Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1333863
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 3.10 21/64] parisc: Fix syscall restarts |
| Date | 2016-02-15 00:50 +0100 |
| Message-ID | <r2eAr-1fL-45@gated-at.bofh.it> (permalink) |
| References | <r2dO1-Ir-9@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
3.10-stable review patch. If anyone has any objections, please let me know.
------------------
From: Helge Deller <deller@gmx.de>
commit 71a71fb5374a23be36a91981b5614590b9e722c3 upstream.
On parisc syscalls which are interrupted by signals sometimes failed to
restart and instead returned -ENOSYS which in the worst case lead to
userspace crashes.
A similiar problem existed on MIPS and was fixed by commit e967ef02
("MIPS: Fix restart of indirect syscalls").
On parisc the current syscall restart code assumes that all syscall
callers load the syscall number in the delay slot of the ble
instruction. That's how it is e.g. done in the unistd.h header file:
ble 0x100(%sr2, %r0)
ldi #syscall_nr, %r20
Because of that assumption the current code never restored %r20 before
returning to userspace.
This assumption is at least not true for code which uses the glibc
syscall() function, which instead uses this syntax:
ble 0x100(%sr2, %r0)
copy regX, %r20
where regX depend on how the compiler optimizes the code and register
usage.
This patch fixes this problem by adding code to analyze how the syscall
number is loaded in the delay branch and - if needed - copy the syscall
number to regX prior returning to userspace for the syscall restart.
Signed-off-by: Helge Deller <deller@gmx.de>
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/parisc/kernel/signal.c | 64 +++++++++++++++++++++++++++++++++++---------
1 file changed, 52 insertions(+), 12 deletions(-)
--- a/arch/parisc/kernel/signal.c
+++ b/arch/parisc/kernel/signal.c
@@ -449,6 +449,55 @@ handle_signal(unsigned long sig, siginfo
regs->gr[28]);
}
+/*
+ * Check how the syscall number gets loaded into %r20 within
+ * the delay branch in userspace and adjust as needed.
+ */
+
+static void check_syscallno_in_delay_branch(struct pt_regs *regs)
+{
+ u32 opcode, source_reg;
+ u32 __user *uaddr;
+ int err;
+
+ /* Usually we don't have to restore %r20 (the system call number)
+ * because it gets loaded in the delay slot of the branch external
+ * instruction via the ldi instruction.
+ * In some cases a register-to-register copy instruction might have
+ * been used instead, in which case we need to copy the syscall
+ * number into the source register before returning to userspace.
+ */
+
+ /* A syscall is just a branch, so all we have to do is fiddle the
+ * return pointer so that the ble instruction gets executed again.
+ */
+ regs->gr[31] -= 8; /* delayed branching */
+
+ /* Get assembler opcode of code in delay branch */
+ uaddr = (unsigned int *) ((regs->gr[31] & ~3) + 4);
+ err = get_user(opcode, uaddr);
+ if (err)
+ return;
+
+ /* Check if delay branch uses "ldi int,%r20" */
+ if ((opcode & 0xffff0000) == 0x34140000)
+ return; /* everything ok, just return */
+
+ /* Check if delay branch uses "nop" */
+ if (opcode == INSN_NOP)
+ return;
+
+ /* Check if delay branch uses "copy %rX,%r20" */
+ if ((opcode & 0xffe0ffff) == 0x08000254) {
+ source_reg = (opcode >> 16) & 31;
+ regs->gr[source_reg] = regs->gr[20];
+ return;
+ }
+
+ pr_warn("syscall restart: %s (pid %d): unexpected opcode 0x%08x\n",
+ current->comm, task_pid_nr(current), opcode);
+}
+
static inline void
syscall_restart(struct pt_regs *regs, struct k_sigaction *ka)
{
@@ -471,10 +520,7 @@ syscall_restart(struct pt_regs *regs, st
}
/* fallthrough */
case -ERESTARTNOINTR:
- /* A syscall is just a branch, so all
- * we have to do is fiddle the return pointer.
