4 ms·
I'm confused about this. I think you understand what you're saying. I've seen your RISC-V runtime library. Can you explain in a bit more detail how I navigate
by fuzzybear3965 6y ago
I'm confused about this. I think you understand what you're saying. I've seen your RISC-V runtime library.
Can you explain in a bit more detail how I navigate this randomized table as a syscall user to call the right one? I call socket(), say. And that is mapped to index 12 of the randomized syscall table. How is it found at runtime?
- fwsgonzo 6y agoWhen Linux loads your program it actually puts quite a bit of stuff on the stack. The first thing it puts is the argc followed by an array of argv pointers, followed by a zero. After that it puts the environment variables, followed by a zero. And then it puts the aux-vector, which contains lots of useful things. And that's where you could pass the address of a system call translation/jump table. This aux-vector is already used to enable multi-threading, because it contains the necessary information to create the thread-local storage. One drawback here is that your simple hello-world write/printf in assembly becomes complicated, because you need to get the table address so you can access the write/exit information. As far as what this would help for security, I have no idea, other than making it harder to exploit cases where you don't have a lot of room. We don't hear a lot about all the exploits that didn't happen because of all the extra hoops you have to jump through with each change over the years.