<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Cyrix coma bug</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Cyrix_coma_bug"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/ext.pygments.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Cyrix_coma_bug rootpage-Cyrix_coma_bug skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Cyrix coma bug</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<style data-mw-deduplicate="TemplateStyles:r1251242444">
/* start https://en.wikipedia.org/ */
.mw-parser-output .ambox{border:1px solid #a2a9b1;border-left:10px solid #36c;background-color:#fbfbfb;box-sizing:border-box}.mw-parser-output .ambox+link+.ambox,.mw-parser-output .ambox+link+style+.ambox,.mw-parser-output .ambox+link+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+style+.ambox,.mw-parser-output .ambox+.mw-empty-elt+link+link+.ambox{margin-top:-1px}html body.mediawiki .mw-parser-output .ambox.mbox-small-left{margin:4px 1em 4px 0;overflow:hidden;width:238px;border-collapse:collapse;font-size:88%;line-height:1.25em}.mw-parser-output .ambox-speedy{border-left:10px solid #b32424;background-color:#fee7e6}.mw-parser-output .ambox-delete{border-left:10px solid #b32424}.mw-parser-output .ambox-content{border-left:10px solid #f28500}.mw-parser-output .ambox-style{border-left:10px solid #fc3}.mw-parser-output .ambox-move{border-left:10px solid #9932cc}.mw-parser-output .ambox-protection{border-left:10px solid #a2a9b1}.mw-parser-output .ambox .mbox-text{border:none;padding:0.25em 0.5em;width:100%}.mw-parser-output .ambox .mbox-image{border:none;padding:2px 0 2px 0.5em;text-align:center}.mw-parser-output .ambox .mbox-imageright{border:none;padding:2px 0.5em 2px 0;text-align:center}.mw-parser-output .ambox .mbox-empty-cell{border:none;padding:0;width:1px}.mw-parser-output .ambox .mbox-image-div{width:52px}@media(min-width:720px){.mw-parser-output .ambox{margin:0 10%}}@media print{body.ns-0 .mw-parser-output .ambox{display:none!important}}
/* end https://en.wikipedia.org/ */
</style>
<p>The <b>Cyrix coma bug</b> is a <a href="Design_flaw" class="mw-redirect" title="Design flaw">design flaw</a> in <a href="Cyrix" title="Cyrix">Cyrix</a> <a href="6x86" class="mw-redirect" title="6x86">6x86</a> (introduced in 1996), <a href="6x86L" class="mw-redirect" title="6x86L">6x86L</a>, and early <a href="6x86MX" class="mw-redirect" title="6x86MX">6x86MX</a> <a href="Central_processing_unit" title="Central processing unit">processors</a> that allows a <a href="Privilege_(computing)" title="Privilege (computing)">non-privileged</a> program to <a href="Hang_(computing)" title="Hang (computing)">hang</a> the computer.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Discovery">Discovery</h2></div>
<p>According to Andrew Balsa, around the time of the discovery of the <a href="Pentium_F00F_bug" title="Pentium F00F bug">F00F bug</a> on <a href="Intel" title="Intel">Intel</a> <a href="Intel_P5" class="mw-redirect" title="Intel P5">Pentium</a>, Serguei Shtyliov from <a href="Moscow" title="Moscow">Moscow</a> found a flaw in a <a href="Cyrix" title="Cyrix">Cyrix</a> processor while developing an <a href="Advanced_Technology_Attachment" class="mw-redirect" title="Advanced Technology Attachment">IDE</a> disk driver in <a href="Assembly_language" title="Assembly language">assembly language</a>. Alexandr Konosevich, from <a href="Omsk" title="Omsk">Omsk</a>, further researched the bug and coauthored an article with Uwe Post in the <a href="German_language" title="German language">German</a> technology magazine <i><a href="C't" title="C't">c't</a></i>, calling it the "hidden CLI bug" (CLI is the instruction that disables <a href="Interrupt" title="Interrupt">interrupts</a> in the <a href="X86" title="X86">x86</a> architecture). Balsa, as a member on the <a href="Linux_kernel_mailing_list" title="Linux kernel mailing list">Linux kernel mailing list</a>, confirmed that the following <a href="C_(programming_language)" title="C (programming language)">C</a> program (which uses inline <a href="X86" title="X86">x86</a>-specific <a href="Assembly_language" title="Assembly language">assembly language</a>) could be compiled and run by an <a href="Privilege_(computing)" title="Privilege (computing)">unprivileged</a> user:
</p>
<div class="mw-highlight mw-highlight-lang-c mw-content-ltr" dir="ltr"><pre><span class="kt">unsigned</span><span class="w"> </span><span class="kt">char</span><span class="w"> </span><span class="n">c</span><span class="p">[</span><span class="mi">4</span><span class="p">]</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">{</span><span class="mh">0x36</span><span class="p">,</span><span class="w"> </span><span class="mh">0x78</span><span class="p">,</span><span class="w"> </span><span class="mh">0x38</span><span class="p">,</span><span class="w"> </span><span class="mh">0x36</span><span class="p">};</span>
