don't leave parts of the bootloader in the kernel's address space
還沒有人認領這個 Issue。
評估
- 難度
- 5/5
- 預估耗時
- 一週以上
- 新手友好度
- 35/100
- Issue 類型
- 重構
- 描述清晰度
- 基本清楚
- 活躍度
- 停滯
- 技術堆疊
- rust
研究方向
首先閱讀 src/binary/level_4_entries.rs 中第一個 512GiB 保留區域附近的程式碼,以及 src/binary/mod.rs 中內容切換和 GDT 對映附近的程式碼。追蹤 kernel 頁表和 Mappings 的建構方式;完成的標準是 bootloader 部分不再留在 kernel 位址空間中、暫時的內容切換對映已獲處理,且 GDT 的位置已公開或可設定。
由索引模型根據 Issue 內容生成。
描述
While implementing finer granular ASLR I came across this comment:
https://github.com/rust-osdev/bootloader/blob/ac46d0455b41c11e5d316348d068df1c495ce0af/src/binary/level_4_entries.rs#L40
We mark the first 512GiB of the address space as unusable for dynamically generated addresses. I think we do this because we identity map the context switch code into kernel memory and this code most likely resides within the first 512GiB of the address space:
https://github.com/rust-osdev/bootloader/blob/a445433010960ec5d8a8b94a85fcac16a00489b5/src/binary/mod.rs#L166-L181
This causes a number of (admittedly small and unlikely) problems:
- The identity mapped pages could overlap with the kernel or other mappings
- We don't expose the identity mapped addresses to the kernel in
Mappings - An attacker could make use of the identity mapped pages to defeat ASLR
- We mark so a lot of usable memory as unusable and because of that we can't check for overlaps because there would be a lot of false positives. We currently just ignore overlaps.
We could probably work around those problems while still mapping parts of the bootloader into the kernel's address space, but I'd like to propose another solution: We use another very short lived page table to do the context switch. This page table would only map a few pages containing code that switches to the kernel's page table. Importantly, we would set the page table up in such a way that the kernel's entrypoint is just after the page table switch instruction, so we don't have to use any code to jump to the kernel, it would simply be the next instruction.
I don't think we could reliably map such code into the bootloader's address space because we'd have to map the code just before the kernel's entrypoint which could be close to bootloader's code, so that's why I want to use a short-lived page table.
We also identity map a GDT into the kernel's address space:
https://github.com/rust-osdev/bootloader/blob/a445433010960ec5d8a8b94a85fcac16a00489b5/src/binary/mod.rs#L183-L193
We should probably make the GDT's location configurable and expose it in Mappings.
I'd be happy to work on a pr for this.
- 主要語言
- Rust
- 星號
- 1.7k
- 分支
- 240
- PR 合併指標
- 30 天內沒有已合併 PR
環境準備
這個專案沒有提供開發容器、Dockerfile 或貢獻指南,環境需要你自己搭建:先看它的 README,通用步驟見我們的新手貢獻指南。
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
rust-osdev/bootloader 的其他 Issue
-
help wanted
難度 3/5 1-2 天 新手友好度 67/100
rust-osdev/bootloader#581 · 2 則留言 ·
-
難度 4/5 3-5 天 新手友好度 35/100
rust-osdev/bootloader#573 · 5 則留言 ·
-
難度 5/5 一週以上 新手友好度 20/100
rust-osdev/bootloader#555 · 2 則留言 ·
-
難度 5/5 一週以上 新手友好度 30/100
rust-osdev/bootloader#534 ·
-
難度 3/5 1-2 天 新手友好度 38/100
rust-osdev/bootloader#525 ·
查看 rust-osdev/bootloader 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 76/100
維護者通常 1 天內回覆
-
bug
難度 2/5 1-3 小時 新手友好度 90/100
維護者通常 1 天內回覆
-
agent:triaged bug bughunt pm:npm priority:p1
難度 2/5 1-3 小時 新手友好度 82/100
SocketDev/socket-patch#464 · 1 則留言 ·
維護者通常 1 天內回覆
-
bug
難度 2/5 1-3 小時 新手友好度 85/100
維護者通常 1 天內回覆
-
bug
難度 2/5 1-3 小時 新手友好度 76/100
維護者通常 1 天內回覆