From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.kernel.org ([198.145.29.99]:44846 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752514AbeDRWCm (ORCPT ); Wed, 18 Apr 2018 18:02:42 -0400 Date: Wed, 18 Apr 2018 23:02:37 +0100 From: James Hogan To: Matt Redfearn Cc: Ralf Baechle , linux-mips@linux-mips.org, stable@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH v2 1/4] MIPS: memset.S: Fix clobber of v1 in last_fixup Message-ID: <20180418220237.GC16439@saruman> References: <1523979603-492-1-git-send-email-matt.redfearn@mips.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="9Ek0hoCL9XbhcSqy" Content-Disposition: inline In-Reply-To: <1523979603-492-1-git-send-email-matt.redfearn@mips.com> Sender: stable-owner@vger.kernel.org List-ID: --9Ek0hoCL9XbhcSqy Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Apr 17, 2018 at 04:40:00PM +0100, Matt Redfearn wrote: > The label .Llast_fixup\@ is jumped to on page fault within the final > byte set loop of memset (on < MIPSR6 architectures). For some reason, in > this fault handler, the v1 register is randomly set to a2 & STORMASK. > This clobbers v1 for the calling function. This can be observed with the > following test code: >=20 > static int __init __attribute__((optimize("O0"))) test_clear_user(void) > { > register int t asm("v1"); > char *test; > int j, k; >=20 > pr_info("\n\n\nTesting clear_user\n"); > test =3D vmalloc(PAGE_SIZE); >=20 > for (j =3D 256; j < 512; j++) { > t =3D 0xa5a5a5a5; > if ((k =3D clear_user(test + PAGE_SIZE - 256, j)) !=3D j - 256) { > pr_err("clear_user (%px %d) returned %d\n", test + PAGE_SIZE - 25= 6, j, k); > } > if (t !=3D 0xa5a5a5a5) { > pr_err("v1 was clobbered to 0x%x!\n", t); > } > } >=20 > return 0; > } > late_initcall(test_clear_user); >=20 > Which demonstrates that v1 is indeed clobbered (MIPS64): >=20 > Testing clear_user > v1 was clobbered to 0x1! > v1 was clobbered to 0x2! > v1 was clobbered to 0x3! > v1 was clobbered to 0x4! > v1 was clobbered to 0x5! > v1 was clobbered to 0x6! > v1 was clobbered to 0x7! >=20 > Since the number of bytes that could not be set is already contained in > a2, the andi placing a value in v1 is not necessary and actively > harmful in clobbering v1. >=20 > Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") > Cc: stable@vger.kernel.org > Reported-by: James Hogan > Signed-off-by: Matt Redfearn Thanks, Patches 1 & 2 applied to my fixes branch. Cheers James --9Ek0hoCL9XbhcSqy Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEd80NauSabkiESfLYbAtpk944dnoFAlrXwHwACgkQbAtpk944 dnrHag/+IUrJMlxzFTrTonbr0bNVombMS6zD7ZSDJ/bBAJnm6Y4xE4iTFXOVISXS F4LVlo3zwJNwzTIrjXCb1tMgZPNeqeYykVZ9xyotAtriPQAFcfGyISeyhkTxwb1o B5yXVcpEHdrZIf0QYD5SyAFlUNXD7nDFq421UmdXtEnzNp/6Wgjrak5oGjyNRhu8 1ZiWmL8BlH/Qh0gVSj2RnAsX9VpNkJJ7jWqm52xI32uqU4njbz+iTLt8Y9ulypVO kuArCI3CWgmi+2ABT1xnvil6Vdi/gRW2nH4NzMxJCtMd4NQju88+YnJwMjO5ki9A fOOdzi5C5pm0+ArxnMvfjZR+7JOf7x/c9VAqJdMSiNGCY/FnLMdwMqcZ2B+FEG9q HMMDDizsi4PdCXICHEAREMnDhrSTlUMi+u2ib/uMy3EKuxYIKLIt6Fe7ONe3T+Nh mBMTWs2zzrG6VkhAB5MBD5ksoSw9/uoHFHysJkKzptNeE8sp/0EqLFl7erWk4Ivm 5YH120f8YidC75fNCR6dXdhV15ejPScrwdo1jkEGginVP/rK7WR8LZPjbl8RVRnl HX8qIL76bR8ThEHVopBaY1JhurkmFxaOfrPpMsw4DEMkf3EQgNAW1dBT/lAI6djh BxFZ4jpQA3k4V0+8xOAUi+1EUaGAVKUcuiafdOcO8+Dyg10jQPg= =S1hV -----END PGP SIGNATURE----- --9Ek0hoCL9XbhcSqy--