<span class="kt">int</span><span class="w"> </span><span class="nf">main</span><span class="p">()</span>
<span class="p">{</span>
<span class="w"> </span><span class="k">asm</span><span class="w"> </span><span class="p">(</span>
<span class="w"> </span><span class="s">" movl $c, %ebx</span><span class="se">\n</span><span class="s">"</span>
<span class="w"> </span><span class="s">"again: xchgl (%ebx), %eax</span><span class="se">\n</span><span class="s">"</span>
<span class="w"> </span><span class="s">" movl %eax, %edx</span><span class="se">\n</span><span class="s">"</span>
<span class="w"> </span><span class="s">" jmp again</span><span class="se">\n</span><span class="s">"</span>
<span class="w"> </span><span class="p">);</span>
<span class="p">}</span>
</pre></div>
<p>Execution of this program renders the processor completely useless until it is rebooted, as it enters an <a href="Infinite_loop" title="Infinite loop">infinite loop</a> that cannot be <a href="Interrupt" title="Interrupt">interrupted</a>. This allows any user with access to a Cyrix system with this bug to perform a <a href="Denial-of-service_attack" title="Denial-of-service attack">denial-of-service attack</a>.
</p><p>It is similar to execution of a <a href="Halt_and_Catch_Fire_(computing)" title="Halt and Catch Fire (computing)">Halt and Catch Fire</a> instruction, although the coma bug is not any one particular instruction.
</p>
<div class="mw-heading mw-heading2"><h2 id="Analysis">Analysis</h2></div>
<p>What causes the bug is not an <a href="Interrupt" title="Interrupt">interrupt</a> mask, nor are interrupts being explicitly disabled. Instead, an anomaly in the Cyrix's <a href="Instruction_pipeline" class="mw-redirect" title="Instruction pipeline">instruction pipeline</a> prevents interrupts from being serviced for the duration of the loop; since the loop never ends, interrupts will never be serviced. The <b>xchg</b><sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> instruction is <a href="Atomic_operation" class="mw-redirect" title="Atomic operation">atomic</a>, meaning that other instructions are not allowed to change the state of the system while it is executed. In order to ensure this atomicity, the designers at Cyrix made the <b>xchg</b> uninterruptible. Due to <a href="Instruction_pipeline" class="mw-redirect" title="Instruction pipeline">pipelining</a> and <a href="Branch_predictor" title="Branch predictor">branch predicting</a>, however, another <b>xchg</b> enters the pipeline before the previous one completes, causing a <a href="Deadlock_(computer_science)" title="Deadlock (computer science)">deadlock</a>.
</p>
<div class="mw-heading mw-heading2"><h2 id="Workarounds">Workarounds</h2></div>
<p>A fix for unintentional instances of the bug is to insert another instruction in the loop, the <b><a href="NOP_(code)" title="NOP (code)">nop</a></b> instruction being a good candidate. Cyrix suggested serializing the xchg opcode, thus bypassing the pipeline. However, these techniques will not serve to prevent deliberate attacks.
</p><p>One can also prevent the bug by disabling implicit bus locking normally done by <b>xchg</b> instruction. This is accomplished by setting bit four (mask of <code>0x10</code>) in the configuration register, <code>CCR1</code>.
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Pentium_F00F_bug" title="Pentium F00F bug">Pentium F00F bug</a></li>
<li><a href="Halt_and_Catch_Fire_(computing)" title="Halt and Catch Fire (computing)">Halt and Catch Fire</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="Notes">Notes</h2></div>
<div class="mw-references-wrap"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-1">^</a></b></span> <span class="reference-text"><b>xchgl</b> in the source code means Exchange (<a href="Long_integer" class="mw-redirect" title="Long integer">Long</a>)</span>
</li>
</ol></div>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li><a rel="nofollow" class="external text" href="https://web.archive.org/web/20130720222634/http://gwyn.tux.org/~balsa/linux/cyrix/p11.html">Andrew Balsa's early description of the bug</a></li>
<li><a rel="nofollow" class="external text" href="https://web.archive.org/web/20090928041114/http://grafi.ii.pw.edu.pl/grafi1/gbm/x86/6x86reg.html">Cx6x86 registers</a> (and undocumented features)</li></ul></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2024-10-21" href="https://en.wikipedia.org/wiki/?title=Cyrix_coma_bug&oldid=1252383702">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
</body></html>