by minipli » Tue Jan 25, 2011 3:23 pm
My attempts booting a 2.6.37 PaX kernel (KERNEXEC + UDEREF) only end up in a tripple fault. Here is the qemu register dump:
qemu: fatal: Trying to execute code outside RAM or ROM at 0x0000000002032ec3
EAX=80000011 EBX=00000000 ECX=00000000 EDX=00000000
ESI=00020800 EDI=c2301000 EBP=02900063 ESP=0208db80
EIP=01032ec3 EFL=00000002 [-------] CPL=0 II=0 A20=1 SMM=0 HLT=0
ES =0018 00000000 ffffffff 00cf9300 DPL=0 DS [-WA]
CS =0010 01000000 ffffffff 01cf9b00 DPL=0 CS32 [-RA]
SS =0018 00000000 ffffffff 00cf9300 DPL=0 DS [-WA]
DS =0018 00000000 ffffffff 00cf9300 DPL=0 DS [-WA]
FS =0018 00000000 ffffffff 00cf9300 DPL=0 DS [-WA]
GS =0018 00000000 ffffffff 00cf9300 DPL=0 DS [-WA]
LDT=0000 00000000 00000000 00008200 DPL=0 LDT
TR =0020 00001000 00000067 00008900 DPL=0 TSS32-avl
GDT= 0180d140 0000001f
IDT= 00000000 00000000
CR0=80000011 CR2=00000000 CR3=01c933c0 CR4=00000000
DR0=00000000 DR1=00000000 DR2=00000000 DR3=00000000
DR6=ffff0ff0 DR7=00000400
CCS=00005800 CCD=80000011 CCO=LOGICL
FCW=037f FSW=0000 [ST=0] FTW=00 MXCSR=00001f80
FPR0=0000000000000000 0000 FPR1=0000000000000000 0000
FPR2=0000000000000000 0000 FPR3=0000000000000000 0000
FPR4=0000000000000000 0000 FPR5=0000000000000000 0000
FPR6=0000000000000000 0000 FPR7=0000000000000000 0000
XMM00=00000000000000000000000000000000 XMM01=00000000000000000000000000000000
XMM02=00000000000000000000000000000000 XMM03=00000000000000000000000000000000
XMM04=00000000000000000000000000000000 XMM05=00000000000000000000000000000000
XMM06=00000000000000000000000000000000 XMM07=00000000000000000000000000000000
EIP is at the long jump in arch/x86/kernel/head_32.S:417, objdump vmlinux:
01032e90 <startup_32_smp>:
...
1032ec3: ea ca 2e 03 01 10 00 ljmp $0x10,$0x1032eca
It looks like the machine doesn't like the reloading of the CS segment selector. ... __BOOT_CS broken? :/