From patchwork Mon Apr 9 00:41:21 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Sasha Levin X-Patchwork-Id: 132960 Delivered-To: patch@linaro.org Received: by 10.46.84.29 with SMTP id i29csp657002ljb; Sun, 8 Apr 2018 17:52:50 -0700 (PDT) X-Google-Smtp-Source: AIpwx491qSW0wce5AZkF0MX0O0pTNp0XCis+j4qh4PRvID54HOdyFfVhw4uReu3LGVXxHv0IVPjO X-Received: by 2002:a17:902:748a:: with SMTP id h10-v6mr2717481pll.160.1523235170648; Sun, 08 Apr 2018 17:52:50 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1523235170; cv=none; d=google.com; s=arc-20160816; b=RiPRnW+nnBuE6ftaU79yGllz/D1phfz2vgMHf+a6QGGllQ1rNgUoosQW/psYfQlKmR H+gvMVc8zhvROEsneAs2wFdzpbBvpRoAX2pgkoXLa4M1snjYvTsOd6Wlg71HAZJNWMdi 72TyjOJJGpeX1Yzyko2uWsb6Hhh2ZDGu4+1cvuP/V8UPQB/Hj9HJa+zQNOr1Ht1VAs5S PEA6zTqYOv3S5OPl115XR58dCTpnFsy30pmSp/oS5ByPvkrheJpekuWy/J8A0jjVCPd/ 8h6d9684dar1zS16AKNzUFEB/2EivbJgAGR85YFCOA+Wd2/yC9C4LbnpWdWNRbS/0k2T J6bA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:content-transfer-encoding :spamdiagnosticmetadata:spamdiagnosticoutput:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature :arc-authentication-results; bh=QFDQoxWb6xMHSnO92LuCW06HI61H1oUwJfcho8andsg=; b=W0KjjpRf3iE/STI5qY7Abqkqsn7q6s6kc2jexKyjb2ei+Hmwim9Y8ZpaZh3RaJ1a83 c4LLyIS80QJAHELK2DMMUPOi1CyMAbjwjskL89GtkQ58+Lv3Mi9Jm96a0DSVNKoZORAx 4orPR53LyMZ87msRbKZ5aP0aJDJiTpCTZR1M775DNsgX8pVpO/eTm79rfxRO3n531s5S IIkY5rKMzu9SnXQ0fnFPePCI+UoQArIGO5wnftMhMILZB+pKlG0JD0gKLzVIY7Axrm/q Rh8Jp6vYy2ngPOHz7pRzu+Xz8Pd0XMJR9zZ4VMoctellcd8Y8xeSuwDxZ2cKgx/rC+0R BSiA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=lMXVBzP7; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id j12si11509343pfh.3.2018.04.08.17.52.50; Sun, 08 Apr 2018 17:52:50 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@microsoft.com header.s=selector1 header.b=lMXVBzP7; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=microsoft.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S933495AbeDIAwS (ORCPT + 29 others); Sun, 8 Apr 2018 20:52:18 -0400 Received: from mail-by2nam03on0126.outbound.protection.outlook.com ([104.47.42.126]:24363 "EHLO NAM03-BY2-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S933421AbeDIAlZ (ORCPT ); Sun, 8 Apr 2018 20:41:25 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=QFDQoxWb6xMHSnO92LuCW06HI61H1oUwJfcho8andsg=; b=lMXVBzP7ZDu2pZ3GxrBVgfT+PmhTZ220M+umh5vVC1OumbH6h8jWt+EUqk1Q5uYEgiHSXhoPCTmQTjyDclEhh86lUqXXjrHHHskREr2wO6PFRKELhAzXQuPoferEfUfll4E9Ub5/lTws2QHBG7lgol3p0G92MYsc7prcbalAe9Y= Received: from DM5PR2101MB1032.namprd21.prod.outlook.com (52.132.128.13) by DM5PR2101MB0901.namprd21.prod.outlook.com (52.132.132.158) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.696.0; Mon, 9 Apr 2018 00:41:22 +0000 Received: from DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8109:aef0:a777:7059]) by DM5PR2101MB1032.namprd21.prod.outlook.com ([fe80::8109:aef0:a777:7059%2]) with mapi id 15.20.0696.003; Mon, 9 Apr 2018 00:41:22 +0000 From: Sasha Levin To: "stable@vger.kernel.org" , "linux-kernel@vger.kernel.org" CC: Dave Martin , Will Deacon , Sasha Levin Subject: [PATCH AUTOSEL for 3.18 057/101] arm64: ptrace: Avoid setting compat FP[SC]R to garbage if get_user fails Thread-Topic: [PATCH AUTOSEL for 3.18 057/101] arm64: ptrace: Avoid setting compat FP[SC]R to garbage if get_user fails Thread-Index: AQHTz5t63zIp/W+nvEOMbAgceMkktw== Date: Mon, 9 Apr 2018 00:41:21 +0000 Message-ID: <20180409004042.164920-7-alexander.levin@microsoft.com> References: <20180409004042.164920-1-alexander.levin@microsoft.com> In-Reply-To: <20180409004042.164920-1-alexander.levin@microsoft.