]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
riscv: Fix kernel crash due to PR_SET_TAGGED_ADDR_CTRL
authorNam Cao <namcao@linutronix.de>
Sun, 4 May 2025 10:19:20 +0000 (12:19 +0200)
committerAlexandre Ghiti <alexghiti@rivosinc.com>
Thu, 8 May 2025 12:01:01 +0000 (12:01 +0000)
When userspace does PR_SET_TAGGED_ADDR_CTRL, but Supm extension is not
available, the kernel crashes:

Oops - illegal instruction [#1]
    [snip]
epc : set_tagged_addr_ctrl+0x112/0x15a
 ra : set_tagged_addr_ctrl+0x74/0x15a
epc : ffffffff80011ace ra : ffffffff80011a30 sp : ffffffc60039be10
    [snip]
status: 0000000200000120 badaddr: 0000000010a79073 cause: 0000000000000002
    set_tagged_addr_ctrl+0x112/0x15a
    __riscv_sys_prctl+0x352/0x73c
    do_trap_ecall_u+0x17c/0x20c
    andle_exception+0x150/0x15c

Fix it by checking if Supm is available.

Fixes: 09d6775f503b ("riscv: Add support for userspace pointer masking")
Signed-off-by: Nam Cao <namcao@linutronix.de>
Cc: stable@vger.kernel.org
Reviewed-by: Samuel Holland <samuel.holland@sifive.com>
Link: https://lore.kernel.org/r/20250504101920.3393053-1-namcao@linutronix.de
Signed-off-by: Alexandre Ghiti <alexghiti@rivosinc.com>
arch/riscv/kernel/process.c

index 7c244de7718008947075357ea4502d56419d507c..3db2c0c07acd07083e7b5bb4b7e32fd3692c7dfe 100644 (file)
@@ -275,6 +275,9 @@ long set_tagged_addr_ctrl(struct task_struct *task, unsigned long arg)
        unsigned long pmm;
        u8 pmlen;
 
+       if (!riscv_has_extension_unlikely(RISCV_ISA_EXT_SUPM))
+               return -EINVAL;
+
        if (is_compat_thread(ti))
                return -EINVAL;