Kyle McMartin a1b0ec0
From eefdca043e8391dcd719711716492063030b55ac Mon Sep 17 00:00:00 2001
Kyle McMartin a1b0ec0
From: Roland McGrath <roland@redhat.com>
Kyle McMartin a1b0ec0
Date: Tue, 14 Sep 2010 12:22:58 -0700
Kyle McMartin a1b0ec0
Subject: [PATCH] x86-64, compat: Retruncate rax after ia32 syscall entry tracing
Kyle McMartin a1b0ec0
Kyle McMartin a1b0ec0
In commit d4d6715, we reopened an old hole for a 64-bit ptracer touching a
Kyle McMartin a1b0ec0
32-bit tracee in system call entry.  A %rax value set via ptrace at the
Kyle McMartin a1b0ec0
entry tracing stop gets used whole as a 32-bit syscall number, while we
Kyle McMartin a1b0ec0
only check the low 32 bits for validity.
Kyle McMartin a1b0ec0
Kyle McMartin a1b0ec0
Fix it by truncating %rax back to 32 bits after syscall_trace_enter,
Kyle McMartin a1b0ec0
in addition to testing the full 64 bits as has already been added.
Kyle McMartin a1b0ec0
Kyle McMartin a1b0ec0
Reported-by: Ben Hawkes <hawkes@sota.gen.nz>
Kyle McMartin a1b0ec0
Signed-off-by: Roland McGrath <roland@redhat.com>
Kyle McMartin a1b0ec0
Signed-off-by: H. Peter Anvin <hpa@linux.intel.com>
Kyle McMartin a1b0ec0
---
Kyle McMartin a1b0ec0
 arch/x86/ia32/ia32entry.S |    8 +++++++-
Kyle McMartin a1b0ec0
 1 files changed, 7 insertions(+), 1 deletions(-)
Kyle McMartin a1b0ec0
Kyle McMartin a1b0ec0
diff --git a/arch/x86/ia32/ia32entry.S b/arch/x86/ia32/ia32entry.S
Kyle McMartin a1b0ec0
index 84e3a4e..518bb99 100644
Kyle McMartin a1b0ec0
--- a/arch/x86/ia32/ia32entry.S
Kyle McMartin a1b0ec0
+++ b/arch/x86/ia32/ia32entry.S
Kyle McMartin a1b0ec0
@@ -50,7 +50,12 @@
Kyle McMartin a1b0ec0
 	/*
Kyle McMartin a1b0ec0
 	 * Reload arg registers from stack in case ptrace changed them.
Kyle McMartin a1b0ec0
 	 * We don't reload %eax because syscall_trace_enter() returned
Kyle McMartin a1b0ec0
-	 * the value it wants us to use in the table lookup.
Kyle McMartin a1b0ec0
+	 * the %rax value we should see.  Instead, we just truncate that
Kyle McMartin a1b0ec0
+	 * value to 32 bits again as we did on entry from user mode.
Kyle McMartin a1b0ec0
+	 * If it's a new value set by user_regset during entry tracing,
Kyle McMartin a1b0ec0
+	 * this matches the normal truncation of the user-mode value.
Kyle McMartin a1b0ec0
+	 * If it's -1 to make us punt the syscall, then (u32)-1 is still
Kyle McMartin a1b0ec0
+	 * an appropriately invalid value.
Kyle McMartin a1b0ec0
 	 */
Kyle McMartin a1b0ec0
 	.macro LOAD_ARGS32 offset, _r9=0
Kyle McMartin a1b0ec0
 	.if \_r9
Kyle McMartin a1b0ec0
@@ -60,6 +65,7 @@
Kyle McMartin a1b0ec0
 	movl \offset+48(%rsp),%edx
Kyle McMartin a1b0ec0
 	movl \offset+56(%rsp),%esi
Kyle McMartin a1b0ec0
 	movl \offset+64(%rsp),%edi
Kyle McMartin a1b0ec0
+	movl %eax,%eax			/* zero extension */
Kyle McMartin a1b0ec0
 	.endm
Kyle McMartin a1b0ec0
 	
Kyle McMartin a1b0ec0
 	.macro CFI_STARTPROC32 simple
Kyle McMartin a1b0ec0
-- 
Kyle McMartin a1b0ec0
1.7.2.3
Kyle McMartin a1b0ec0