git: 281ad195bd42 - stable/13 - x86: Mark the trapframe as initialized in ipi_bitmap_handler()
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Mon, 01 Nov 2021 14:33:12 UTC
The branch stable/13 has been updated by markj:
URL: https://cgit.FreeBSD.org/src/commit/?id=281ad195bd42fa2dbb503c7b55b9108615e83d79
commit 281ad195bd42fa2dbb503c7b55b9108615e83d79
Author: Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2021-07-10 00:38:18 +0000
Commit: Mark Johnston <markj@FreeBSD.org>
CommitDate: 2021-11-01 14:06:57 +0000
x86: Mark the trapframe as initialized in ipi_bitmap_handler()
Otherwise KASAN may generate false positives if the trapframe was
written into a poisoned region of the stack.
Reported by: pho
Reported by: syzbot+ee60455cd58e6eed20c9@syzkaller.appspotmail.com
Reported by: syzbot+be5f9df26426ace3a00c@syzkaller.appspotmail.com
Sponsored by: The FreeBSD Foundation
(cherry picked from commit 36226163fa48ee2c5f73bd2e870ce2e5a057f42e)
---
sys/x86/x86/mp_x86.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/sys/x86/x86/mp_x86.c b/sys/x86/x86/mp_x86.c
index 255a6c13f025..ca1125886619 100644
--- a/sys/x86/x86/mp_x86.c
+++ b/sys/x86/x86/mp_x86.c
@@ -42,6 +42,7 @@ __FBSDID("$FreeBSD$");
#include <sys/param.h>
#include <sys/systm.h>
+#include <sys/asan.h>
#include <sys/bus.h>
#include <sys/cons.h> /* cngetc() */
#include <sys/cpuset.h>
@@ -1282,6 +1283,8 @@ ipi_bitmap_handler(struct trapframe frame)
int cpu = PCPU_GET(cpuid);
u_int ipi_bitmap;
+ kasan_mark(&frame, sizeof(frame), sizeof(frame), 0);
+
td = curthread;
ipi_bitmap = atomic_readandclear_int(&cpuid_to_pcpu[cpu]->
pc_ipi_bitmap);