Sushi Roll: A CPU research kernel with minimal noise for microarch introspection
gamozolabs.github.io
gamozolabs.github.io
[1] https://old.reddit.com/r/programming/comments/csfj53/sushi_r...
I can only speculate as to the types of vulnerabilities not disclosed.
I used this kernel originally for my vectorized emulator, which is designed as a high-performance fuzzer/harness to find bugs (more info https://gamozolabs.github.io/fuzzing/2018/10/14/vectorized_e...). I used vectorized emulation on Windows DHCP to find multiple RCEs (which were disclosed earlier this year), as well as one of the Intel MDS vulnerabilities (such as RIDL and Fallout) disclosed earlier this year (specifically I found "MLPDS", https://nvd.nist.gov/vuln/detail/CVE-2018-12127).
I do most of my work in a personal kernel as it really gives me an edge with optimization. I'm able to use page tables directly (super fast fork()-like behavior), and write hypervisors that don't have to go through crazy call stacks to vmexit, use bleeding-edge CPU features, etc. Ultimately I just do it because it's fun, but I've found ways to justify it from time to time.
>"These are often complex operations, like switching operating modes, reading/writing internal CPU registers, etc."
Is a switch from ring 3 to ring 0 handled by microcode then? If so why is this?
The reason this was confusing is that we put the earlier post in the second-chance queue (described at https://news.ycombinator.com/item?id=11662380), which temporarily modifies the timestamps on re-up as explained here: https://news.ycombinator.com/item?id=19774614. This confusion comes up periodically but I don't know a globally better solution than how we currently do it.
Also, out of curiosity, how does that work on mobile? I know it's a naive question but I've never figured that out.