2019-06-04 16:11:33 +08:00
|
|
|
// SPDX-License-Identifier: GPL-2.0-only
|
2005-04-17 06:20:36 +08:00
|
|
|
/*
|
|
|
|
* linux/arch/arm/kernel/signal.c
|
|
|
|
*
|
2009-10-25 23:39:37 +08:00
|
|
|
* Copyright (C) 1995-2009 Russell King
|
2005-04-17 06:20:36 +08:00
|
|
|
*/
|
|
|
|
#include <linux/errno.h>
|
2013-07-24 07:29:18 +08:00
|
|
|
#include <linux/random.h>
|
2005-04-17 06:20:36 +08:00
|
|
|
#include <linux/signal.h>
|
|
|
|
#include <linux/personality.h>
|
2008-09-06 18:35:55 +08:00
|
|
|
#include <linux/uaccess.h>
|
2009-09-09 15:30:21 +08:00
|
|
|
#include <linux/tracehook.h>
|
2014-03-08 00:23:04 +08:00
|
|
|
#include <linux/uprobes.h>
|
2017-09-07 23:30:46 +08:00
|
|
|
#include <linux/syscalls.h>
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2006-11-09 22:20:47 +08:00
|
|
|
#include <asm/elf.h>
|
2005-04-17 06:20:36 +08:00
|
|
|
#include <asm/cacheflush.h>
|
2013-07-24 07:29:18 +08:00
|
|
|
#include <asm/traps.h>
|
2005-04-17 06:20:36 +08:00
|
|
|
#include <asm/unistd.h>
|
2010-04-11 22:58:27 +08:00
|
|
|
#include <asm/vfp.h>
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2017-08-10 11:42:51 +08:00
|
|
|
#include "signal.h"
|
|
|
|
|
|
|
|
extern const unsigned long sigreturn_codes[17];
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2013-07-24 07:29:18 +08:00
|
|
|
static unsigned long signal_return_offset;
|
|
|
|
|
2006-06-28 05:56:18 +08:00
|
|
|
#ifdef CONFIG_CRUNCH
|
2009-08-05 06:20:45 +08:00
|
|
|
static int preserve_crunch_context(struct crunch_sigframe __user *frame)
|
2006-06-28 05:56:18 +08:00
|
|
|
{
|
|
|
|
char kbuf[sizeof(*frame) + 8];
|
|
|
|
struct crunch_sigframe *kframe;
|
|
|
|
|
|
|
|
/* the crunch context must be 64 bit aligned */
|
|
|
|
kframe = (struct crunch_sigframe *)((unsigned long)(kbuf + 8) & ~7);
|
|
|
|
kframe->magic = CRUNCH_MAGIC;
|
|
|
|
kframe->size = CRUNCH_STORAGE_SIZE;
|
|
|
|
crunch_task_copy(current_thread_info(), &kframe->storage);
|
|
|
|
return __copy_to_user(frame, kframe, sizeof(*frame));
|
|
|
|
}
|
|
|
|
|
2017-07-01 01:56:59 +08:00
|
|
|
static int restore_crunch_context(char __user **auxp)
|
2006-06-28 05:56:18 +08:00
|
|
|
{
|
2017-07-01 01:56:59 +08:00
|
|
|
struct crunch_sigframe __user *frame =
|
|
|
|
(struct crunch_sigframe __user *)*auxp;
|
2006-06-28 05:56:18 +08:00
|
|
|
char kbuf[sizeof(*frame) + 8];
|
|
|
|
struct crunch_sigframe *kframe;
|
|
|
|
|
|
|
|
/* the crunch context must be 64 bit aligned */
|
|
|
|
kframe = (struct crunch_sigframe *)((unsigned long)(kbuf + 8) & ~7);
|
|
|
|
if (__copy_from_user(kframe, frame, sizeof(*frame)))
|
|
|
|
return -1;
|
|
|
|
if (kframe->magic != CRUNCH_MAGIC ||
|
|
|
|
kframe->size != CRUNCH_STORAGE_SIZE)
|
|
|
|
return -1;
|
2017-07-01 01:56:59 +08:00
|
|
|
*auxp += CRUNCH_STORAGE_SIZE;
|
2006-06-28 05:56:18 +08:00
|
|
|
crunch_task_restore(current_thread_info(), &kframe->storage);
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
#ifdef CONFIG_IWMMXT
|
|
|
|
|
2017-07-01 01:56:09 +08:00
|
|
|
static int preserve_iwmmxt_context(struct iwmmxt_sigframe __user *frame)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
[PATCH] mm: arm ready for split ptlock
Prepare arm for the split page_table_lock: three issues.
Signal handling's preserve and restore of iwmmxt context currently involves
reading and writing that context to and from user space, while holding
page_table_lock to secure the user page(s) against kswapd. If we split the
lock, then the structure might span two pages, secured by to read into and
write from a kernel stack buffer, copying that out and in without locking (the
structure is 160 bytes in size, and here we're near the top of the kernel
stack). Or would the overhead be noticeable?
arm_syscall's cmpxchg emulation use pte_offset_map_lock, instead of
pte_offset_map and mm-wide page_table_lock; and strictly, it should now also
take mmap_sem before descending to pmd, to guard against another thread
munmapping, and the page table pulled out beneath this thread.
Updated two comments in fault-armv.c. adjust_pte is interesting, since its
modification of a pte in one part of the mm depends on the lock held when
calling update_mmu_cache for a pte in some other part of that mm. This can't
be done with a split page_table_lock (and we've already taken the lowest lock
in the hierarchy here): so we'll have to disable split on arm, unless
CONFIG_CPU_CACHE_VIPT to ensures adjust_pte never used.
Signed-off-by: Hugh Dickins <hugh@veritas.com>
Signed-off-by: Andrew Morton <akpm@osdl.org>
Signed-off-by: Linus Torvalds <torvalds@osdl.org>
2005-10-30 09:16:36 +08:00
|
|
|
char kbuf[sizeof(*frame) + 8];
|
|
|
|
struct iwmmxt_sigframe *kframe;
|
2017-07-01 01:56:59 +08:00
|
|
|
int err = 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* the iWMMXt context must be 64 bit aligned */
|
[PATCH] mm: arm ready for split ptlock
Prepare arm for the split page_table_lock: three issues.
Signal handling's preserve and restore of iwmmxt context currently involves
reading and writing that context to and from user space, while holding
page_table_lock to secure the user page(s) against kswapd. If we split the
lock, then the structure might span two pages, secured by to read into and
write from a kernel stack buffer, copying that out and in without locking (the
structure is 160 bytes in size, and here we're near the top of the kernel
stack). Or would the overhead be noticeable?
arm_syscall's cmpxchg emulation use pte_offset_map_lock, instead of
pte_offset_map and mm-wide page_table_lock; and strictly, it should now also
take mmap_sem before descending to pmd, to guard against another thread
munmapping, and the page table pulled out beneath this thread.
Updated two comments in fault-armv.c. adjust_pte is interesting, since its
modification of a pte in one part of the mm depends on the lock held when
calling update_mmu_cache for a pte in some other part of that mm. This can't
be done with a split page_table_lock (and we've already taken the lowest lock
in the hierarchy here): so we'll have to disable split on arm, unless
CONFIG_CPU_CACHE_VIPT to ensures adjust_pte never used.
Signed-off-by: Hugh Dickins <hugh@veritas.com>
Signed-off-by: Andrew Morton <akpm@osdl.org>
Signed-off-by: Linus Torvalds <torvalds@osdl.org>
2005-10-30 09:16:36 +08:00
|
|
|
kframe = (struct iwmmxt_sigframe *)((unsigned long)(kbuf + 8) & ~7);
|
2017-07-01 01:56:59 +08:00
|
|
|
|
|
|
|
if (test_thread_flag(TIF_USING_IWMMXT)) {
|
|
|
|
kframe->magic = IWMMXT_MAGIC;
|
|
|
|
kframe->size = IWMMXT_STORAGE_SIZE;
|
|
|
|
iwmmxt_task_copy(current_thread_info(), &kframe->storage);
|
|
|
|
} else {
|
|
|
|
/*
|
|
|
|
* For bug-compatibility with older kernels, some space
|
|
|
|
* has to be reserved for iWMMXt even if it's not used.
|
|
|
|
* Set the magic and size appropriately so that properly
|
|
|
|
* written userspace can skip it reliably:
|
|
|
|
*/
|
2018-09-11 17:12:05 +08:00
|
|
|
*kframe = (struct iwmmxt_sigframe) {
|
|
|
|
.magic = DUMMY_MAGIC,
|
|
|
|
.size = IWMMXT_STORAGE_SIZE,
|
|
|
|
};
|
2017-07-01 01:56:59 +08:00
|
|
|
}
|
|
|
|
|
2018-09-11 17:12:05 +08:00
|
|
|
err = __copy_to_user(frame, kframe, sizeof(*kframe));
|
|
|
|
|
2017-07-01 01:56:59 +08:00
|
|
|
return err;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2017-07-01 01:56:59 +08:00
|
|
|
static int restore_iwmmxt_context(char __user **auxp)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2017-07-01 01:56:59 +08:00
|
|
|
struct iwmmxt_sigframe __user *frame =
|
|
|
|
(struct iwmmxt_sigframe __user *)*auxp;
|
[PATCH] mm: arm ready for split ptlock
Prepare arm for the split page_table_lock: three issues.
