OPNsense - FreeBSD source
Find a file
Jessica Clarke 29863d1eff xhci: Rework 64-byte context support to avoid pointer abuse
Currently, to support 64-byte contexts, xhci_ctx_[gs]et_le(32|64) take a
pointer to the field within a 32-byte context and, if 64-byte contexts
are in use, compute where the 64-byte context field is and use that
instead by deriving a pointer from the 32-byte field pointer. This is
done by exploiting a combination of 64-byte contexts being the same
layout as their 32-byte counterparts, just with 32 bytes of padding at
the end, and that all individual contexts are either in a device
context or an input context which itself is page-aligned. By masking out
the low 4 bits (which is the offset of the field within the 32-byte
contxt) of the offset within the page, the offset of the invididual
context within the containing device/input context can be determined,
which is itself 32 times the number of preceding contexts. Thus, adding
this value to the pointer again gets 64 times the number of preceding
contexts plus the field offset, which gives the offset of the 64-byte
context plus the field offset, which is the address of the field in the
64-byte context.

However, this involves a fair amount of lying to the compiler when
constructing these intermediate pointers, and is rather difficult to
reason about. In particular, this is problematic for CHERI, where we
compile the kernel with subobject bounds enabled; that is, unless
annotated to opt out (e.g. for C struct inheritance reasons where you
need to be able to downcast, or containerof idioms), a pointer to a
member of a struct is a capability whose bounds only cover that field,
and any attempt to dereference outside those bounds will fault,
protecting against intra-object buffer overflows. Thus the pointer given
to xhci_ctx_[gs]et_le(32|64) is a capability whose bounds only cover the
field in the 32-byte context, and computing the pointer to the 64-byte
context field takes the address out of bounds, resulting in a fault when
later dereferenced.

This can be cleaned up by using a different abstraction. Instead of
doing the 32-byte to 64-byte conversion on access to the field, we can
do the conversion when getting a pointer to the context itself, and
define proper 64-byte versions of contexts in order to let the compiler
do all the necessary arithmetic rather than do it manually ourselves.
This provides a cleaner implementation, works for CHERI and may even be
slightly more performant as it avoids the need to mess with masking
pointers (which cannot in the general case be optimised by compilers to
be reused across accesses to different fields within the same context,
since it does not know that the contexts are over-aligned compared with
the C ABI requirements).

