mirror of
				https://github.com/torvalds/linux.git
				synced 2025-11-04 02:30:34 +02:00 
			
		
		
		
	A future patch will move SYSENTER_stack to the beginning of cpu_tss to help detect overflow. Before this can happen, fix several code paths that hardcode assumptions about the old layout. Signed-off-by: Andy Lutomirski <luto@kernel.org> Signed-off-by: Thomas Gleixner <tglx@linutronix.de> Reviewed-by: Borislav Petkov <bp@suse.de> Reviewed-by: Dave Hansen <dave.hansen@intel.com> Reviewed-by: Thomas Gleixner <tglx@linutronix.de> Cc: Boris Ostrovsky <boris.ostrovsky@oracle.com> Cc: Borislav Petkov <bp@alien8.de> Cc: Borislav Petkov <bpetkov@suse.de> Cc: Brian Gerst <brgerst@gmail.com> Cc: Dave Hansen <dave.hansen@linux.intel.com> Cc: David Laight <David.Laight@aculab.com> Cc: Denys Vlasenko <dvlasenk@redhat.com> Cc: Eduardo Valentin <eduval@amazon.com> Cc: Greg KH <gregkh@linuxfoundation.org> Cc: H. Peter Anvin <hpa@zytor.com> Cc: Josh Poimboeuf <jpoimboe@redhat.com> Cc: Juergen Gross <jgross@suse.com> Cc: Linus Torvalds <torvalds@linux-foundation.org> Cc: Peter Zijlstra <peterz@infradead.org> Cc: Rik van Riel <riel@redhat.com> Cc: Will Deacon <will.deacon@arm.com> Cc: aliguori@amazon.com Cc: daniel.gruss@iaik.tugraz.at Cc: hughd@google.com Cc: keescook@google.com Link: https://lkml.kernel.org/r/20171204150605.722425540@linutronix.de Signed-off-by: Ingo Molnar <mingo@kernel.org>
		
			
				
	
	
		
			83 lines
		
	
	
	
		
			2 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
			
		
		
	
	
			83 lines
		
	
	
	
		
			2 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
// SPDX-License-Identifier: GPL-2.0
 | 
						|
#include <linux/mm.h>
 | 
						|
#include <linux/sched.h>
 | 
						|
#include <linux/sched/debug.h>
 | 
						|
#include <linux/init_task.h>
 | 
						|
#include <linux/fs.h>
 | 
						|
 | 
						|
#include <linux/uaccess.h>
 | 
						|
#include <asm/pgtable.h>
 | 
						|
#include <asm/processor.h>
 | 
						|
#include <asm/desc.h>
 | 
						|
 | 
						|
#ifdef CONFIG_X86_32
 | 
						|
 | 
						|
#define DOUBLEFAULT_STACKSIZE (1024)
 | 
						|
static unsigned long doublefault_stack[DOUBLEFAULT_STACKSIZE];
 | 
						|
#define STACK_START (unsigned long)(doublefault_stack+DOUBLEFAULT_STACKSIZE)
 | 
						|
 | 
						|
#define ptr_ok(x) ((x) > PAGE_OFFSET && (x) < PAGE_OFFSET + MAXMEM)
 | 
						|
 | 
						|
static void doublefault_fn(void)
 | 
						|
{
 | 
						|
	struct desc_ptr gdt_desc = {0, 0};
 | 
						|
	unsigned long gdt, tss;
 | 
						|
 | 
						|
	native_store_gdt(&gdt_desc);
 | 
						|
	gdt = gdt_desc.address;
 | 
						|
 | 
						|
	printk(KERN_EMERG "PANIC: double fault, gdt at %08lx [%d bytes]\n", gdt, gdt_desc.size);
 | 
						|
 | 
						|
	if (ptr_ok(gdt)) {
 | 
						|
		gdt += GDT_ENTRY_TSS << 3;
 | 
						|
		tss = get_desc_base((struct desc_struct *)gdt);
 | 
						|
		printk(KERN_EMERG "double fault, tss at %08lx\n", tss);
 | 
						|
 | 
						|
		if (ptr_ok(tss)) {
 | 
						|
			struct x86_hw_tss *t = (struct x86_hw_tss *)tss;
 | 
						|
 | 
						|
			printk(KERN_EMERG "eip = %08lx, esp = %08lx\n",
 | 
						|
			       t->ip, t->sp);
 | 
						|
 | 
						|
			printk(KERN_EMERG "eax = %08lx, ebx = %08lx, ecx = %08lx, edx = %08lx\n",
 | 
						|
				t->ax, t->bx, t->cx, t->dx);
 | 
						|
			printk(KERN_EMERG "esi = %08lx, edi = %08lx\n",
 | 
						|
				t->si, t->di);
 | 
						|
		}
 | 
						|
	}
 | 
						|
 | 
						|
	for (;;)
 | 
						|
		cpu_relax();
 | 
						|
}
 | 
						|
 | 
						|
struct x86_hw_tss doublefault_tss __cacheline_aligned = {
 | 
						|
	.sp0		= STACK_START,
 | 
						|
	.ss0		= __KERNEL_DS,
 | 
						|
	.ldt		= 0,
 | 
						|
	.io_bitmap_base	= INVALID_IO_BITMAP_OFFSET,
 | 
						|
 | 
						|
	.ip		= (unsigned long) doublefault_fn,
 | 
						|
	/* 0x2 bit is always set */
 | 
						|
	.flags		= X86_EFLAGS_SF | 0x2,
 | 
						|
	.sp		= STACK_START,
 | 
						|
	.es		= __USER_DS,
 | 
						|
	.cs		= __KERNEL_CS,
 | 
						|
	.ss		= __KERNEL_DS,
 | 
						|
	.ds		= __USER_DS,
 | 
						|
	.fs		= __KERNEL_PERCPU,
 | 
						|
 | 
						|
	.__cr3		= __pa_nodebug(swapper_pg_dir),
 | 
						|
};
 | 
						|
 | 
						|
/* dummy for do_double_fault() call */
 | 
						|
void df_debug(struct pt_regs *regs, long error_code) {}
 | 
						|
 | 
						|
#else /* !CONFIG_X86_32 */
 | 
						|
 | 
						|
void df_debug(struct pt_regs *regs, long error_code)
 | 
						|
{
 | 
						|
	pr_emerg("PANIC: double fault, error_code: 0x%lx\n", error_code);
 | 
						|
	show_regs(regs);
 | 
						|
	panic("Machine halted.");
 | 
						|
}
 | 
						|
#endif
 |