On Wed Mar 19 05:43:39 2025 +0000, Paul Gofman wrote:
Looks like patch subject is a bit misleading? "leaq 0x70(%rcx),%rsp\n\t" doesn't leave kernel stack, maybe "ntdll: Move stack to machine frame before accessing %gs in x86_64 syscall dispatcher."?
Good catch, I think I put that as a placeholder but forgot to update it later.