Received: by 10.192.165.156 with SMTP id m28csp1736797imm; Wed, 18 Apr 2018 15:05:01 -0700 (PDT) X-Google-Smtp-Source: AIpwx4/j2M1Qj/CkRM80okkg+F0qpu9ngYyQBYR222WcKm0BdFmAwbyaiPtb4nErNhVZUyjf9PPS X-Received: by 2002:a17:902:9042:: with SMTP id w2-v6mr3570603plz.34.1524089101878; Wed, 18 Apr 2018 15:05:01 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1524089101; cv=none; d=google.com; s=arc-20160816; b=PVlr6UHXA50VY/QL8EYn7qdQ5OR1vKVw7dJ5j7wAO0PgfIXAKI0M64+59iEswPpvJD ZSsWmGOEyta7caLvxBgiFfxAEOPeEY75TAwDs8k6DqHehyfBIq+ZN0BJNY48QrYDO6w4 hcwLaHycnqVgDZ2dSgftUgU511GDbOD9mL8poBvGa7VnFNUPj+cckkl/KSSNHTOCJGbe 5jrIAdNXFBe3tj/7tu2JyPYKM9F8rV7Nx2TQj1VxtUCEj+EbM7qYQzFVvj2eu+gZiGx1 j1qWYB+CH/+TBEOqfVtteQnOfjub0vRxDtevMlKXRVOPvhMIJ1ICoqEEf1wSkTzrYtHJ JwUQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:user-agent:in-reply-to :content-disposition:mime-version:references:message-id:subject:cc :to:from:date:dmarc-filter:arc-authentication-results; bh=UvKLgNkLu594Xb89c4GLt/amkA/VTkoCL3u/RdFdz70=; b=u7pSMMNklF3bk637w3y1P6Suan/wtpw2p8ei1PVpfdw9i4IwtV7HZ8HpQzwAcYbEsD YEYlkjkruCrXKqf0mhaubwI6zYbaCwQ0CLj0d9/7AYFXl2PiWcdPLsicsO5ZuYb2qDNm LmN3hxhDloJ/dvmrsCBLgxbniFPhoYWQ/pNFBSSxOCVGIEwXYZf7x7M8VW8eTgkQnu/1 98HoPiN3LM7TZmzHA5n7T4xTqWG1f/lRo5/SrBbpSC593WNsPtQIhzTCijnzdk1ZEPlA ejKRmR3FdUak2DVFrSjZZmDuU2PO2SNne/ocoMw4lVU4D/+WYszluVkYF6037htPXAY4 F85Q== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id p11-v6si2392743plo.276.2018.04.18.15.04.19; Wed, 18 Apr 2018 15:05:01 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752738AbeDRWCo (ORCPT + 99 others); Wed, 18 Apr 2018 18:02:44 -0400 Received: from mail.kernel.org ([198.145.29.99]:44846 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752514AbeDRWCm (ORCPT ); Wed, 18 Apr 2018 18:02:42 -0400 Received: from saruman (jahogan.plus.com [212.159.75.221]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 1549321781; Wed, 18 Apr 2018 22:02:40 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 1549321781 Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=kernel.org Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=jhogan@kernel.org Date: Wed, 18 Apr 2018 23:02:37 +0100 From: James Hogan To: Matt Redfearn Cc: Ralf Baechle , linux-mips@linux-mips.org, stable@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH v2 1/4] MIPS: memset.S: Fix clobber of v1 in last_fixup Message-ID: <20180418220237.GC16439@saruman> References: <1523979603-492-1-git-send-email-matt.redfearn@mips.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="9Ek0hoCL9XbhcSqy" Content-Disposition: inline In-Reply-To: <1523979603-492-1-git-send-email-matt.redfearn@mips.com> User-Agent: Mutt/1.7.2 (2016-11-26) Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org --9Ek0hoCL9XbhcSqy Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Apr 17, 2018 at 04:40:00PM +0100, Matt Redfearn wrote: > The label .Llast_fixup\@ is jumped to on page fault within the final > byte set loop of memset (on < MIPSR6 architectures). For some reason, in > this fault handler, the v1 register is randomly set to a2 & STORMASK. > This clobbers v1 for the calling function. This can be observed with the > following test code: >=20 > static int __init __attribute__((optimize("O0"))) test_clear_user(void) > { > register int t asm("v1"); > char *test; > int j, k; >=20 > pr_info("\n\n\nTesting clear_user\n"); > test =3D vmalloc(PAGE_SIZE); >=20 > for (j =3D 256; j < 512; j++) { > t =3D 0xa5a5a5a5; > if ((k =3D clear_user(test + PAGE_SIZE - 256, j)) !=3D j - 256) { > pr_err("clear_user (%px %d) returned %d\n", test + PAGE_SIZE - 25= 6, j, k); > } > if (t !=3D 0xa5a5a5a5) { > pr_err("v1 was clobbered to 0x%x!\n", t); > } > } >=20 > return 0; > } > late_initcall(test_clear_user); >=20 > Which demonstrates that v1 is indeed clobbered (MIPS64): >=20 > Testing clear_user > v1 was clobbered to 0x1! > v1 was clobbered to 0x2! > v1 was clobbered to 0x3! > v1 was clobbered to 0x4! > v1 was clobbered to 0x5! > v1 was clobbered to 0x6! > v1 was clobbered to 0x7! >=20 > Since the number of bytes that could not be set is already contained in > a2, the andi placing a value in v1 is not necessary and actively > harmful in clobbering v1. >=20 > Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") > Cc: stable@vger.kernel.org > Reported-by: James Hogan > Signed-off-by: Matt Redfearn Thanks, Patches 1 & 2 applied to my fixes branch. Cheers James --9Ek0hoCL9XbhcSqy Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEd80NauSabkiESfLYbAtpk944dnoFAlrXwHwACgkQbAtpk944 dnrHag/+IUrJMlxzFTrTonbr0bNVombMS6zD7ZSDJ/bBAJnm6Y4xE4iTFXOVISXS F4LVlo3zwJNwzTIrjXCb1tMgZPNeqeYykVZ9xyotAtriPQAFcfGyISeyhkTxwb1o B5yXVcpEHdrZIf0QYD5SyAFlUNXD7nDFq421UmdXtEnzNp/6Wgjrak5oGjyNRhu8 1ZiWmL8BlH/Qh0gVSj2RnAsX9VpNkJJ7jWqm52xI32uqU4njbz+iTLt8Y9ulypVO kuArCI3CWgmi+2ABT1xnvil6Vdi/gRW2nH4NzMxJCtMd4NQju88+YnJwMjO5ki9A fOOdzi5C5pm0+ArxnMvfjZR+7JOf7x/c9VAqJdMSiNGCY/FnLMdwMqcZ2B+FEG9q HMMDDizsi4PdCXICHEAREMnDhrSTlUMi+u2ib/uMy3EKuxYIKLIt6Fe7ONe3T+Nh mBMTWs2zzrG6VkhAB5MBD5ksoSw9/uoHFHysJkKzptNeE8sp/0EqLFl7erWk4Ivm 5YH120f8YidC75fNCR6dXdhV15ejPScrwdo1jkEGginVP/rK7WR8LZPjbl8RVRnl HX8qIL76bR8ThEHVopBaY1JhurkmFxaOfrPpMsw4DEMkf3EQgNAW1dBT/lAI6djh BxFZ4jpQA3k4V0+8xOAUi+1EUaGAVKUcuiafdOcO8+Dyg10jQPg= =S1hV -----END PGP SIGNATURE----- --9Ek0hoCL9XbhcSqy--