Signal handling's preserve and restore of iwmmxt context currently involves
reading and writing that context to and from user space, while holding
page_table_lock to secure the user page(s) against kswapd. If we split the
lock, then the structure might span two pages, secured by to read into and
write from a kernel stack buffer, copying that out and in without locking (the
structure is 160 bytes in size, and here we're near the top of the kernel
stack). Or would the overhead be noticeable?
arm_syscall's cmpxchg emulation use pte_offset_map_lock, instead of
pte_offset_map and mm-wide page_table_lock; and strictly, it should now also
take mmap_sem before descending to pmd, to guard against another thread
munmapping, and the page table pulled out beneath this thread.
Updated two comments in fault-armv.c. adjust_pte is interesting, since its
modification of a pte in one part of the mm depends on the lock held when
calling update_mmu_cache for a pte in some other part of that mm. This can't
be done with a split page_table_lock (and we've already taken the lowest lock
in the hierarchy here): so we'll have to disable split on arm, unless
CONFIG_CPU_CACHE_VIPT to ensures adjust_pte never used.
Signed-off-by: Hugh Dickins <hugh@veritas.com>
Signed-off-by: Andrew Morton <akpm@osdl.org>
Signed-off-by: Linus Torvalds <torvalds@osdl.org>
2005-10-30 09:16:36 +08:00
|
|
|
char kbuf[sizeof(*frame) + 8];
|
|
|
|
struct iwmmxt_sigframe *kframe;
|
|
|
|
|
|
|
|
/* the iWMMXt context must be 64 bit aligned */
|
|
|
|
kframe = (struct iwmmxt_sigframe *)((unsigned long)(kbuf + 8) & ~7);
|
|
|
|
if (__copy_from_user(kframe, frame, sizeof(*frame)))
|
|
|
|
return -1;
|
2017-07-01 01:56:59 +08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* For non-iWMMXt threads: a single iwmmxt_sigframe-sized dummy
|
|
|
|
* block is discarded for compatibility with setup_sigframe() if
|
|
|
|
* present, but we don't mandate its presence. If some other
|
|
|
|
* magic is here, it's not for us:
|
|
|
|
*/
|
|
|
|
if (!test_thread_flag(TIF_USING_IWMMXT) &&
|
|
|
|
kframe->magic != DUMMY_MAGIC)
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
if (kframe->size != IWMMXT_STORAGE_SIZE)
|
[PATCH] mm: arm ready for split ptlock
Prepare arm for the split page_table_lock: three issues.
Signal handling's preserve and restore of iwmmxt context currently involves
reading and writing that context to and from user space, while holding
page_table_lock to secure the user page(s) against kswapd. If we split the
lock, then the structure might span two pages, secured by to read into and
write from a kernel stack buffer, copying that out and in without locking (the
structure is 160 bytes in size, and here we're near the top of the kernel
stack). Or would the overhead be noticeable?
arm_syscall's cmpxchg emulation use pte_offset_map_lock, instead of
pte_offset_map and mm-wide page_table_lock; and strictly, it should now also
take mmap_sem before descending to pmd, to guard against another thread
munmapping, and the page table pulled out beneath this thread.
Updated two comments in fault-armv.c. adjust_pte is interesting, since its
modification of a pte in one part of the mm depends on the lock held when
calling update_mmu_cache for a pte in some other part of that mm. This can't
be done with a split page_table_lock (and we've already taken the lowest lock
in the hierarchy here): so we'll have to disable split on arm, unless
CONFIG_CPU_CACHE_VIPT to ensures adjust_pte never used.
Signed-off-by: Hugh Dickins <hugh@veritas.com>
Signed-off-by: Andrew Morton <akpm@osdl.org>
Signed-off-by: Linus Torvalds <torvalds@osdl.org>
2005-10-30 09:16:36 +08:00
|
|
|
return -1;
|
2017-07-01 01:56:59 +08:00
|
|
|
|
|
|
|
if (test_thread_flag(TIF_USING_IWMMXT)) {
|
|
|
|
if (kframe->magic != IWMMXT_MAGIC)
|
|
|
|
return -1;
|
|
|
|
|
|
|
|
iwmmxt_task_restore(current_thread_info(), &kframe->storage);
|
|
|
|
}
|
|
|
|
|
|
|
|
*auxp += IWMMXT_STORAGE_SIZE;
|
[PATCH] mm: arm ready for split ptlock
Prepare arm for the split page_table_lock: three issues.
Signal handling's preserve and restore of iwmmxt context currently involves
reading and writing that context to and from user space, while holding
page_table_lock to secure the user page(s) against kswapd. If we split the
lock, then the structure might span two pages, secured by to read into and
write from a kernel stack buffer, copying that out and in without locking (the
structure is 160 bytes in size, and here we're near the top of the kernel
stack). Or would the overhead be noticeable?
arm_syscall's cmpxchg emulation use pte_offset_map_lock, instead of
pte_offset_map and mm-wide page_table_lock; and strictly, it should now also
take mmap_sem before descending to pmd, to guard against another thread
munmapping, and the page table pulled out beneath this thread.
Updated two comments in fault-armv.c. adjust_pte is interesting, since its
modification of a pte in one part of the mm depends on the lock held when
calling update_mmu_cache for a pte in some other part of that mm. This can't
be done with a split page_table_lock (and we've already taken the lowest lock
in the hierarchy here): so we'll have to disable split on arm, unless
CONFIG_CPU_CACHE_VIPT to ensures adjust_pte never used.
Signed-off-by: Hugh Dickins <hugh@veritas.com>
Signed-off-by: Andrew Morton <akpm@osdl.org>
Signed-off-by: Linus Torvalds <torvalds@osdl.org>
2005-10-30 09:16:36 +08:00
|
|
|
return 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
#endif
|
|
|
|
|
2010-04-11 22:58:27 +08:00
|
|
|
#ifdef CONFIG_VFP
|
|
|
|
|
|
|
|
static int preserve_vfp_context(struct vfp_sigframe __user *frame)
|
|
|
|
{
|
2018-09-11 17:12:18 +08:00
|
|
|
struct vfp_sigframe kframe;
|
2010-04-11 22:58:27 +08:00
|
|
|
int err = 0;
|
|
|
|
|
2018-09-11 17:12:18 +08:00
|
|
|
memset(&kframe, 0, sizeof(kframe));
|
|
|
|
kframe.magic = VFP_MAGIC;
|
|
|
|
kframe.size = VFP_STORAGE_SIZE;
|
2010-04-11 22:58:27 +08:00
|
|
|
|
2018-09-11 17:12:18 +08:00
|
|
|
err = vfp_preserve_user_clear_hwstate(&kframe.ufp, &kframe.ufp_exc);
|
2012-04-23 22:38:28 +08:00
|
|
|
if (err)
|
2018-09-11 17:12:18 +08:00
|
|
|
return err;
|
2012-04-23 22:38:28 +08:00
|
|
|
|
2018-09-11 17:12:18 +08:00
|
|
|
return __copy_to_user(frame, &kframe, sizeof(kframe));
|
2010-04-11 22:58:27 +08:00
|
|
|
}
|
|
|
|
|
2017-07-01 01:56:59 +08:00
|
|
|
static int restore_vfp_context(char __user **auxp)
|
2010-04-11 22:58:27 +08:00
|
|
|
{
|
2018-07-09 17:13:36 +08:00
|
|
|
struct vfp_sigframe frame;
|
|
|
|
int err;
|
2010-04-11 22:58:27 +08:00
|
|
|
|
2018-07-09 17:13:36 +08:00
|
|
|
err = __copy_from_user(&frame, *auxp, sizeof(frame));
|
2010-04-11 22:58:27 +08:00
|
|
|
if (err)
|
2018-07-09 17:13:36 +08:00
|
|
|
return err;
|
|
|
|
|
|
|
|
if (frame.magic != VFP_MAGIC || frame.size != VFP_STORAGE_SIZE)
|
2010-04-11 22:58:27 +08:00
|
|
|
return -EINVAL;
|
|
|
|
|
2018-07-09 17:13:36 +08:00
|
|
|
*auxp += sizeof(frame);
|
|
|
|
return vfp_restore_user_hwstate(&frame.ufp, &frame.ufp_exc);
|
2010-04-11 22:58:27 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
#endif
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/*
|
|
|
|
* Do a signal return; undo the signal stack. These are aligned to 64-bit.