- */
- regs->gr[31] -= 8; /* delayed branching */
+ check_syscallno_in_delay_branch(regs);
break;
}
}
@@ -523,15 +569,9 @@ insert_restart_trampoline(struct pt_regs
}
case -ERESTARTNOHAND:
case -ERESTARTSYS:
- case -ERESTARTNOINTR: {
- /* Hooray for delayed branching. We don't
- * have to restore %r20 (the system call
- * number) because it gets loaded in the delay
- * slot of the branch external instruction.
- */
- regs->gr[31] -= 8;
+ case -ERESTARTNOINTR:
+ check_syscallno_in_delay_branch(regs);
return;
- }
default:
break;
}
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 3.10 00/64] 3.10.97-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 03/64] crypto: algif_hash - Only export and import on sockets with data Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 31/64] ALSA: rawmidi: Remove kernel WARNING for NULL user-space buffer check Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 55/64] crypto: af_alg - Disallow bind/setkey/... after accept(2) Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 25/64] fix sysvfs symlinks Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 01/64] recordmcount: Fix endianness handling bug for nop_mcount Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 37/64] ALSA: seq: Fix lockdep warnings due to double mutex locks Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 60/64] crypto: algif_hash - wait for crypto_ahash_init() to complete Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 59/64] ahci: Intel DNV device IDs SATA Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 07/64] kernel/signal.c: unexport sigsuspend() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 24/64] [media] media: vb2 dma-contig: Fully cache synchronise buffers in prepare and finish Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 39/64] ALSA: timer: Fix leftover link at closing Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 28/64] ALSA: compress: Disable GET_CODEC_CAPS ioctl for some architectures Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 23/64] [media] v4l2-compat-ioctl32: fix alignment for ARM64 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 05/64] HID: usbhid: fix recursive deadlock Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 57/64] AHCI: Fix softreset failed issue of Port Multiplier Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 04/64] dm btree: fix leak of bufio-backed block in btree_split_sibling error path Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:40 +0100
[PATCH 3.10 16/64] vTPM: fix memory allocation flag for rtce buffer at kernel boot Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:50 +0100
[PATCH 3.10 14/64] wlcore/wl12xx: spi: fix oops on firmware load Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:50 +0100
[PATCH 3.10 15/64] wlcore/wl12xx: spi: fix NULL pointer dereference (Oops) Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:50 +0100
[PATCH 3.10 22/64] parisc: Fix __ARCH_SI_PREAMBLE_SIZE Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:50 +0100
[PATCH 3.10 19/64] [PATCH] fix calculation of meta_bg descriptor backups Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:50 +0100
[PATCH 3.10 18/64] jbd2: Fix unreclaimed pages after truncate in data=journal mode Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:50 +0100
[PATCH 3.10 17/64] mtd: mtdpart: fix add_mtd_partitions error path Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:50 +0100
[PATCH 3.10 12/64] spi: atmel: Fix DMA-setup for transfers with more than 8 bits per word Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:50 +0100
[PATCH 3.10 21/64] parisc: Fix syscall restarts Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:50 +0100
[PATCH 3.10 11/64] Revert "dm mpath: fix stalls when handling invalid ioctls" Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:50 +0100
[PATCH 3.10 13/64] spi: fix parent-device reference leak Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:50 +0100
[PATCH 3.10 02/64] xhci: fix placement of call to usb_disabled() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 00:50 +0100
Re: [PATCH 3.10 00/64] 3.10.97-stable review Guenter Roeck <linux@roeck-us.net> - 2016-02-15 06:30 +0100
Re: [PATCH 3.10 00/64] 3.10.97-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-15 19:20 +0100
Re: [PATCH 3.10 00/64] 3.10.97-stable review Guenter Roeck <linux@roeck-us.net> - 2016-02-15 16:50 +0100
Re: [PATCH 3.10 00/64] 3.10.97-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-02-15 18:20 +0100
Re: [PATCH 3.10 00/64] 3.10.97-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-02-17 21:40 +0100
Re: [PATCH 3.10 00/64] 3.10.97-stable review Willy Tarreau <w@1wt.eu> - 2016-02-18 00:30 +0100
Re: [PATCH 3.10 00/64] 3.10.97-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-02-18 00:40 +0100
Re: [PATCH 3.10 00/64] 3.10.97-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2016-02-18 04:30 +0100
Re: [PATCH 3.10 00/64] 3.10.97-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-19 23:30 +0100
Re: [PATCH 3.10 00/64] 3.10.97-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-02-17 21:40 +0100
csiph-web