Reviewed by:	hselasky
Differential Revision:	https://reviews.freebsd.org/D32554
2021-10-27 18:38:37 +01:00
.cirrus-ci Cirrus-CI: add some timing info on pkg install failure 2021-08-04 15:02:00 -04:00
.github [skip ci] fix syntax in CODEOWNERS 2021-07-22 10:58:54 -06:00
bin sh: Set PATH envvar after setting HOME in dotfile 2021-10-26 22:50:09 +08:00
cddl zfs: merge openzfs/zfs@ec64fdb93 (master) into main 2021-10-21 15:06:06 +02:00
contrib strip/objcopy: handle empty file as unknown 2021-10-25 17:28:41 -04:00
crypto OpenSSH: cherry-pick "need initgroups() before setresgid()" 2021-10-08 21:29:25 -04:00
etc sh(1): make it the default shell for the root user 2021-10-20 09:34:05 +02:00
gnu libdialog: Bump shared library version to 10. 2021-10-27 09:30:24 -07:00
include Remove FreeBSD's local copy of the dmu_buf_hold_array() function 2021-10-13 11:01:01 -07:00
kerberos5 pkgbase: Create a FreeBSD-kerberos package 2021-09-07 10:23:14 +02:00
lib libdialog: Bump shared library version to 10. 2021-10-27 09:30:24 -07:00
libexec rtld: Print currently configured search path for libraries for -v 2021-10-25 20:41:53 +03:00
release release: add _LOCATION to the list of required AZURE variables 2021-10-13 17:11:48 -04:00
rescue Retire synchronous PPP kernel driver sppp(4). 2021-10-22 11:41:36 -07:00
sbin Retire obsolete iscsi_initiator(4) 2021-10-26 16:17:35 -04:00
secure libssh: Rearrange Makefile SRCS to match upstream Makefile.in 2021-10-19 20:10:56 -04:00
share Retire obsolete iscsi_initiator(4) 2021-10-26 16:17:35 -04:00
stand lualoader: fix the autoboot_delay countdown message 2021-10-26 11:24:29 -05:00
sys xhci: Rework 64-byte context support to avoid pointer abuse 2021-10-27 18:38:37 +01:00
targets Retire obsolete iscsi_initiator(4) 2021-10-26 16:17:35 -04:00
tests pf tests: test NAT-ed ICMP errors 2021-10-22 09:52:17 +02:00
tools libdialog: Bump shared library version to 10. 2021-10-27 09:30:24 -07:00
usr.bin Retire obsolete iscsi_initiator(4) 2021-10-26 16:17:35 -04:00
usr.sbin crunchgen: use realpath(3) instead of ``pwd -P'' 2021-10-27 09:26:00 +00:00
.arcconfig Remove history.immutable from .arcconfig 2021-04-13 12:36:25 +01:00
.arclint arc lint: ignore /tests/ in chmod 2017-12-19 03:38:06 +00:00
.cirrus.yml Cirrus-CI: add a manually triggered arm64 task 2021-09-14 15:12:55 -04:00
.clang-format clang-format: Add bitset loop macros 2021-09-21 12:08:01 -04:00
.gitattributes Add a basic clang-format configuration file 2019-06-07 15:23:52 +00:00
.gitignore gitignore: Add .clangd and .ccls-cache 2021-06-04 16:56:08 +08:00
COPYRIGHT copyrights: Happy New Year 2021 2020-12-31 10:29:44 -05:00
LOCKS LOCKS: update current locks 2018-06-09 03:08:04 +00:00
MAINTAINERS [skip ci] volunteer to maintain POSIX AIO 2021-05-30 17:21:12 -06:00
Makefile Revert "Fix native-xtools build" 2021-08-03 10:00:28 -07:00
Makefile.inc1 Makefile.inc1: Remove mentions of removed target "update" 2021-10-24 21:07:45 +02:00
Makefile.libcompat ncurses: fix libcompat (lib32 for example) building 2021-10-04 14:16:32 +02:00
Makefile.sys.inc AUTO_OBJ: For all top-level targets enforce using an OBJDIR. 2017-12-05 21:29:47 +00:00
ObsoleteFiles.inc libdialog: Bump shared library version to 10. 2021-10-27 09:30:24 -07:00
README.md Whitespace cleanup 2021-03-12 19:57:58 +08:00
RELNOTES RELNOTES: Fix KMSAN entry 2021-10-22 15:16:54 +08:00
UPDATING Retire synchronous PPP kernel driver sppp(4). 2021-10-22 11:41:36 -07:00

FreeBSD Source:

This is the top level of the FreeBSD source directory.

FreeBSD is an operating system used to power modern servers, desktops, and embedded platforms. A large community has continually developed it for more than thirty years. Its advanced networking, security, and storage features have made FreeBSD the platform of choice for many of the busiest web sites and most pervasive embedded networking and storage devices.

For copyright information, please see the file COPYRIGHT in this directory. Additional copyright information also exists for some sources in this tree - please see the specific source directories for more information.

The Makefile in this directory supports a number of targets for building components (or all) of the FreeBSD source tree. See build(7), config(8), FreeBSD handbook on building userland, and Handbook for kernels for more information, including setting make(1) variables.

Source Roadmap:

Directory Description
bin System/user commands.
cddl Various commands and libraries under the Common Development and Distribution License.
contrib Packages contributed by 3rd parties.
crypto Cryptography stuff (see crypto/README).
etc Template files for /etc.
gnu Various commands and libraries under the GNU Public License. Please see gnu/COPYING and gnu/COPYING.LIB for more information.
include System include files.
kerberos5 Kerberos5 (Heimdal) package.
lib System libraries.
libexec System daemons.
release Release building Makefile & associated tools.
rescue Build system for statically linked /rescue utilities.
sbin System commands.
secure Cryptographic libraries and commands.
share Shared resources.
stand Boot loader sources.
sys Kernel sources.
sys/arch/conf Kernel configuration files. GENERIC is the configuration used in release builds. NOTES contains documentation of all possible entries.
tests Regression tests which can be run by Kyua. See tests/README for additional information.
tools Utilities for regression testing and miscellaneous tasks.
usr.bin User commands.
usr.sbin System administration commands.

For information on synchronizing your source tree with one or more of the FreeBSD Project's development branches, please see FreeBSD Handbook.