|
|
|
|
*/
|
|
|
|
|
2006-06-16 03:23:02 +08:00
|
|
|
static int restore_sigframe(struct pt_regs *regs, struct sigframe __user *sf)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2018-07-09 17:05:22 +08:00
|
|
|
struct sigcontext context;
|
2017-07-01 01:56:59 +08:00
|
|
|
char __user *aux;
|
2006-06-16 03:23:02 +08:00
|
|
|
sigset_t set;
|
|
|
|
int err;
|
|
|
|
|
|
|
|
err = __copy_from_user(&set, &sf->uc.uc_sigmask, sizeof(set));
|
2012-04-28 01:58:59 +08:00
|
|
|
if (err == 0)
|
2012-03-06 07:05:34 +08:00
|
|
|
set_current_blocked(&set);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2018-07-09 17:05:22 +08:00
|
|
|
err |= __copy_from_user(&context, &sf->uc.uc_mcontext, sizeof(context));
|
|
|
|
if (err == 0) {
|
|
|
|
regs->ARM_r0 = context.arm_r0;
|
|
|
|
regs->ARM_r1 = context.arm_r1;
|
|
|
|
regs->ARM_r2 = context.arm_r2;
|
|
|
|
regs->ARM_r3 = context.arm_r3;
|
|
|
|
regs->ARM_r4 = context.arm_r4;
|
|
|
|
regs->ARM_r5 = context.arm_r5;
|
|
|
|
regs->ARM_r6 = context.arm_r6;
|
|
|
|
regs->ARM_r7 = context.arm_r7;
|
|
|
|
regs->ARM_r8 = context.arm_r8;
|
|
|
|
regs->ARM_r9 = context.arm_r9;
|
|
|
|
regs->ARM_r10 = context.arm_r10;
|
|
|
|
regs->ARM_fp = context.arm_fp;
|
|
|
|
regs->ARM_ip = context.arm_ip;
|
|
|
|
regs->ARM_sp = context.arm_sp;
|
|
|
|
regs->ARM_lr = context.arm_lr;
|
|
|
|
regs->ARM_pc = context.arm_pc;
|
|
|
|
regs->ARM_cpsr = context.arm_cpsr;
|
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
err |= !valid_user_regs(regs);
|
|
|
|
|
2017-07-01 01:56:59 +08:00
|
|
|
aux = (char __user *) sf->uc.uc_regspace;
|
2006-06-28 05:56:18 +08:00
|
|
|
#ifdef CONFIG_CRUNCH
|
|
|
|
if (err == 0)
|
2017-07-01 01:56:59 +08:00
|
|
|
err |= restore_crunch_context(&aux);
|
2006-06-28 05:56:18 +08:00
|
|
|
#endif
|
2005-04-17 06:20:36 +08:00
|
|
|
#ifdef CONFIG_IWMMXT
|
2017-07-01 01:56:59 +08:00
|
|
|
if (err == 0)
|
|
|
|
err |= restore_iwmmxt_context(&aux);
|
2005-04-17 06:20:36 +08:00
|
|
|
#endif
|
|
|
|
#ifdef CONFIG_VFP
|
2010-04-11 22:58:27 +08:00
|
|
|
if (err == 0)
|
2017-07-01 01:56:59 +08:00
|
|
|
err |= restore_vfp_context(&aux);
|
2005-04-17 06:20:36 +08:00
|
|
|
#endif
|
|
|
|
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
|
|
|
|
asmlinkage int sys_sigreturn(struct pt_regs *regs)
|
|
|
|
{
|
|
|
|
struct sigframe __user *frame;
|
|
|
|
|
|
|
|
/* Always make any pending restarted system calls return -EINTR */
|
2015-02-13 07:01:14 +08:00
|
|
|
current->restart_block.fn = do_no_restart_syscall;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Since we stacked the signal on a 64-bit boundary,
|
|
|
|
* then 'sp' should be word aligned here. If it's
|
|
|
|
* not, then the user is trying to mess with us.
|
|
|
|
*/
|
|
|
|
if (regs->ARM_sp & 7)
|
|
|
|
goto badframe;
|
|
|
|
|
|
|
|
frame = (struct sigframe __user *)regs->ARM_sp;
|
|
|
|
|
Remove 'type' argument from access_ok() function
Nobody has actually used the type (VERIFY_READ vs VERIFY_WRITE) argument
of the user address range verification function since we got rid of the
old racy i386-only code to walk page tables by hand.
It existed because the original 80386 would not honor the write protect
bit when in kernel mode, so you had to do COW by hand before doing any
user access. But we haven't supported that in a long time, and these
days the 'type' argument is a purely historical artifact.
A discussion about extending 'user_access_begin()' to do the range
checking resulted this patch, because there is no way we're going to
move the old VERIFY_xyz interface to that model. And it's best done at
the end of the merge window when I've done most of my merges, so let's
just get this done once and for all.
This patch was mostly done with a sed-script, with manual fix-ups for
the cases that weren't of the trivial 'access_ok(VERIFY_xyz' form.
There were a couple of notable cases:
- csky still had the old "verify_area()" name as an alias.
- the iter_iov code had magical hardcoded knowledge of the actual
values of VERIFY_{READ,WRITE} (not that they mattered, since nothing
really used it)
- microblaze used the type argument for a debug printout
but other than those oddities this should be a total no-op patch.
I tried to fix up all architectures, did fairly extensive grepping for
access_ok() uses, and the changes are trivial, but I may have missed
something. Any missed conversion should be trivially fixable, though.
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2019-01-04 10:57:57 +08:00
|
|
|
if (!access_ok(frame, sizeof (*frame)))
|
2005-04-17 06:20:36 +08:00
|
|
|
goto badframe;
|
|
|
|
|
2006-06-16 03:23:02 +08:00
|
|
|
if (restore_sigframe(regs, frame))
|
2005-04-17 06:20:36 +08:00
|
|
|
goto badframe;
|
|
|
|
|
|
|
|
return regs->ARM_r0;
|
|
|
|
|
|
|
|
badframe:
|
2019-05-23 23:17:27 +08:00
|
|
|
force_sig(SIGSEGV);
|
2005-04-17 06:20:36 +08:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
asmlinkage int sys_rt_sigreturn(struct pt_regs *regs)
|
|
|
|
{
|
|
|
|
struct rt_sigframe __user *frame;
|
|
|
|
|
|
|
|
/* Always make any pending restarted system calls return -EINTR */
|
2015-02-13 07:01:14 +08:00
|
|
|
current->restart_block.fn = do_no_restart_syscall;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Since we stacked the signal on a 64-bit boundary,
|
|
|
|
* then 'sp' should be word aligned here. If it's
|
|
|
|
* not, then the user is trying to mess with us.
|
|
|
|
*/
|
|
|
|
if (regs->ARM_sp & 7)
|
|
|
|
goto badframe;
|
|
|
|
|
|
|
|
frame = (struct rt_sigframe __user *)regs->ARM_sp;
|
|
|
|
|
Remove 'type' argument from access_ok() function
Nobody has actually used the type (VERIFY_READ vs VERIFY_WRITE) argument
of the user address range verification function since we got rid of the
old racy i386-only code to walk page tables by hand.
It existed because the original 80386 would not honor the write protect
bit when in kernel mode, so you had to do COW by hand before doing any
user access. But we haven't supported that in a long time, and these
days the 'type' argument is a purely historical artifact.
A discussion about extending 'user_access_begin()' to do the range
checking resulted this patch, because there is no way we're going to
move the old VERIFY_xyz interface to that model. And it's best done at
the end of the merge window when I've done most of my merges, so let's
just get this done once and for all.
This patch was mostly done with a sed-script, with manual fix-ups for
the cases that weren't of the trivial 'access_ok(VERIFY_xyz' form.
There were a couple of notable cases:
- csky still had the old "verify_area()" name as an alias.
- the iter_iov code had magical hardcoded knowledge of the actual
values of VERIFY_{READ,WRITE} (not that they mattered, since nothing
really used it)
- microblaze used the type argument for a debug printout
but other than those oddities this should be a total no-op patch.
I tried to fix up all architectures, did fairly extensive grepping for
access_ok() uses, and the changes are trivial, but I may have missed
something. Any missed conversion should be trivially fixable, though.
