mirror of
https://github.com/torvalds/linux.git
synced 2026-09-12 20:53:03 +02:00
OpenRISC 7.3 updates
One small item and one bug fix.
* The bug fix is to fix an unchecked access in our or1k_atomic syscall,
I am debating if we should just deprecate this as there is minimal
need for it.
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEE2cRzVK74bBA6Je/xw7McLV5mJ+QFAmqSfncACgkQw7McLV5m
J+TprRAAuyxaYmmnTQqJacQt8OEaVJ5DPsZfCtENwEg9BkXpvzo1F/uK4Enp+YEf
VABscIWCAEKY2BCbn6TYdq6uDAHg9GY0fRUcJ7ERUH9pZt7RD24R6uP0oTIffYL4
wzD5E7DOkVdKHrw5KHB75K4BTPgHPLK2aJxhnS9eX/tYS2yDLQNyFvH5OxZ/uezp
6wJlZhdSdcTTNNBu/ZLj0YHa/22RixqxWHB0Wax061LU4QFjbYo8qufSA1sdP5Do
qz/zjW6fr6ieJOwNKsM6n9BLcCS1OqTNKRrWUbxUYqeni8jX2qXWxnwjOK0RrXH2
nmraEviXMrYGg29BIi914nG1uePp0MeX8LE2+GrBQ8iEMmnJeVk+TDNqGiXT4Zg1
1NTeQaGDJu2aggPlNC2DnnJyKb7KkTceBcpBC1amUco6co7m+TbFzcnqpUcTsVSu
HhH72NGnKmY7aFuMaw6Apl6pqw8C38moXhDo45XkucQzRQJADlIkm4amm8gV+MFk
ivP6OMuW4I08DxUlZw/thUdG6qMXVUKCrVqlohjQFXNKuFeHJM+rfJFXGnEmoSCW
AkFtgCH2wMDcW5BsM1d3YV3Bj4OFYR/YaElx0T83fcTUvGNbwdFQOlmGy06Jo2Hj
Vr/5pvoYbTUdL0uJMLPEG6mZuB5LmW5K4ktGTMTPosunXRQipIk=
=DkYR
-----END PGP SIGNATURE-----
Merge tag 'for-linus' of https://github.com/openrisc/linux
Pull OpenRISC updates from Stafford Horne:
"One small trivial macro cleanup and one bug fix.
The bug fix is to fix an unchecked access in our or1k_atomic syscall,
I am debating if we should just deprecate this as there is minimal
need for it"
* tag 'for-linus' of https://github.com/openrisc/linux:
openrisc: fix arbitrary kernel memory access via or1k_atomic syscall
openrisc: drop unneeded semicolon
This commit is contained in:
commit
fb5b59a6a6
|
|
@ -1223,15 +1223,50 @@ _no_syscall_trace:
|
|||
*
|
||||
*/
|
||||
|
||||
/* Keep this literal; hi()/lo() can't use the UL-suffixed TASK_SIZE. */
|
||||
#define OR1K_ATOMIC_ADDR_LIMIT 0x7ffffffc
|
||||
|
||||
ENTRY(sys_or1k_atomic)
|
||||
/* FIXME: This ignores r3 and always does an XCHG */
|
||||
|
||||
/* Check both user pointers before accessing them. */
|
||||
l.movhi r13,hi(OR1K_ATOMIC_ADDR_LIMIT)
|
||||
l.ori r13,r13,lo(OR1K_ATOMIC_ADDR_LIMIT)
|
||||
l.sfgtu r4,r13
|
||||
l.bf 9f
|
||||
l.nop
|
||||
l.sfgtu r5,r13
|
||||
l.bf 9f
|
||||
l.nop
|
||||
|
||||
DISABLE_INTERRUPTS(r17,r19)
|
||||
l.lwz r29,0(r4)
|
||||
l.lwz r27,0(r5)
|
||||
l.sw 0(r4),r27
|
||||
l.sw 0(r5),r29
|
||||
10: l.lwz r29,0(r4)
|
||||
11: l.lwz r27,0(r5)
|
||||
12: l.sw 0(r4),r27
|
||||
13: l.sw 0(r5),r29
|
||||
ENABLE_INTERRUPTS(r17)
|
||||
l.jr r9
|
||||
l.or r11,r0,r0
|
||||
|
||||
/*
|
||||
* Either pointer was outside user space, or turned out to be
|
||||
* unmapped/inaccessible when we actually touched it.
|
||||
*/
|
||||
9: l.jr r9
|
||||
l.addi r11,r0,-EFAULT
|
||||
|
||||
.section .fixup, "ax"
|
||||
14:
|
||||
ENABLE_INTERRUPTS(r17)
|
||||
l.j 9b
|
||||
l.nop
|
||||
.previous
|
||||
|
||||
.section __ex_table, "a"
|
||||
.long 10b, 14b
|
||||
.long 11b, 14b
|
||||
.long 12b, 14b
|
||||
.long 13b, 14b
|
||||
.previous
|
||||
|
||||
/* ============================================================[ EOF ]=== */
|
||||
|
|
|
|||
|
|
@ -74,11 +74,11 @@ void local_flush_tlb_all(void)
|
|||
|
||||
#define flush_dtlb_page_eir(addr) mtspr(SPR_DTLBEIR, addr)
|
||||
#define flush_dtlb_page_no_eir(addr) \
|
||||
mtspr_off(SPR_DTLBMR_BASE(0), DTLB_OFFSET(addr), 0);
|
||||
mtspr_off(SPR_DTLBMR_BASE(0), DTLB_OFFSET(addr), 0)
|
||||
|
||||
#define flush_itlb_page_eir(addr) mtspr(SPR_ITLBEIR, addr)
|
||||
#define flush_itlb_page_no_eir(addr) \
|
||||
mtspr_off(SPR_ITLBMR_BASE(0), ITLB_OFFSET(addr), 0);
|
||||
mtspr_off(SPR_ITLBMR_BASE(0), ITLB_OFFSET(addr), 0)
|
||||
|
||||
void local_flush_tlb_page(struct vm_area_struct *vma, unsigned long addr)
|
||||
{
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user