Re: [PATCH RFC v9 2/7] x86/entry: Add STACKLEAK erasing the kernel stack at the end of syscalls
From: Dave Hansen
Date: Wed Mar 21 2018 - 11:35:19 EST
On 03/21/2018 04:04 AM, Alexander Popov wrote:
> The main obstacle:
> erase_kstack() must save and restore any modified registers, because it is
> called from the trampoline stack (introduced by Andy Lutomirski), when all
> registers except RDI are live.
Wow, cool, thanks for doing this!
PTI might also cause you some problems here because it probably won't
map your function. Did you have to put it in one of the sections that
gets mapped by the user page tables?