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2019-01-04 10:57:57 +08:00
|
|
|
if (!access_ok(frame, sizeof (*frame)))
|
2005-04-17 06:20:36 +08:00
|
|
|
goto badframe;
|
|
|
|
|
2006-06-16 03:23:02 +08:00
|
|
|
if (restore_sigframe(regs, &frame->sig))
|
2005-04-17 06:20:36 +08:00
|
|
|
goto badframe;
|
|
|
|
|
2012-12-23 14:52:54 +08:00
|
|
|
if (restore_altstack(&frame->sig.uc.uc_stack))
|
2005-04-17 06:20:36 +08:00
|
|
|
goto badframe;
|
|
|
|
|
|
|
|
return regs->ARM_r0;
|
|
|
|
|
|
|
|
badframe:
|
2019-05-23 23:17:27 +08:00
|
|
|
force_sig(SIGSEGV);
|
2005-04-17 06:20:36 +08:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int
|
2006-06-16 03:28:03 +08:00
|
|
|
setup_sigframe(struct sigframe __user *sf, struct pt_regs *regs, sigset_t *set)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2006-06-25 06:46:21 +08:00
|
|
|
struct aux_sigframe __user *aux;
|
2018-09-11 17:11:06 +08:00
|
|
|
struct sigcontext context;
|
2005-04-17 06:20:36 +08:00
|
|
|
int err = 0;
|
|
|
|
|
2018-09-11 17:11:06 +08:00
|
|
|
context = (struct sigcontext) {
|
|
|
|
.arm_r0 = regs->ARM_r0,
|
|
|
|
.arm_r1 = regs->ARM_r1,
|
|
|
|
.arm_r2 = regs->ARM_r2,
|
|
|
|
.arm_r3 = regs->ARM_r3,
|
|
|
|
.arm_r4 = regs->ARM_r4,
|
|
|
|
.arm_r5 = regs->ARM_r5,
|
|
|
|
.arm_r6 = regs->ARM_r6,
|
|
|
|
.arm_r7 = regs->ARM_r7,
|
|
|
|
.arm_r8 = regs->ARM_r8,
|
|
|
|
.arm_r9 = regs->ARM_r9,
|
|
|
|
.arm_r10 = regs->ARM_r10,
|
|
|
|
.arm_fp = regs->ARM_fp,
|
|
|
|
.arm_ip = regs->ARM_ip,
|
|
|
|
.arm_sp = regs->ARM_sp,
|
|
|
|
.arm_lr = regs->ARM_lr,
|
|
|
|
.arm_pc = regs->ARM_pc,
|
|
|
|
.arm_cpsr = regs->ARM_cpsr,
|
|
|
|
|
|
|
|
.trap_no = current->thread.trap_no,
|
|
|
|
.error_code = current->thread.error_code,
|
|
|
|
.fault_address = current->thread.address,
|
|
|
|
.oldmask = set->sig[0],
|
|
|
|
};
|
|
|
|
|
|
|
|
err |= __copy_to_user(&sf->uc.uc_mcontext, &context, sizeof(context));
|
2006-06-16 03:28:03 +08:00
|
|
|
|
|
|
|
err |= __copy_to_user(&sf->uc.uc_sigmask, set, sizeof(*set));
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2006-06-25 06:46:21 +08:00
|
|
|
aux = (struct aux_sigframe __user *) sf->uc.uc_regspace;
|
2006-06-28 05:56:18 +08:00
|
|
|
#ifdef CONFIG_CRUNCH
|
|
|
|
if (err == 0)
|
|
|
|
err |= preserve_crunch_context(&aux->crunch);
|
|
|
|
#endif
|
2005-04-17 06:20:36 +08:00
|
|
|
#ifdef CONFIG_IWMMXT
|
2017-07-01 01:56:59 +08:00
|
|
|
if (err == 0)
|
2005-04-17 06:20:36 +08:00
|
|
|
err |= preserve_iwmmxt_context(&aux->iwmmxt);
|
|
|
|
#endif
|
|
|
|
#ifdef CONFIG_VFP
|
2010-04-11 22:58:27 +08:00
|
|
|
if (err == 0)
|
|
|
|
err |= preserve_vfp_context(&aux->vfp);
|
2005-04-17 06:20:36 +08:00
|
|
|
#endif
|
2018-09-11 17:13:11 +08:00
|
|
|
err |= __put_user(0, &aux->end_magic);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline void __user *
|
2012-11-08 06:53:13 +08:00
|
|
|
get_sigframe(struct ksignal *ksig, struct pt_regs *regs, int framesize)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2012-11-08 06:53:13 +08:00
|
|
|
unsigned long sp = sigsp(regs->ARM_sp, ksig);
|
2005-04-17 06:20:36 +08:00
|
|
|
void __user *frame;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* ATPCS B01 mandates 8-byte alignment
|
|
|
|
*/
|
|
|
|
frame = (void __user *)((sp - framesize) & ~7);
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Check that we can actually write to the signal frame.
|
|
|
|
*/
|
Remove 'type' argument from access_ok() function
Nobody has actually used the type (VERIFY_READ vs VERIFY_WRITE) argument
of the user address range verification function since we got rid of the
old racy i386-only code to walk page tables by hand.
It existed because the original 80386 would not honor the write protect
bit when in kernel mode, so you had to do COW by hand before doing any
user access. But we haven't supported that in a long time, and these
days the 'type' argument is a purely historical artifact.
A discussion about extending 'user_access_begin()' to do the range
checking resulted this patch, because there is no way we're going to
move the old VERIFY_xyz interface to that model. And it's best done at
the end of the merge window when I've done most of my merges, so let's
just get this done once and for all.
This patch was mostly done with a sed-script, with manual fix-ups for
the cases that weren't of the trivial 'access_ok(VERIFY_xyz' form.
There were a couple of notable cases:
- csky still had the old "verify_area()" name as an alias.
- the iter_iov code had magical hardcoded knowledge of the actual
values of VERIFY_{READ,WRITE} (not that they mattered, since nothing
really used it)
- microblaze used the type argument for a debug printout
but other than those oddities this should be a total no-op patch.
I tried to fix up all architectures, did fairly extensive grepping for
access_ok() uses, and the changes are trivial, but I may have missed
something. Any missed conversion should be trivially fixable, though.
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2019-01-04 10:57:57 +08:00
|
|
|
if (!access_ok(frame, framesize))
|
2005-04-17 06:20:36 +08:00
|
|
|
frame = NULL;
|
|
|
|
|
|
|
|
return frame;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int
|
2012-11-08 06:53:13 +08:00
|
|
|
setup_return(struct pt_regs *regs, struct ksignal *ksig,
|
|
|
|
unsigned long __user *rc, void __user *frame)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2012-11-08 06:53:13 +08:00
|
|
|
unsigned long handler = (unsigned long)ksig->ka.sa.sa_handler;
|
2017-08-10 11:42:51 +08:00
|
|
|
unsigned long handler_fdpic_GOT = 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
unsigned long retcode;
|
2017-08-10 11:42:51 +08:00
|
|
|
unsigned int idx, thumb = 0;
|
2011-02-20 20:22:52 +08:00
|
|
|
unsigned long cpsr = regs->ARM_cpsr & ~(PSR_f | PSR_E_BIT);
|
2017-08-10 11:42:51 +08:00
|
|
|
bool fdpic = IS_ENABLED(CONFIG_BINFMT_ELF_FDPIC) &&
|
|
|
|
(current->personality & FDPIC_FUNCPTRS);
|
|
|
|
|
|
|
|
if (fdpic) {
|
|
|
|
unsigned long __user *fdpic_func_desc =
|
|
|
|
(unsigned long __user *)handler;
|
|
|
|
if (__get_user(handler, &fdpic_func_desc[0]) ||
|
|
|
|
__get_user(handler_fdpic_GOT, &fdpic_func_desc[1]))
|
|
|
|
return 1;
|
|
|
|
}
|
2011-02-20 20:22:52 +08:00
|
|
|
|
|
|
|
cpsr |= PSR_ENDSTATE;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Maybe we need to deliver a 32-bit signal to a 26-bit task.
|
|
|
|
*/
|
2012-11-08 06:53:13 +08:00
|
|
|
if (ksig->ka.sa.sa_flags & SA_THIRTYTWO)
|
2005-04-17 06:20:36 +08:00
|
|
|
cpsr = (cpsr & ~MODE_MASK) | USR_MODE;
|
|
|
|
|
|
|
|
#ifdef CONFIG_ARM_THUMB
|
|
|
|
if (elf_hwcap & HWCAP_THUMB) {
|
|
|
|
/*
|
|
|
|
* The LSB of the handler determines if we're going to
|
|
|
|
* be using THUMB or ARM mode for this signal handler.
|
|
|
|
*/
|
|
|
|
thumb = handler & 1;
|
|
|
|
|
2013-11-07 01:38:05 +08:00
|
|
|
/*
|
2015-09-11 23:44:02 +08:00
|
|
|
* Clear the If-Then Thumb-2 execution state. ARM spec
|
|
|
|
* requires this to be all 000s in ARM mode. Snapdragon
|
|
|
|
* S4/Krait misbehaves on a Thumb=>ARM signal transition
|
|
|
|
* without this.
|
|
|
|
*
|
|
|
|
* We must do this whenever we are running on a Thumb-2
|
|
|
|
* capable CPU, which includes ARMv6T2. However, we elect
|
2015-09-16 18:08:49 +08:00
|
|
|
* to always do this to simplify the code; this field is
|
|
|
|
* marked UNK/SBZP for older architectures.
|
2013-11-07 01:38:05 +08:00
|
|
|
*/
|
|
|
|
cpsr &= ~PSR_IT_MASK;
|
|
|
|
|
|
|
|
if (thumb) {
|
|
|
|
cpsr |= PSR_T_BIT;
|
2009-05-30 21:00:15 +08:00
|
|
|
} else
|
2005-04-17 06:20:36 +08:00
|
|
|
cpsr &= ~PSR_T_BIT;
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
|
2012-11-08 06:53:13 +08:00
|
|
|
if (ksig->ka.sa.sa_flags & SA_RESTORER) {
|
|
|
|
retcode = (unsigned long)ksig->ka.sa.sa_restorer;
|
2017-08-10 11:42:51 +08:00
|
|
|
if (fdpic) {
|
|
|
|
/*
|
|
|
|
* We need code to load the function descriptor.
|
|
|
|
* That code follows the standard sigreturn code
|
|
|
|
* (6 words), and is made of 3 + 2 words for each
|
|
|
|
* variant. The 4th copied word is the actual FD
|
|
|
|
* address that the assembly code expects.