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [52.168.54.252] x-ms-publictraffictype: Email x-microsoft-exchange-diagnostics: 1; DM5PR2101MB0901; 7:Xd0QxPoF6iYGKpyUbt80WN8ymeNdeEuTb8d1KEi306sbNp/ii4AjxnzqOC7pOVMF6f0mc8229RcdwI0lP2dL7zE/dKL4Gu6HhFSsPU5Jg7ud64ZFWdrqzF1VELnXkRDRCazzXtieAiOjjb8mBHIDixaWGvi0yI6DRHoKk4thJleqRMHGXg/WuozuWPCnnxJwxxfLmxSKt4v0dOaoeoJ6Fdf+JdHRgaE1exFsZiAE0I6p3X9DVDswgCJYJ2eUkMhF; 20:bs5gmrZU7DBrQbTiE3orR3kuNfyD6sxdb2Jg50YOTw5PSJtVYAuvqfKPvMxaUjmRoXCNUMfGDyPo0sPThxSwJWZeeXnUfzBbF7iK2NEeCJAYoGxBapQrMBPLPGWaIDc5iDkyhlnR1cLi21qAU2BzFJjBeVzJNJshLVn23V002A4= x-ms-office365-filtering-ht: Tenant X-MS-Office365-Filtering-Correlation-Id: 77d37509-af0b-4b39-b1f9-08d59db29e06 x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(48565401081)(5600026)(4604075)(3008032)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603328)(7193020); SRVR:DM5PR2101MB0901; x-ms-traffictypediagnostic: DM5PR2101MB0901: authentication-results: spf=none (sender IP is ) smtp.mailfrom=Alexander.Levin@microsoft.com; x-microsoft-antispam-prvs: x-exchange-antispam-report-test: UriScan:(28532068793085)(180628864354917)(89211679590171); x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(61425038)(6040522)(2401047)(8121501046)(5005006)(93006095)(93001095)(3231221)(944501327)(52105095)(3002001)(10201501046)(6055026)(61426038)(61427038)(6041310)(20161123562045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123558120)(20161123564045)(20161123560045)(6072148)(201708071742011); SRVR:DM5PR2101MB0901; BCL:0; PCL:0; RULEID:; SRVR:DM5PR2101MB0901; x-forefront-prvs: 0637FCE711 x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39860400002)(39380400002)(376002)(346002)(396003)(366004)(189003)(199004)(99286004)(68736007)(10290500003)(25786009)(86612001)(6116002)(66066001)(97736004)(3846002)(76176011)(6512007)(54906003)(6436002)(4326008)(53936002)(105586002)(110136005)(6486002)(3280700002)(1076002)(107886003)(8676002)(10090500001)(2501003)(81156014)(81166006)(5660300001)(14454004)(186003)(3660700001)(102836004)(7736002)(2906002)(26005)(5250100002)(36756003)(478600001)(446003)(316002)(6506007)(2616005)(106356001)(8936002)(11346002)(22452003)(2900100001)(86362001)(486006)(476003)(305945005)(72206003)(22906009)(217873001); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR2101MB0901; H:DM5PR2101MB1032.namprd21.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1; received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts) x-microsoft-antispam-message-info: vLgjRz/zANIr2eRJVi7Y9n33j3O8YZLtFJs1GRWfgpKMmusVfq4jG06o+gv97NCibfVTKBdTHsP9awTfEQYoEcuNgHDmr+w1/4VBOGECx2NbMWul0NwbS0jGCTZbRVrNiBu0QANiFv7yNNzE9AX4w0hAo5Mku4CCM7oh3eHGQlsWqs93KJy7UHSdknAfy0zs1ae6a5ez8s1iOpSR3q8NSxkDIHEdw+JgSQQHf6TNu3id/Q8BXHh9HTcXTjBlBxuoO6PZ/F/F0xM9mS/lYcGUOt2ka+cZZvaj0bXKePsv2GzsyoxhEVadI6bAhdCq1QqfzV4jExQVuL04M715LSy3yPtOH1CbwA3lf+qhdLAfdCnP0nN29n4HNRR95ixGazsx8IlizyoIDHKOkz+8tH3g+oh+N3LzTjyh9oW5CO0TOT4= spamdiagnosticoutput: 1:99 spamdiagnosticmetadata: NSPM MIME-Version: 1.0 X-OriginatorOrg: microsoft.com X-MS-Exchange-CrossTenant-Network-Message-Id: 77d37509-af0b-4b39-b1f9-08d59db29e06 X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Apr 2018 00:41:21.2677 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR2101MB0901 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Dave Martin [ Upstream commit 53b1a742ed251780267a57415bc955bd50f40c3d ] If get_user() fails when reading the new FPSCR value from userspace in compat_vfp_get(), then garbage* will be written to the task's FPSR and FPCR registers. This patch prevents this by checking the return from get_user() first. [*] Actually, zero, due to the behaviour of get_user() on error, but that's still not what userspace expects. Fixes: 478fcb2cdb23 ("arm64: Debugging support") Signed-off-by: Dave Martin Signed-off-by: Will Deacon Signed-off-by: Sasha Levin --- arch/arm64/kernel/ptrace.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) -- 2.15.1 diff --git a/arch/arm64/kernel/ptrace.c b/arch/arm64/kernel/ptrace.c index 2e845f5c8ab2..a12eb17e7985 100644 --- a/arch/arm64/kernel/ptrace.c +++ b/arch/arm64/kernel/ptrace.c @@ -785,8 +785,10 @@ static int compat_vfp_set(struct task_struct *target, if (count && !ret) { ret = get_user(fpscr, (compat_ulong_t *)ubuf); - uregs->fpsr = fpscr & VFP_FPSCR_STAT_MASK; - uregs->fpcr = fpscr & VFP_FPSCR_CTRL_MASK; + if (!ret) { + uregs->fpsr = fpscr & VFP_FPSCR_STAT_MASK; + uregs->fpcr = fpscr & VFP_FPSCR_CTRL_MASK; + } } fpsimd_flush_task_state(target);