sys/i386/i386/exception.s @@ -229,22 +229,23 @@ irettraps: leal (doreti_iret - 1b)(%ebx), %edx cmpl %edx, TF_EIP(%esp) jne 2f - movl $(2 * TF_SZ - TF_EIP), %ecx + /* -8 because exception did not switch ring */ + movl $(2 * TF_SZ - TF_EIP - 8), %ecx jmp 6f 2: leal (doreti_popl_ds - 1b)(%ebx), %edx cmpl %edx, TF_EIP(%esp) jne 3f - movl $(2 * TF_SZ - TF_DS), %ecx + movl $(2 * TF_SZ - TF_DS - 8), %ecx jmp 6f 3: leal (doreti_popl_es - 1b)(%ebx), %edx cmpl %edx, TF_EIP(%esp) jne 4f - movl $(2 * TF_SZ - TF_ES), %ecx + movl $(2 * TF_SZ - TF_ES - 8), %ecx jmp 6f 4: leal (doreti_popl_fs - 1b)(%ebx), %edx cmpl %edx, TF_EIP(%esp) jne 5f - movl $(2 * TF_SZ - TF_FS), %ecx + movl $(2 * TF_SZ - TF_FS - 8), %ecx jmp 6f /* kernel mode, normal */ 5: jmp calltrap