|
|
|
|
*/
|
|
|
|
idx = 6 + thumb * 3;
|
|
|
|
if (ksig->ka.sa.sa_flags & SA_SIGINFO)
|
|
|
|
idx += 5;
|
|
|
|
if (__put_user(sigreturn_codes[idx], rc ) ||
|
|
|
|
__put_user(sigreturn_codes[idx+1], rc+1) ||
|
|
|
|
__put_user(sigreturn_codes[idx+2], rc+2) ||
|
|
|
|
__put_user(retcode, rc+3))
|
|
|
|
return 1;
|
|
|
|
goto rc_finish;
|
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
} else {
|
2017-08-10 11:42:51 +08:00
|
|
|
idx = thumb << 1;
|
2012-11-08 06:53:13 +08:00
|
|
|
if (ksig->ka.sa.sa_flags & SA_SIGINFO)
|
2006-01-19 06:38:47 +08:00
|
|
|
idx += 3;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2013-04-19 01:37:24 +08:00
|
|
|
/*
|
|
|
|
* Put the sigreturn code on the stack no matter which return
|
|
|
|
* mechanism we use in order to remain ABI compliant
|
|
|
|
*/
|
2006-01-19 06:38:47 +08:00
|
|
|
if (__put_user(sigreturn_codes[idx], rc) ||
|
|
|
|
__put_user(sigreturn_codes[idx+1], rc+1))
|
2005-04-17 06:20:36 +08:00
|
|
|
return 1;
|
|
|
|
|
2017-08-10 11:42:51 +08:00
|
|
|
rc_finish:
|
2013-08-03 17:39:51 +08:00
|
|
|
#ifdef CONFIG_MMU
|
|
|
|
if (cpsr & MODE32_BIT) {
|
2013-07-24 07:29:18 +08:00
|
|
|
struct mm_struct *mm = current->mm;
|
|
|
|
|
2005-06-23 03:26:05 +08:00
|
|
|
/*
|
2013-07-24 07:29:18 +08:00
|
|
|
* 32-bit code can use the signal return page
|
|
|
|
* except when the MPU has protected the vectors
|
|
|
|
* page from PL0
|
2005-06-23 03:26:05 +08:00
|
|
|
*/
|
2013-07-24 07:29:18 +08:00
|
|
|
retcode = mm->context.sigpage + signal_return_offset +
|
|
|
|
(idx << 2) + thumb;
|
2013-08-03 17:39:51 +08:00
|
|
|
} else
|
|
|
|
#endif
|
|
|
|
{
|
2005-06-23 03:26:05 +08:00
|
|
|
/*
|
|
|
|
* Ensure that the instruction cache sees
|
|
|
|
* the return code written onto the stack.
|
|
|
|
*/
|
|
|
|
flush_icache_range((unsigned long)rc,
|
2017-08-10 11:42:51 +08:00
|
|
|
(unsigned long)(rc + 3));
|
2005-06-23 03:26:05 +08:00
|
|
|
|
|
|
|
retcode = ((unsigned long)rc) + thumb;
|
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2014-07-13 21:24:03 +08:00
|
|
|
regs->ARM_r0 = ksig->sig;
|
2005-04-17 06:20:36 +08:00
|
|
|
regs->ARM_sp = (unsigned long)frame;
|
|
|
|
regs->ARM_lr = retcode;
|
|
|
|
regs->ARM_pc = handler;
|
2017-08-10 11:42:51 +08:00
|
|
|
if (fdpic)
|
|
|
|
regs->ARM_r9 = handler_fdpic_GOT;
|
2005-04-17 06:20:36 +08:00
|
|
|
regs->ARM_cpsr = cpsr;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int
|
2012-11-08 06:53:13 +08:00
|
|
|
setup_frame(struct ksignal *ksig, sigset_t *set, struct pt_regs *regs)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2012-11-08 06:53:13 +08:00
|
|
|
struct sigframe __user *frame = get_sigframe(ksig, regs, sizeof(*frame));
|
2005-04-17 06:20:36 +08:00
|
|
|
int err = 0;
|
|
|
|
|
|
|
|
if (!frame)
|
|
|
|
return 1;
|
|
|
|
|
2006-06-25 05:41:09 +08:00
|
|
|
/*
|
|
|
|
* Set uc.uc_flags to a value which sc.trap_no would never have.
|
|
|
|
*/
|
2018-09-11 17:13:11 +08:00
|
|
|
err = __put_user(0x5ac3c35a, &frame->uc.uc_flags);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2006-06-16 03:28:03 +08:00
|
|
|
err |= setup_sigframe(frame, regs, set);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (err == 0)
|
2012-11-08 06:53:13 +08:00
|
|
|
err = setup_return(regs, ksig, frame->retcode, frame);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int
|
2012-11-08 06:53:13 +08:00
|
|
|
setup_rt_frame(struct ksignal *ksig, sigset_t *set, struct pt_regs *regs)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2012-11-08 06:53:13 +08:00
|
|
|
struct rt_sigframe __user *frame = get_sigframe(ksig, regs, sizeof(*frame));
|
2005-04-17 06:20:36 +08:00
|
|
|
int err = 0;
|
|
|
|
|
|
|
|
if (!frame)
|
|
|
|
return 1;
|
|
|
|
|
2012-11-08 06:53:13 +08:00
|
|
|
err |= copy_siginfo_to_user(&frame->info, &ksig->info);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2018-09-11 17:13:11 +08:00
|
|
|
err |= __put_user(0, &frame->sig.uc.uc_flags);
|
|
|
|
err |= __put_user(NULL, &frame->sig.uc.uc_link);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2012-12-23 14:52:54 +08:00
|
|
|
err |= __save_altstack(&frame->sig.uc.uc_stack, regs->ARM_sp);
|
2006-06-16 03:28:03 +08:00
|
|
|
err |= setup_sigframe(&frame->sig, regs, set);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (err == 0)
|
2012-11-08 06:53:13 +08:00
|
|
|
err = setup_return(regs, ksig, frame->sig.retcode, frame);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (err == 0) {
|
|
|
|
/*
|
|
|
|
* For realtime signals we must also set the second and third
|
|
|
|
* arguments for the signal handler.
|
|
|
|
* -- Peter Maydell <pmaydell@chiark.greenend.org.uk> 2000-12-06
|
|
|
|
*/
|
|
|
|
regs->ARM_r1 = (unsigned long)&frame->info;
|
2006-06-16 03:18:25 +08:00
|
|
|
regs->ARM_r2 = (unsigned long)&frame->sig.uc;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* OK, we're invoking a handler
|
|
|
|
*/
|
2012-11-08 06:53:13 +08:00
|
|
|
static void handle_signal(struct ksignal *ksig, struct pt_regs *regs)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2012-05-02 21:59:21 +08:00
|
|
|
sigset_t *oldset = sigmask_to_save();
|
2005-04-17 06:20:36 +08:00
|
|
|
int ret;
|
|
|
|
|
2018-06-02 20:43:55 +08:00
|
|
|
/*
|
2019-03-06 03:47:53 +08:00
|
|
|
* Perform fixup for the pre-signal frame.
|
2018-06-02 20:43:55 +08:00
|
|
|
*/
|
2018-06-22 18:45:07 +08:00
|
|
|
rseq_signal_deliver(ksig, regs);
|
2018-06-02 20:43:55 +08:00
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/*
|
|
|
|
* Set up the stack frame
|
|
|
|
*/
|
2012-11-08 06:53:13 +08:00
|
|
|
if (ksig->ka.sa.sa_flags & SA_SIGINFO)
|
|
|
|
ret = setup_rt_frame(ksig, oldset, regs);
|
2005-04-17 06:20:36 +08:00
|
|
|
else
|
2012-11-08 06:53:13 +08:00
|
|
|
ret = setup_frame(ksig, oldset, regs);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Check that the resulting registers are actually sane.
|
|
|
|
*/
|
|
|
|
ret |= !valid_user_regs(regs);
|
|
|
|
|
2012-11-08 06:53:13 +08:00
|
|
|
signal_setup_done(ret, ksig, 0);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Note that 'init' is a special process: it doesn't get signals it doesn't
|
|
|
|
* want to handle. Thus you cannot kill init even with a SIGKILL even by
|
|
|
|
* mistake.
|
|
|
|
*
|
|
|
|
* Note that we go through the signals twice: once to check the signals that
|
|
|
|
* the kernel can handle, and then we build all the user-level signal handling
|
|
|
|
* stack-frames in one go after that.
|
|
|
|
*/
|
2012-07-20 00:48:21 +08:00
|
|
|
static int do_signal(struct pt_regs *regs, int syscall)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
ARM: 6892/1: handle ptrace requests to change PC during interrupted system calls
GDB's interrupt.exp test cases currenly fail on ARM. The problem is how do_signal
handled restarting interrupted system calls:
The entry.S assembler code determines that we come from a system call; and that
information is passed as "syscall" parameter to do_signal. That routine then
calls get_signal_to_deliver [*] and if a signal is to be delivered, calls into
handle_signal. If a system call is to be restarted either after the signal
handler returns, or if no handler is to be called in the first place, the PC
is updated after the get_signal_to_deliver call, either in handle_signal (if
we have a handler) or at the end of do_signal (otherwise).
Now the problem is that during [*], the call to get_signal_to_deliver, a ptrace
intercept may happen. During this intercept, the debugger may change registers,
including the PC. This is done by GDB if it wants to execute an "inferior call",
i.e. the execution of some code in the debugged program triggered by GDB.
To this purpose, GDB will save all registers, allocate a stack frame, set up
PC and arguments as appropriate for the call, and point the link register to
a dummy breakpoint instruction. Once the process is restarted, it will execute
the call and then trap back to the debugger, at which point GDB will restore
all registers and continue original execution.
This generally works fine. However, now consider what happens when GDB attempts
to do exactly that while the process was interrupted during execution of a to-be-
restarted system call: do_signal is called with the syscall flag set; it calls
get_signal_to_deliver, at which point the debugger takes over and changes the PC
to point to a completely different place. Now get_signal_to_deliver returns
without a signal to deliver; but now do_signal decides it should be restarting
a system call, and decrements the PC by 2 or 4 -- so it now points to 2 or 4
bytes before the function GDB wants to call -- which leads to a subsequent crash.
To fix this problem, two things need to be supported:
- do_signal must be able to recognize that get_signal_to_deliver changed the PC
to a different location, and skip the restart-syscall sequence
- once the debugger has restored all registers at the end of the inferior call
sequence, do_signal must recognize that *now* it needs to restart the pending
system call, even though it was now entered from a breakpoint instead of an
actual svc instruction
This set of issues is solved on other platforms, usually by one of two
mechanisms:
- The status information "do_signal is handling a system call that may need
restarting" is itself carried in some register that can be accessed via
ptrace. This is e.g. on Intel the "orig_eax" register; on Sparc the kernel
defines a magic extra bit in the flags register for this purpose.
