public inbox for u-boot@lists.denx.de
 help / color / mirror / Atom feed
From: Stefan Roese <sr@denx.de>
To: u-boot@lists.denx.de
Subject: [PATCH 04/26 v6] mips: start.S: avoid overwriting outside gd when clearing global data in stack
Date: Wed,  8 Apr 2020 10:09:20 +0200	[thread overview]
Message-ID: <20200408080942.7694-5-sr@denx.de> (raw)
In-Reply-To: <20200408080942.7694-1-sr@denx.de>

From: Weijie Gao <weijie.gao@mediatek.com>

When setting up initial stack, global data will also be put in the stack,
and being cleared.

The assembler instructions for clearing gd is as follows:

	move	t0, k0
1:
	PTR_S	zero, 0(t0)
	blt	t0, t1, 1b
	 PTR_ADDIU t0, PTRSIZE

t0 is the start address of gd, t1 is the end address of gd (t0 + GD_SIZE).

[PTR_ADDIU t0, PTRSIZE] is in the delay slot of [blt t0, t1, 1b], so it
will be executed before the branch operation.

However the comparison for the BLT instruction is done before executing the
delay slot. This means when the last word just before k1 is cleared, the
loop will continue to run once. This will clear an extra word at k1, which
is outside the global data.

Global data is placed at the top of the stack. If the initial stack is a
SRAM or locked cache, the area outside them may be inaccessible. A write
operation performed in this area may cause an exception.

To solve this, [PTR_ADDIU t0, PTRSIZE] should be placed before the BLT
instruction.

Reviewed-by: Daniel Schwierzeck <daniel.schwierzeck@gmail.com>
Reviewed-by: Stefan Roese <sr@denx.de>
Signed-off-by: Weijie Gao <weijie.gao@mediatek.com>
---
Changes since v3: none

 arch/mips/cpu/start.S | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/arch/mips/cpu/start.S b/arch/mips/cpu/start.S
index f9805fa000..dd93df9e4a 100644
--- a/arch/mips/cpu/start.S
+++ b/arch/mips/cpu/start.S
@@ -71,8 +71,9 @@
 	move	t0, k0
 1:
 	PTR_S	zero, 0(t0)
+	PTR_ADDIU t0, PTRSIZE
 	blt	t0, t1, 1b
-	 PTR_ADDIU t0, PTRSIZE
+	 nop
 
 #if CONFIG_VAL(SYS_MALLOC_F_LEN)
 	PTR_S	sp, GD_MALLOC_BASE(k0)	# gd->malloc_base offset
-- 
2.26.0

  parent reply	other threads:[~2020-04-08  8:09 UTC|newest]

Thread overview: 35+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-04-08  8:09 [PATCH 00/26 v6] Refactor the architecture parts of mt7628 Stefan Roese
2020-04-08  8:09 ` [PATCH 01/26 v6] mips: add support to restore exception vector base before booting linux Stefan Roese
2020-04-08  8:09 ` [PATCH 02/26 v6] mips: mtmips: add predefined i-cache/d-cache size and linesize Stefan Roese
2020-04-08  8:09 ` [PATCH 03/26 v6] mips: add an option to support initialize SRAM for initial stack Stefan Roese
2020-04-08  8:09 ` Stefan Roese [this message]
2020-04-08  8:09 ` [PATCH 05/26 v6] sysreset: add reset controller based reboot driver Stefan Roese
2020-04-08  8:09 ` [PATCH 06/26 v6] mips: mtmips: make use of sysreset-resetctrl for mt7628 soc Stefan Roese
2020-04-08  8:09 ` [PATCH 07/26 v6] configs: enable CONFIG_RESTORE_EXCEPTION_VECTOR_BASE for all mtmips boards Stefan Roese
2020-04-08  8:09 ` [PATCH 08/26 v6] mips: add a mtmips-specific field to architecture-specific global data Stefan Roese
2020-04-08  8:09 ` [PATCH 09/26 v6] mips: add a option to support not reserving malloc space on initial stack Stefan Roese
2020-04-08  8:09 ` [PATCH 10/26 v6] mips: mtmips: rewrite lowlevel codes of mt7628 Stefan Roese
2020-04-08  8:09 ` [PATCH 11/26 v6] dts: mtmips: add alternative pinmux node for uart2 Stefan Roese
2020-04-08  8:09 ` [PATCH 12/26 v6] mips: enable support for appending dtb to spl binary Stefan Roese
2020-04-08  8:09 ` [PATCH 13/26 v6] mips: add an option to enable u_boot_list section for SPL loaders in u-boot-spl.lds Stefan Roese
2020-04-08  8:09 ` [PATCH 14/26 v6] lib: enable lzma decompression support for SPL build Stefan Roese
2020-04-08  8:09 ` [PATCH 15/26 v6] Makefile: add support to generate LZMA compressed u-boot image Stefan Roese
2020-04-08  8:09 ` [PATCH 16/26 v6] tools: binman: add etype file for u-boot-lzma-img Stefan Roese
2020-04-08  8:09 ` [PATCH 17/26 v6] spl: Extract legacy image handling into separate file Stefan Roese
2020-04-08  8:09 ` [PATCH 18/26 v6] spl: spl_legacy: Use IS_ENABLED() to remove #ifdef Stefan Roese
2020-04-08  8:09 ` [PATCH 19/26 v6] spl: spl_nor: Copy image header to local struct Stefan Roese
2020-04-09  7:24   ` Simon Goldschmidt
2020-04-08  8:09 ` [PATCH 20/26 v6] spl: spl_nor: Move legacy image loading into spl_legacy.c Stefan Roese
2020-04-09 18:51   ` Daniel Schwierzeck
2020-04-10  8:02     ` Stefan Roese
2020-04-08  8:09 ` [PATCH 21/26 v6] spl: spl_legacy: Add lzma decompression support for legacy image Stefan Roese
2020-04-08  8:09 ` [PATCH 22/26 v6] spl: spl_legacy: Add cache flush after reading U-Boot image Stefan Roese
2020-04-09  7:29   ` Simon Goldschmidt
2020-04-09  7:43     ` Stefan Roese
2020-04-09 16:47       ` Daniel Schwierzeck
2020-04-10  7:50         ` Stefan Roese
2020-04-09 18:15       ` Simon Goldschmidt
2020-04-08  8:09 ` [PATCH 23/26 v6] mips: mtmips: add SPL support Stefan Roese
2020-04-08  8:09 ` [PATCH 24/26 v6] mips: mtmips: enable SPL for all boards Stefan Roese
2020-04-08  8:09 ` [PATCH 25/26 v6] mips: mtmips: add support for mt7628-rfb Stefan Roese
2020-04-08  8:09 ` [PATCH 26/26 v6] mips: mtmips: Increase CONFIG_SPL_SYS_MALLOC_F_LEN Stefan Roese

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20200408080942.7694-5-sr@denx.de \
    --to=sr@denx.de \
    --cc=u-boot@lists.denx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox