Pull OpenRISC updates from Stafford Horne:
 "One small trivial macro cleanup and one bug fix.

  The bug fix is to fix an unchecked access in our or1k_atomic syscall,
  I am debating if we should just deprecate this as there is minimal
  need for it"

* tag 'for-linus' of https://github.com/openrisc/linux:
  openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
  openrisc: drop unneeded semicolon
This commit is contained in:
Linus Torvalds
2026-08-30 09:26:54 -07:00
2 changed files with 41 additions and 6 deletions

View File

@@ -1223,15 +1223,50 @@ _no_syscall_trace:
*
*/
/* Keep this literal; hi()/lo() can't use the UL-suffixed TASK_SIZE. */
#define OR1K_ATOMIC_ADDR_LIMIT 0x7ffffffc
ENTRY(sys_or1k_atomic)
/* FIXME: This ignores r3 and always does an XCHG */
/* Check both user pointers before accessing them. */
l.movhi r13,hi(OR1K_ATOMIC_ADDR_LIMIT)
l.ori r13,r13,lo(OR1K_ATOMIC_ADDR_LIMIT)
l.sfgtu r4,r13
l.bf 9f
l.nop
l.sfgtu r5,r13
l.bf 9f
l.nop
DISABLE_INTERRUPTS(r17,r19)
l.lwz r29,0(r4)
l.lwz r27,0(r5)
l.sw 0(r4),r27
l.sw 0(r5),r29
10: l.lwz r29,0(r4)
11: l.lwz r27,0(r5)
12: l.sw 0(r4),r27
13: l.sw 0(r5),r29
ENABLE_INTERRUPTS(r17)
l.jr r9
l.or r11,r0,r0
/*
* Either pointer was outside user space, or turned out to be
* unmapped/inaccessible when we actually touched it.
*/
9: l.jr r9
l.addi r11,r0,-EFAULT
.section .fixup, "ax"
14:
ENABLE_INTERRUPTS(r17)
l.j 9b
l.nop
.previous
.section __ex_table, "a"
.long 10b, 14b
.long 11b, 14b
.long 12b, 14b
.long 13b, 14b
.previous
/* ============================================================[ EOF ]=== */

View File

@@ -74,11 +74,11 @@ void local_flush_tlb_all(void)
#define flush_dtlb_page_eir(addr) mtspr(SPR_DTLBEIR, addr)
#define flush_dtlb_page_no_eir(addr) \
mtspr_off(SPR_DTLBMR_BASE(0), DTLB_OFFSET(addr), 0);
mtspr_off(SPR_DTLBMR_BASE(0), DTLB_OFFSET(addr), 0)
#define flush_itlb_page_eir(addr) mtspr(SPR_ITLBEIR, addr)
#define flush_itlb_page_no_eir(addr) \
mtspr_off(SPR_ITLBMR_BASE(0), ITLB_OFFSET(addr), 0);
mtspr_off(SPR_ITLBMR_BASE(0), ITLB_OFFSET(addr), 0)
void local_flush_tlb_page(struct vm_area_struct *vma, unsigned long addr)
{