This allows GDB to manage that state: reset it when doing an inferior call,
and restore it after the call is finished.
- On s390, do_signal transparently handles this problem without requiring
GDB interaction, by performing system call restarting in the following
way: first, adjust the PC as necessary for restarting the call. Then,
call get_signal_to_deliver; and finally just continue execution at the
PC. This way, if GDB does not change the PC, everything is as before.
If GDB *does* change the PC, execution will simply continue there --
and once GDB restores the PC it saved at that point, it will automatically
point to the *restarted* system call. (There is the minor twist how to
handle system calls that do *not* need restarting -- do_signal will undo
the PC change in this case, after get_signal_to_deliver has returned, and
only if ptrace did not change the PC during that call.)
Because there does not appear to be any obvious register to carry the
syscall-restart information on ARM, we'd either have to introduce a new
artificial ptrace register just for that purpose, or else handle the issue
transparently like on s390. The patch below implements the second option;
using this patch makes the interrupt.exp test cases pass on ARM, with no
regression in the GDB test suite otherwise.
Cc: patches@linaro.org
Signed-off-by: Ulrich Weigand <ulrich.weigand@linaro.org>
Signed-off-by: Arnd Bergmann <arnd.bergmann@linaro.org>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
2011-05-04 01:32:55 +08:00
|
|
|
unsigned int retval = 0, continue_addr = 0, restart_addr = 0;
|
2012-11-08 06:53:13 +08:00
|
|
|
struct ksignal ksig;
|
2012-07-20 00:48:21 +08:00
|
|
|
int restart = 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
ARM: 6892/1: handle ptrace requests to change PC during interrupted system calls
GDB's interrupt.exp test cases currenly fail on ARM. The problem is how do_signal
handled restarting interrupted system calls:
The entry.S assembler code determines that we come from a system call; and that
information is passed as "syscall" parameter to do_signal. That routine then
calls get_signal_to_deliver [*] and if a signal is to be delivered, calls into
handle_signal. If a system call is to be restarted either after the signal
handler returns, or if no handler is to be called in the first place, the PC
is updated after the get_signal_to_deliver call, either in handle_signal (if
we have a handler) or at the end of do_signal (otherwise).
Now the problem is that during [*], the call to get_signal_to_deliver, a ptrace
intercept may happen. During this intercept, the debugger may change registers,
including the PC. This is done by GDB if it wants to execute an "inferior call",
i.e. the execution of some code in the debugged program triggered by GDB.
To this purpose, GDB will save all registers, allocate a stack frame, set up
PC and arguments as appropriate for the call, and point the link register to
a dummy breakpoint instruction. Once the process is restarted, it will execute
the call and then trap back to the debugger, at which point GDB will restore
all registers and continue original execution.
This generally works fine. However, now consider what happens when GDB attempts
to do exactly that while the process was interrupted during execution of a to-be-
restarted system call: do_signal is called with the syscall flag set; it calls
get_signal_to_deliver, at which point the debugger takes over and changes the PC
to point to a completely different place. Now get_signal_to_deliver returns
without a signal to deliver; but now do_signal decides it should be restarting
a system call, and decrements the PC by 2 or 4 -- so it now points to 2 or 4
bytes before the function GDB wants to call -- which leads to a subsequent crash.
To fix this problem, two things need to be supported:
- do_signal must be able to recognize that get_signal_to_deliver changed the PC
to a different location, and skip the restart-syscall sequence
- once the debugger has restored all registers at the end of the inferior call
sequence, do_signal must recognize that *now* it needs to restart the pending
system call, even though it was now entered from a breakpoint instead of an
actual svc instruction
This set of issues is solved on other platforms, usually by one of two
mechanisms:
- The status information "do_signal is handling a system call that may need
restarting" is itself carried in some register that can be accessed via
ptrace. This is e.g. on Intel the "orig_eax" register; on Sparc the kernel
defines a magic extra bit in the flags register for this purpose.
This allows GDB to manage that state: reset it when doing an inferior call,
and restore it after the call is finished.
- On s390, do_signal transparently handles this problem without requiring
GDB interaction, by performing system call restarting in the following
way: first, adjust the PC as necessary for restarting the call. Then,
call get_signal_to_deliver; and finally just continue execution at the
PC. This way, if GDB does not change the PC, everything is as before.
If GDB *does* change the PC, execution will simply continue there --
and once GDB restores the PC it saved at that point, it will automatically
point to the *restarted* system call. (There is the minor twist how to
handle system calls that do *not* need restarting -- do_signal will undo
the PC change in this case, after get_signal_to_deliver has returned, and
only if ptrace did not change the PC during that call.)
Because there does not appear to be any obvious register to carry the
syscall-restart information on ARM, we'd either have to introduce a new
artificial ptrace register just for that purpose, or else handle the issue
transparently like on s390. The patch below implements the second option;
using this patch makes the interrupt.exp test cases pass on ARM, with no
regression in the GDB test suite otherwise.
Cc: patches@linaro.org
Signed-off-by: Ulrich Weigand <ulrich.weigand@linaro.org>
Signed-off-by: Arnd Bergmann <arnd.bergmann@linaro.org>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
2011-05-04 01:32:55 +08:00
|
|
|
/*
|
|
|
|
* If we were from a system call, check for system call restarting...
|
|
|
|
*/
|
|
|
|
if (syscall) {
|
|
|
|
continue_addr = regs->ARM_pc;
|
|
|
|
restart_addr = continue_addr - (thumb_mode(regs) ? 2 : 4);
|
|
|
|
retval = regs->ARM_r0;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Prepare for system call restart. We do this here so that a
|
|
|
|
* debugger will see the already changed PSW.
|
|
|
|
*/
|
|
|
|
switch (retval) {
|
2012-07-20 00:48:21 +08:00
|
|
|
case -ERESTART_RESTARTBLOCK:
|
2012-07-20 00:48:50 +08:00
|
|
|
restart -= 2;
|
2020-08-24 06:36:59 +08:00
|
|
|
fallthrough;
|
ARM: 6892/1: handle ptrace requests to change PC during interrupted system calls
GDB's interrupt.exp test cases currenly fail on ARM. The problem is how do_signal
handled restarting interrupted system calls:
The entry.S assembler code determines that we come from a system call; and that
information is passed as "syscall" parameter to do_signal. That routine then
calls get_signal_to_deliver [*] and if a signal is to be delivered, calls into
handle_signal. If a system call is to be restarted either after the signal
handler returns, or if no handler is to be called in the first place, the PC
is updated after the get_signal_to_deliver call, either in handle_signal (if
we have a handler) or at the end of do_signal (otherwise).
Now the problem is that during [*], the call to get_signal_to_deliver, a ptrace
intercept may happen. During this intercept, the debugger may change registers,
including the PC. This is done by GDB if it wants to execute an "inferior call",
i.e. the execution of some code in the debugged program triggered by GDB.
To this purpose, GDB will save all registers, allocate a stack frame, set up
PC and arguments as appropriate for the call, and point the link register to
a dummy breakpoint instruction. Once the process is restarted, it will execute
the call and then trap back to the debugger, at which point GDB will restore
all registers and continue original execution.
This generally works fine. However, now consider what happens when GDB attempts
to do exactly that while the process was interrupted during execution of a to-be-
restarted system call: do_signal is called with the syscall flag set; it calls
get_signal_to_deliver, at which point the debugger takes over and changes the PC
to point to a completely different place. Now get_signal_to_deliver returns
without a signal to deliver; but now do_signal decides it should be restarting
a system call, and decrements the PC by 2 or 4 -- so it now points to 2 or 4
bytes before the function GDB wants to call -- which leads to a subsequent crash.
To fix this problem, two things need to be supported:
- do_signal must be able to recognize that get_signal_to_deliver changed the PC
to a different location, and skip the restart-syscall sequence
- once the debugger has restored all registers at the end of the inferior call
sequence, do_signal must recognize that *now* it needs to restart the pending
system call, even though it was now entered from a breakpoint instead of an
actual svc instruction
This set of issues is solved on other platforms, usually by one of two
mechanisms:
- The status information "do_signal is handling a system call that may need
restarting" is itself carried in some register that can be accessed via
ptrace. This is e.g. on Intel the "orig_eax" register; on Sparc the kernel
defines a magic extra bit in the flags register for this purpose.
This allows GDB to manage that state: reset it when doing an inferior call,
and restore it after the call is finished.
- On s390, do_signal transparently handles this problem without requiring
GDB interaction, by performing system call restarting in the following
way: first, adjust the PC as necessary for restarting the call. Then,
call get_signal_to_deliver; and finally just continue execution at the
PC. This way, if GDB does not change the PC, everything is as before.
If GDB *does* change the PC, execution will simply continue there --
and once GDB restores the PC it saved at that point, it will automatically
point to the *restarted* system call. (There is the minor twist how to
handle system calls that do *not* need restarting -- do_signal will undo
the PC change in this case, after get_signal_to_deliver has returned, and
only if ptrace did not change the PC during that call.)
Because there does not appear to be any obvious register to carry the
syscall-restart information on ARM, we'd either have to introduce a new
artificial ptrace register just for that purpose, or else handle the issue
transparently like on s390. The patch below implements the second option;
using this patch makes the interrupt.exp test cases pass on ARM, with no
regression in the GDB test suite otherwise.
