Demo: Privileged Instructions Fault in User Mode¶
Two tiny assembly programs try to run a privileged instruction -- cli, which disables interrupts, and mov rax, cr3, which reads the page-table base -- from an ordinary process.
Run¶
Each prints first, hits the forbidden instruction, and is killed before second.
The kernel logs the fault:
Now run one again as root:
Ask¶
- There is no check for
clianywhere in the kernel. What refused to run it, then? - Under
sudoit crashes exactly the same way. What does that say about the difference between root and kernel mode? - If a program cannot run privileged instructions itself, how does it ever get privileged work done?