From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id ; Sat, 8 Feb 2003 11:38:03 -0500 Received: (majordomo@vger.kernel.org) by vger.kernel.org id ; Sat, 8 Feb 2003 11:38:03 -0500 Received: from [195.39.17.254] ([195.39.17.254]:10500 "EHLO Elf.ucw.cz") by vger.kernel.org with ESMTP id ; Sat, 8 Feb 2003 11:38:02 -0500 Date: Fri, 7 Feb 2003 17:33:01 +0100 From: Pavel Machek To: Andi Kleen Cc: Kevin Lawton , linux-kernel@vger.kernel.org Subject: Re: Possible bug in arch/i386/kernel/process.c for reloading of debug registers (DRx)? Message-ID: <20030207163301.GH345@elf.ucw.cz> References: <20030203235140.10443.qmail@web80304.mail.yahoo.com.suse.lists.linux.kernel> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-Warning: Reading this can be dangerous to your mental health. User-Agent: Mutt/1.5.3i Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Hi! > > I was scanning through the source and noticed the lines below. > > Should the code below, be reloading at least the local bits of > > DR7 if the current DR7 value != 0? From a quick glance, it > > looks like only if the next task's DR7 value is non-zero, > > that DR7 is reloaded. I'm wondering if this would leave > > a new task to receive "local" debug events for the previous > > task if prev->DR7!=0 && next->DR7==0. > > The do_debug trap handler handles that. It checks that > the debug event is set in the current process before doing anything > and if they weren't they are clared. > > So yes they leak, but only once and the user should never notice. What if DRx contains sensitive data? ...Its probably pretty unlikely. Still it allows for example easy communication between tasks that should not be able to communicate. Pavel -- Worst form of spam? Adding advertisment signatures ala sourceforge.net. What goes next? Inserting advertisment *into* email?