Cc: patches@linaro.org
Signed-off-by: Ulrich Weigand <ulrich.weigand@linaro.org>
Signed-off-by: Arnd Bergmann <arnd.bergmann@linaro.org>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
2011-05-04 01:32:55 +08:00
|
|
|
case -ERESTARTNOHAND:
|
|
|
|
case -ERESTARTSYS:
|
|
|
|
case -ERESTARTNOINTR:
|
2012-07-20 00:48:21 +08:00
|
|
|
restart++;
|
ARM: 6892/1: handle ptrace requests to change PC during interrupted system calls
GDB's interrupt.exp test cases currenly fail on ARM. The problem is how do_signal
handled restarting interrupted system calls:
The entry.S assembler code determines that we come from a system call; and that
information is passed as "syscall" parameter to do_signal. That routine then
calls get_signal_to_deliver [*] and if a signal is to be delivered, calls into
handle_signal. If a system call is to be restarted either after the signal
handler returns, or if no handler is to be called in the first place, the PC
is updated after the get_signal_to_deliver call, either in handle_signal (if
we have a handler) or at the end of do_signal (otherwise).
Now the problem is that during [*], the call to get_signal_to_deliver, a ptrace
intercept may happen. During this intercept, the debugger may change registers,
including the PC. This is done by GDB if it wants to execute an "inferior call",
i.e. the execution of some code in the debugged program triggered by GDB.
To this purpose, GDB will save all registers, allocate a stack frame, set up
PC and arguments as appropriate for the call, and point the link register to
a dummy breakpoint instruction. Once the process is restarted, it will execute
the call and then trap back to the debugger, at which point GDB will restore
all registers and continue original execution.
This generally works fine. However, now consider what happens when GDB attempts
to do exactly that while the process was interrupted during execution of a to-be-
restarted system call: do_signal is called with the syscall flag set; it calls
get_signal_to_deliver, at which point the debugger takes over and changes the PC
to point to a completely different place. Now get_signal_to_deliver returns
without a signal to deliver; but now do_signal decides it should be restarting
a system call, and decrements the PC by 2 or 4 -- so it now points to 2 or 4
bytes before the function GDB wants to call -- which leads to a subsequent crash.
To fix this problem, two things need to be supported:
- do_signal must be able to recognize that get_signal_to_deliver changed the PC
to a different location, and skip the restart-syscall sequence
- once the debugger has restored all registers at the end of the inferior call
sequence, do_signal must recognize that *now* it needs to restart the pending
system call, even though it was now entered from a breakpoint instead of an
actual svc instruction
This set of issues is solved on other platforms, usually by one of two
mechanisms:
- The status information "do_signal is handling a system call that may need
restarting" is itself carried in some register that can be accessed via
ptrace. This is e.g. on Intel the "orig_eax" register; on Sparc the kernel
defines a magic extra bit in the flags register for this purpose.
This allows GDB to manage that state: reset it when doing an inferior call,
and restore it after the call is finished.
- On s390, do_signal transparently handles this problem without requiring
GDB interaction, by performing system call restarting in the following
way: first, adjust the PC as necessary for restarting the call. Then,
call get_signal_to_deliver; and finally just continue execution at the
PC. This way, if GDB does not change the PC, everything is as before.
If GDB *does* change the PC, execution will simply continue there --
and once GDB restores the PC it saved at that point, it will automatically
point to the *restarted* system call. (There is the minor twist how to
handle system calls that do *not* need restarting -- do_signal will undo
the PC change in this case, after get_signal_to_deliver has returned, and
only if ptrace did not change the PC during that call.)
Because there does not appear to be any obvious register to carry the
syscall-restart information on ARM, we'd either have to introduce a new
artificial ptrace register just for that purpose, or else handle the issue
transparently like on s390. The patch below implements the second option;
using this patch makes the interrupt.exp test cases pass on ARM, with no
regression in the GDB test suite otherwise.
Cc: patches@linaro.org
Signed-off-by: Ulrich Weigand <ulrich.weigand@linaro.org>
Signed-off-by: Arnd Bergmann <arnd.bergmann@linaro.org>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
2011-05-04 01:32:55 +08:00
|
|
|
regs->ARM_r0 = regs->ARM_ORIG_r0;
|
|
|
|
regs->ARM_pc = restart_addr;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Get the signal to deliver. When running under ptrace, at this
|
|
|
|
* point the debugger may change all our registers ...
|
|
|
|
*/
|
2012-07-20 00:48:21 +08:00
|
|
|
/*
|
|
|
|
* Depending on the signal settings we may need to revert the
|
|
|
|
* decision to restart the system call. But skip this if a
|
|
|
|
* debugger has chosen to restart at a different PC.
|
|
|
|
*/
|
2012-11-08 06:53:13 +08:00
|
|
|
if (get_signal(&ksig)) {
|
|
|
|
/* handler */
|
|
|
|
if (unlikely(restart) && regs->ARM_pc == restart_addr) {
|
2012-07-20 00:46:44 +08:00
|
|
|
if (retval == -ERESTARTNOHAND ||
|
|
|
|
retval == -ERESTART_RESTARTBLOCK
|
ARM: 6892/1: handle ptrace requests to change PC during interrupted system calls
GDB's interrupt.exp test cases currenly fail on ARM. The problem is how do_signal
handled restarting interrupted system calls:
The entry.S assembler code determines that we come from a system call; and that
information is passed as "syscall" parameter to do_signal. That routine then
calls get_signal_to_deliver [*] and if a signal is to be delivered, calls into
handle_signal. If a system call is to be restarted either after the signal
handler returns, or if no handler is to be called in the first place, the PC
is updated after the get_signal_to_deliver call, either in handle_signal (if
we have a handler) or at the end of do_signal (otherwise).
Now the problem is that during [*], the call to get_signal_to_deliver, a ptrace
intercept may happen. During this intercept, the debugger may change registers,
including the PC. This is done by GDB if it wants to execute an "inferior call",
i.e. the execution of some code in the debugged program triggered by GDB.
To this purpose, GDB will save all registers, allocate a stack frame, set up
PC and arguments as appropriate for the call, and point the link register to
a dummy breakpoint instruction. Once the process is restarted, it will execute
the call and then trap back to the debugger, at which point GDB will restore
all registers and continue original execution.
This generally works fine. However, now consider what happens when GDB attempts
to do exactly that while the process was interrupted during execution of a to-be-
restarted system call: do_signal is called with the syscall flag set; it calls
get_signal_to_deliver, at which point the debugger takes over and changes the PC
to point to a completely different place. Now get_signal_to_deliver returns
without a signal to deliver; but now do_signal decides it should be restarting
a system call, and decrements the PC by 2 or 4 -- so it now points to 2 or 4
bytes before the function GDB wants to call -- which leads to a subsequent crash.
To fix this problem, two things need to be supported:
- do_signal must be able to recognize that get_signal_to_deliver changed the PC
to a different location, and skip the restart-syscall sequence
- once the debugger has restored all registers at the end of the inferior call
sequence, do_signal must recognize that *now* it needs to restart the pending
system call, even though it was now entered from a breakpoint instead of an
actual svc instruction
This set of issues is solved on other platforms, usually by one of two
mechanisms:
- The status information "do_signal is handling a system call that may need
restarting" is itself carried in some register that can be accessed via
ptrace. This is e.g. on Intel the "orig_eax" register; on Sparc the kernel
defines a magic extra bit in the flags register for this purpose.
This allows GDB to manage that state: reset it when doing an inferior call,
and restore it after the call is finished.
- On s390, do_signal transparently handles this problem without requiring
GDB interaction, by performing system call restarting in the following
way: first, adjust the PC as necessary for restarting the call. Then,
call get_signal_to_deliver; and finally just continue execution at the
PC. This way, if GDB does not change the PC, everything is as before.
If GDB *does* change the PC, execution will simply continue there --
and once GDB restores the PC it saved at that point, it will automatically
point to the *restarted* system call. (There is the minor twist how to
handle system calls that do *not* need restarting -- do_signal will undo
the PC change in this case, after get_signal_to_deliver has returned, and
only if ptrace did not change the PC during that call.)
Because there does not appear to be any obvious register to carry the
syscall-restart information on ARM, we'd either have to introduce a new
artificial ptrace register just for that purpose, or else handle the issue
transparently like on s390. The patch below implements the second option;
using this patch makes the interrupt.exp test cases pass on ARM, with no
regression in the GDB test suite otherwise.
Cc: patches@linaro.org
Signed-off-by: Ulrich Weigand <ulrich.weigand@linaro.org>
Signed-off-by: Arnd Bergmann <arnd.bergmann@linaro.org>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
2011-05-04 01:32:55 +08:00
|
|
|
|| (retval == -ERESTARTSYS
|
2012-11-08 06:53:13 +08:00
|
|
|
&& !(ksig.ka.sa.sa_flags & SA_RESTART))) {
|
ARM: 6892/1: handle ptrace requests to change PC during interrupted system calls
GDB's interrupt.exp test cases currenly fail on ARM. The problem is how do_signal
handled restarting interrupted system calls:
The entry.S assembler code determines that we come from a system call; and that
information is passed as "syscall" parameter to do_signal. That routine then
calls get_signal_to_deliver [*] and if a signal is to be delivered, calls into
handle_signal. If a system call is to be restarted either after the signal
handler returns, or if no handler is to be called in the first place, the PC
is updated after the get_signal_to_deliver call, either in handle_signal (if
we have a handler) or at the end of do_signal (otherwise).
