tree 498c2612d3bf85513522acb7df8e8ab8398611a0
parent a109221c6e66c040f054ca6db1969aa1b7d2fad4
author Venkatesh Srinivas <venkateshs@google.com> 1601002934 +0000
committer Venkatesh Srinivas <venkateshs@google.com> 1601002934 +0000

Fuchsia: Turn safeside ret2spec tests into a library

ret2spec is a class of Spectre V2-related speculative execution
information leaks, where the contents of return address stacks are
poisoned. Poisoned return address stacks can be used to cause
sensitive code to (speculatively) execute attacker-controlled
code, which can be used as a building block in infoleak attacks.

Ret2spec attacks can be carried out within a process, across
user/kernel boundaries on a CPU, and across processes.

Safeside is a collection of demos of speculative execution
attacks, including ret2spec; we plan to use its demos to test
Fuchsia's speculative execution mitigations.

Convert Safeside's standalone ret2spec demos into a library,
so that Fuchsia-driven tests can use them. We do not have a
test in-tree of ret2spec_ca (cross-address-space), but will adapt
ret2spec_sa into one.

Bug: 12540 Speculative Execution Mitigations.
Bug: 33667 Spectre mitigations?

Change-Id: I239a8ba1f1b73f6ef58b6baa2b1f54ac6f3c3cb3
