NetBSD Problem Report #50245
From www@NetBSD.org Mon Sep 14 16:45:59 2015
Return-Path: <www@NetBSD.org>
Received: from mail.netbsd.org (mail.netbsd.org [149.20.53.66])
(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
(Client CN "mail.netbsd.org", Issuer "Postmaster NetBSD.org" (verified OK))
by mollari.NetBSD.org (Postfix) with ESMTPS id 8B4F7A5B2E
for <gnats-bugs@gnats.NetBSD.org>; Mon, 14 Sep 2015 16:45:59 +0000 (UTC)
Message-Id: <20150914164558.4BE4AA6562@mollari.NetBSD.org>
Date: Mon, 14 Sep 2015 16:45:58 +0000 (UTC)
From: cube@cubidou.net
Reply-To: cube@cubidou.net
To: gnats-bugs@NetBSD.org
Subject: i386 multiboot kernel assumes ss:esp is valid
X-Send-Pr-Version: www-1.0
>Number: 50245
>Category: port-i386
>Synopsis: i386 multiboot kernel assumes ss:esp is valid
>Confidential: no
>Severity: serious
>Priority: medium
>Responsible: port-i386-maintainer
>State: closed
>Class: sw-bug
>Submitter-Id: net
>Arrival-Date: Mon Sep 14 16:50:01 +0000 2015
>Closed-Date: Thu Aug 10 14:15:23 +0000 2017
>Last-Modified: Sat Sep 09 17:30:01 +0000 2017
>Originator: Quentin Garnier
>Release: current
>Organization:
>Environment:
>Description:
https://www.gnu.org/software/grub/manual/multiboot/multiboot.html
says this:
‘ESP’
The OS image must create its own stack as soon as it needs one.
However, sys/arch/i386/i386/locore.S does this:
/*
* Indeed, a multiboot-compliant boot loader executed us. We copy
* the received Multiboot information structure into kernel's data
* space to process it later -- after we are relocated. It will
* be safer to run complex C code than doing it at this point.
*/
pushl %ebx # Address of Multiboot information
which assumes that ss:esp points to something usable, when there is no guarantee for that.
>How-To-Repeat:
>Fix:
>Release-Note:
>Audit-Trail:
State-Changed-From-To: open->closed
State-Changed-By: maxv@NetBSD.org
State-Changed-When: Thu, 10 Aug 2017 14:15:23 +0000
State-Changed-Why:
Fixed, thanks for the report.
From: "Maxime Villard" <maxv@netbsd.org>
To: gnats-bugs@gnats.NetBSD.org
Cc:
Subject: PR/50245 CVS commit: src/sys/arch/i386/i386
Date: Thu, 10 Aug 2017 14:13:45 +0000
Module Name: src
Committed By: maxv
Date: Thu Aug 10 14:13:45 UTC 2017
Modified Files:
src/sys/arch/i386/i386: locore.S
Log Message:
Switch to the temporary stack right away when booted via multiboot. GRUB
happens to give a correct stack, but it is not guaranteed by the spec. This
temporary stack will be reset later, which is fine.
Fixes PR/50245.
To generate a diff of this commit:
cvs rdiff -u -r1.149 -r1.150 src/sys/arch/i386/i386/locore.S
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
From: "Soren Jacobsen" <snj@netbsd.org>
To: gnats-bugs@gnats.NetBSD.org
Cc:
Subject: PR/50245 CVS commit: [netbsd-8] src/sys/arch
Date: Sat, 9 Sep 2017 17:29:41 +0000
Module Name: src
Committed By: snj
Date: Sat Sep 9 17:29:41 UTC 2017
Modified Files:
src/sys/arch/amd64/conf [netbsd-8]: ALL
src/sys/arch/i386/conf [netbsd-8]: ALL
src/sys/arch/i386/i386 [netbsd-8]: i386_trap.S locore.S
src/sys/arch/x86/x86 [netbsd-8]: sys_machdep.c
Log Message:
Pull up following revision(s) (requested by maxv in ticket #258):
sys/arch/amd64/conf/ALL: 1.68
sys/arch/i386/conf/ALL: 1.428
sys/arch/i386/i386/i386_trap.S: 1.12
sys/arch/i386/i386/locore.S: 1.149-1.150
sys/arch/x86/x86/sys_machdep.c: 1.38
Remove undocumented hack.
--
Switch to the temporary stack right away when booted via multiboot. GRUB
happens to give a correct stack, but it is not guaranteed by the spec. This
temporary stack will be reset later, which is fine.
Fixes PR/50245.
--
Pfff, use %ss and not %ds. The latter is controlled by userland, the former
contains the kernel value (flat); FreeBSD fixed this too a few weeks ago.
As I said earlier, this dtrace code is complete bullshit.
--
Don't allow userland to create 286/386 call gates anymore - they are not
used by Wine. While here, don't allow it to overwrite the static entries
either, don't allow unknown entry types, remove LDT_DEBUG, and style.
To generate a diff of this commit:
cvs rdiff -u -r1.59 -r1.59.2.1 src/sys/arch/amd64/conf/ALL
cvs rdiff -u -r1.419.2.1 -r1.419.2.2 src/sys/arch/i386/conf/ALL
cvs rdiff -u -r1.6.6.1 -r1.6.6.2 src/sys/arch/i386/i386/i386_trap.S
cvs rdiff -u -r1.145.6.1 -r1.145.6.2 src/sys/arch/i386/i386/locore.S
cvs rdiff -u -r1.35.6.1 -r1.35.6.2 src/sys/arch/x86/x86/sys_machdep.c
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
>Unformatted:
(Contact us)
$NetBSD: query-full-pr,v 1.39 2013/11/01 18:47:49 spz Exp $
$NetBSD: gnats_config.sh,v 1.8 2006/05/07 09:23:38 tsutsui Exp $
Copyright © 1994-2014
The NetBSD Foundation, Inc. ALL RIGHTS RESERVED.