From: Karl Mehltretter <kmehltretter@gmail.com>
To: Russell King <linux@armlinux.org.uk>
Cc: Karl Mehltretter <kmehltretter@gmail.com>,
Xie Yuanbin <xieyuanbin1@huawei.com>,
Ard Biesheuvel <ardb@kernel.org>,
Linus Walleij <linusw@kernel.org>,
Robin Murphy <robin.murphy@arm.com>,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org
Subject: [PATCH RESEND] ARM: alignment: fix LSR #32 and ASR #32 offset decoding
Date: Wed, 12 Aug 2026 20:50:57 +0200 [thread overview]
Message-ID: <20260812185057.1573-1-kmehltretter@gmail.com> (raw)
The register-offset form of LDR/STR may apply a shift to Rm. Per
DecodeImmShift() (ARM ARM DDI0406C section A8.4.3, "Pseudocode details
of instruction-specified shifts and rotates"), an imm5 of 0 encodes a
shift of 32 for LSR and ASR; only LSL treats 0 as "no shift", and ROR
with 0 encodes RRX.
do_alignment() special-cases RRX but not LSR or ASR, and IS_SHIFT() does
not filter these encodings out, so the block is entered with
shiftval == 0 and the offset becomes Rm instead of 0 (LSR #32) or the
replicated sign of Rm (ASR #32).
do_alignment_finish_ldst() applies the offset to the base-register
writeback of the post-indexed form, so the emulated access itself uses
the correct faulting address but Rn is left holding the wrong value.
Reproduced on ARM926EJ-S (versatile_defconfig, CONFIG_ALIGNMENT_TRAP=y,
gcc 13.3.0) with a misaligned base and Rm = 0x1000:
ldr r0, [r1], r2, lsr #32 Rn advanced by 0x1000, must be unchanged
ldr r0, [r1], r2, asr #32 Rn advanced by 0x1000, must be unchanged
ldr r0, [r1], r2, asr #32 with Rm negative, Rn must decrease by 1
All three are correct with the patch applied, while a lsr #1 control
case is emulated correctly both before and after.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
---
Resending after two weeks without feedback; add ARM alignment reviewers
to Cc.
arch/arm/mm/alignment.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/arch/arm/mm/alignment.c b/arch/arm/mm/alignment.c
index 812380f30ae3..49045e09ae18 100644
--- a/arch/arm/mm/alignment.c
+++ b/arch/arm/mm/alignment.c
@@ -892,11 +892,17 @@ do_alignment(unsigned long addr, unsigned int fsr, struct pt_regs *regs)
break;
case SHIFT_LSR:
- offset.un >>= shiftval;
+ if (shiftval == 0)
+ offset.un = 0;
+ else
+ offset.un >>= shiftval;
break;
case SHIFT_ASR:
- offset.sn >>= shiftval;
+ if (shiftval == 0)
+ offset.sn >>= 31;
+ else
+ offset.sn >>= shiftval;
break;
case SHIFT_RORRRX:
--
2.39.5 (Apple Git-154)
reply other threads:[~2026-08-12 18:51 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260812185057.1573-1-kmehltretter@gmail.com \
--to=kmehltretter@gmail.com \
--cc=ardb@kernel.org \
--cc=linusw@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux@armlinux.org.uk \
--cc=robin.murphy@arm.com \
--cc=xieyuanbin1@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox