4 ms·
I really wish people would stop applying the "flat 32-bit" revisionist history to the 386. That wasn't its obvious target, but rather picking up the important "
by StillBored 3y ago
I really wish people would stop applying the "flat 32-bit" revisionist history to the 386. That wasn't its obvious target, but rather picking up the important "capability" arch features which were seen as the future before unix/c/risc/single supervisor/ideas destroyed the previous 30 years of mainframe/minicomputer OS research in things like security.
So, what this article fails to really clarify is that the segment registers were now basically "selector" indexes into tables with base+length (in either pages or bytes) fields, execution permission controls. And these selectors and the GDT/LDT/IDT/TSS/call gates/task gates/etc were all designed to support OSs with a 4 level permissions hierarchy, user/library/driver/kernel (or similar), passing around access selectors which could do things like enforce the size of data structures, etc. And to support this, they added FS/GS so that all the general purpose registers could have their own permissions masks.
Pause for a moment and consider that again, Pointers (capabilities, aka selectors) can have not only a base address, but a hardware enforced limit, along with a permissions model that means a function like strcpy() would be incapable of writing to any memory that wasn't the target buffer or part of its own scratch space. Languages/os's could have enforced that called functions were unable to write to the callers stack, or even possibly run in their own completely separate stack. And that is just the beginning.
So, here nearly 40 years later the industry is still trying to recover from the mistakes of designing OS's and programming languages around flat memory models and simplistic user/supervisor permissions models. The 386 provided hardware assistance for writing OS's features that to this day aren't common.
ex: see CHERI.
- bonzini 3y ago> Pointers (capabilities, aka selectors) can have not only a base address, but a hardware enforced limit There are only 8k possible pointers in the LDT, plus 8k in the GDT. The x86 segmented model isn't really suitable for implementing capabilities.
- StillBored 3y agoSure, 40 years later, but for comparison my computer in 1990 had 1MB ram. Its replacement had 8M iirc a year or two later. I remember in the later 1990's having a problem with my socket7 computer because the caches couldn't physically tag more than 64M of ram, so everything above that was uncached. Linux of the mid 1990's would print a half dozen lines when one typed 'ps'. A limitation of 8 thousand different protection ranges would have been a lot for a program utilizing a few hundred KB of actual data and coming from a system were it was a PITA to access a data structure > 64K. It might not have been enough to do a super fine grained implementation, but it was more than enough for the time period, and had any significant OS's used it in a meaningful way I'm sure it would have been extended when limitations here hit, as was everything else in the following products. Oh, and also one could have reloaded the GDT, or swapped some number of LDTs at some boundary if needed. It wouldn't have really been much more disruptive in the 1980s than switching the page tables on task switch, like every modern OS.
- aforwardslash 3y ago8k LDT descriptors per task. Each LDT table also needed an entry in GDT, limiting the amount of tasks to also another 8k. So 64k descriptors total. Thing is, most ia32 operating systems dont actually use the existing hardware model for multitasking, and instead use simpler approaches that cater to the flat memory model.
- nezirus 3y agoIt been long since I have stopped following grsecurity, but I would not be surprised if segment registers are still used (e.g. Pax UDEREF) https://forums.grsecurity.net/viewtopic.php?f=7&t=3046 https://forums.grsecurity.net/viewtopic.php?f=7&t=3046 https://pax.grsecurity.net/docs/PaXTeam-H2HC12-PaX-kernel-self-protection.pdf https://pax.grsecurity.net/docs/PaXTeam-H2HC12-PaX-kernel-se...
- sweetjuly 3y agoI would be amazed of PaX still used segment registers seeing as they don't really do much in long mode. In fact, they specifically call this out in the description of UDEREF in your second link.
- clausecker 3y agoThe whole segmented protected mode stuff was introduced with the 286 already. The 386 only added FS/GS and grew segments to 32 bits.