} else {
bzero(&new_ldt->ldt[start_sel - begin_sel], num_sels * sizeof(struct real_descriptor));
}
-
/*
* Validate descriptors.
* Only allow descriptors with user privileges.
case 0:
case ACC_P:
/* valid empty descriptor, clear Present preemptively */
- dp->access &= ~ACC_P;
+ dp->access &= (~ACC_P & 0xff);
break;
case ACC_P | ACC_PL_U | ACC_DATA:
case ACC_P | ACC_PL_U | ACC_DATA_W:
user_ldt_free(new_ldt);
return EACCES;
}
+ /* Reject attempts to create segments with 64-bit granules */
+ if (dp->granularity & SZ_64) {
+ task_unlock(task);
+ user_ldt_free(new_ldt);
+ return EACCES;
+ }
}
}
unsigned int ldt_count;
kern_return_t err;
- if (start_sel >= 8192)
+ if (start_sel >= LDTSZ)
return EINVAL;
- if ((uint64_t)start_sel + (uint64_t)num_sels > 8192)
+ if ((uint64_t)start_sel + (uint64_t)num_sels > LDTSZ)
return EINVAL;
if (descs == 0)
return EINVAL;
bcopy(user_ldt->ldt, &ldtp[user_ldt->start],
sizeof(struct real_descriptor) * (user_ldt->count));
- gdt_desc_p(USER_LDT)->limit_low = (sizeof(struct real_descriptor) * (user_ldt->start + user_ldt->count)) - 1;
+ gdt_desc_p(USER_LDT)->limit_low = (uint16_t)((sizeof(struct real_descriptor) * (user_ldt->start + user_ldt->count)) - 1);
ml_cpu_set_ldt(USER_LDT);
} else {