Now the problem is that during [*], the call to get_signal_to_deliver, a ptrace
intercept may happen. During this intercept, the debugger may change registers,
including the PC. This is done by GDB if it wants to execute an "inferior call",
i.e. the execution of some code in the debugged program triggered by GDB.
To this purpose, GDB will save all registers, allocate a stack frame, set up
PC and arguments as appropriate for the call, and point the link register to
a dummy breakpoint instruction. Once the process is restarted, it will execute
the call and then trap back to the debugger, at which point GDB will restore
all registers and continue original execution.
This generally works fine. However, now consider what happens when GDB attempts
to do exactly that while the process was interrupted during execution of a to-be-
restarted system call: do_signal is called with the syscall flag set; it calls
get_signal_to_deliver, at which point the debugger takes over and changes the PC
to point to a completely different place. Now get_signal_to_deliver returns
without a signal to deliver; but now do_signal decides it should be restarting
a system call, and decrements the PC by 2 or 4 -- so it now points to 2 or 4
bytes before the function GDB wants to call -- which leads to a subsequent crash.
To fix this problem, two things need to be supported:
- do_signal must be able to recognize that get_signal_to_deliver changed the PC
to a different location, and skip the restart-syscall sequence
- once the debugger has restored all registers at the end of the inferior call
sequence, do_signal must recognize that *now* it needs to restart the pending
system call, even though it was now entered from a breakpoint instead of an
actual svc instruction
This set of issues is solved on other platforms, usually by one of two
mechanisms:
- The status information "do_signal is handling a system call that may need
restarting" is itself carried in some register that can be accessed via
ptrace. This is e.g. on Intel the "orig_eax" register; on Sparc the kernel
defines a magic extra bit in the flags register for this purpose.
This allows GDB to manage that state: reset it when doing an inferior call,
and restore it after the call is finished.
- On s390, do_signal transparently handles this problem without requiring
GDB interaction, by performing system call restarting in the following
way: first, adjust the PC as necessary for restarting the call. Then,
call get_signal_to_deliver; and finally just continue execution at the
PC. This way, if GDB does not change the PC, everything is as before.
If GDB *does* change the PC, execution will simply continue there --
and once GDB restores the PC it saved at that point, it will automatically
point to the *restarted* system call. (There is the minor twist how to
handle system calls that do *not* need restarting -- do_signal will undo
the PC change in this case, after get_signal_to_deliver has returned, and
only if ptrace did not change the PC during that call.)
Because there does not appear to be any obvious register to carry the
syscall-restart information on ARM, we'd either have to introduce a new
artificial ptrace register just for that purpose, or else handle the issue
transparently like on s390. The patch below implements the second option;
using this patch makes the interrupt.exp test cases pass on ARM, with no
regression in the GDB test suite otherwise.
Cc: patches@linaro.org
Signed-off-by: Ulrich Weigand <ulrich.weigand@linaro.org>
Signed-off-by: Arnd Bergmann <arnd.bergmann@linaro.org>
Signed-off-by: Russell King <rmk+kernel@arm.linux.org.uk>
2011-05-04 01:32:55 +08:00
|
|
|
regs->ARM_r0 = -EINTR;
|
|
|
|
regs->ARM_pc = continue_addr;
|
|
|
|
}
|
|
|
|
}
|
2012-11-08 06:53:13 +08:00
|
|
|
handle_signal(&ksig, regs);
|
|
|
|
} else {
|
|
|
|
/* no handler */
|
|
|
|
restore_saved_sigmask();
|
|
|
|
if (unlikely(restart) && regs->ARM_pc == restart_addr) {
|
|
|
|
regs->ARM_pc = continue_addr;
|
|
|
|
return restart;
|
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
2012-11-08 06:53:13 +08:00
|
|
|
return 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2012-07-20 00:48:21 +08:00
|
|
|
asmlinkage int
|
2012-07-20 00:47:55 +08:00
|
|
|
do_work_pending(struct pt_regs *regs, unsigned int thread_flags, int syscall)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2015-08-20 23:13:37 +08:00
|
|
|
/*
|
|
|
|
* The assembly code enters us with IRQs off, but it hasn't
|
|
|
|
* informed the tracing code of that for efficiency reasons.
|
|
|
|
* Update the trace code with the current status.
|
|
|
|
*/
|
|
|
|
trace_hardirqs_off();
|
2012-07-20 00:47:55 +08:00
|
|
|
do {
|
|
|
|
if (likely(thread_flags & _TIF_NEED_RESCHED)) {
|
|
|
|
schedule();
|
|
|
|
} else {
|
|
|
|
if (unlikely(!user_mode(regs)))
|
2012-07-20 00:48:21 +08:00
|
|
|
return 0;
|
2012-07-20 00:47:55 +08:00
|
|
|
local_irq_enable();
|
2020-10-10 06:00:49 +08:00
|
|
|
if (thread_flags & (_TIF_SIGPENDING | _TIF_NOTIFY_SIGNAL)) {
|
2012-07-20 00:48:50 +08:00
|
|
|
int restart = do_signal(regs, syscall);
|
|
|
|
if (unlikely(restart)) {
|
2012-07-20 00:48:21 +08:00
|
|
|
/*
|
|
|
|
* Restart without handlers.
|
|
|
|
* Deal with it without leaving
|
|
|
|
* the kernel space.
|
|
|
|
*/
|
2012-07-20 00:48:50 +08:00
|
|
|
return restart;
|
2012-07-20 00:48:21 +08:00
|
|
|
}
|
2012-07-20 00:47:55 +08:00
|
|
|
syscall = 0;
|
2014-03-08 00:23:04 +08:00
|
|
|
} else if (thread_flags & _TIF_UPROBE) {
|
|
|
|
uprobe_notify_resume(regs);
|
2012-07-20 00:47:55 +08:00
|
|
|
} else {
|
|
|
|
tracehook_notify_resume(regs);
|
2018-06-22 18:45:07 +08:00
|
|
|
rseq_handle_notify_resume(NULL, regs);
|
2012-07-20 00:47:55 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
local_irq_disable();
|
|
|
|
thread_flags = current_thread_info()->flags;
|
|
|
|
} while (thread_flags & _TIF_WORK_MASK);
|
2012-07-20 00:48:21 +08:00
|
|
|
return 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
2013-07-24 07:29:18 +08:00
|
|
|
|
|
|
|
struct page *get_signal_page(void)
|
|
|
|
{
|
2013-08-03 17:30:05 +08:00
|
|
|
unsigned long ptr;
|
|
|
|
unsigned offset;
|
|
|
|
struct page *page;
|
|
|
|
void *addr;
|
2013-07-24 07:29:18 +08:00
|
|
|
|
2013-08-03 17:30:05 +08:00
|
|
|
page = alloc_pages(GFP_KERNEL, 0);
|
2013-07-24 07:29:18 +08:00
|
|
|
|
2013-08-03 17:30:05 +08:00
|
|
|
if (!page)
|
|
|
|
return NULL;
|
2013-07-24 07:29:18 +08:00
|
|
|
|
2013-08-03 17:30:05 +08:00
|
|
|
addr = page_address(page);
|
2013-07-24 07:29:18 +08:00
|
|
|
|
2021-01-29 18:19:07 +08:00
|
|
|
/* Poison the entire page */
|
|
|
|
memset32(addr, __opcode_to_mem_arm(0xe7fddef1),
|
|
|
|
PAGE_SIZE / sizeof(u32));
|
|
|
|
|
2013-08-03 17:30:05 +08:00
|
|
|
/* Give the signal return code some randomness */
|
|
|
|
offset = 0x200 + (get_random_int() & 0x7fc);
|
|
|
|
signal_return_offset = offset;
|
2013-07-24 07:29:18 +08:00
|
|
|
|
2021-01-29 18:19:07 +08:00
|
|
|
/* Copy signal return handlers into the page */
|
2013-08-03 17:30:05 +08:00
|
|
|
memcpy(addr + offset, sigreturn_codes, sizeof(sigreturn_codes));
|
2013-07-24 07:29:18 +08:00
|
|
|
|
2021-01-29 18:19:07 +08:00
|
|
|
/* Flush out all instructions in this page */
|
|
|
|
ptr = (unsigned long)addr;
|
|
|
|
flush_icache_range(ptr, ptr + PAGE_SIZE);
|
2013-07-24 07:29:18 +08:00
|
|
|
|
2013-08-03 17:30:05 +08:00
|
|
|
return page;
|
2013-07-24 07:29:18 +08:00
|
|
|
}
|
2017-09-07 23:30:46 +08:00
|
|
|
|
|
|
|
/* Defer to generic check */
|
|
|
|
asmlinkage void addr_limit_check_failed(void)
|
|
|
|
{
|
2020-08-12 09:33:34 +08:00
|
|
|
#ifdef CONFIG_MMU
|
2017-09-07 23:30:46 +08:00
|
|
|
addr_limit_user_check();
|
2020-08-12 09:33:34 +08:00
|
|
|
#endif
|
2017-09-07 23:30:46 +08:00
|
|
|
}
|
2018-06-02 20:43:56 +08:00
|
|
|
|
|
|
|
#ifdef CONFIG_DEBUG_RSEQ
|
|
|
|
asmlinkage void do_rseq_syscall(struct pt_regs *regs)
|
|
|
|
{
|
|
|
|
rseq_syscall(regs);
|
|
|
|
}
|
|
|
|
#endif
|