[RFC PATCH 0/7] x86: introduce system calls addess space isolation

Jiri Kosina jikos at kernel.org
Fri Apr 26 08:07:50 UTC 2019


On Thu, 25 Apr 2019, Andy Lutomirski wrote:

> The benefit seems to come from making sure that the RET instruction 
> actually goes somewhere that's already been faulted in.

Which doesn't seem to be really compatible with things like retpolines or 
anyone using FTRACE_WITH_REGS to modify stored instruction pointer.

-- 
Jiri Kosina
SUSE Labs



More information about the Linux-security-module-archive mailing list