]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
ARM: 9464/1: fix input-only operand modification in load_unaligned_zeropad()
authorLiyuan Pang <pangliyuan1@huawei.com>
Tue, 9 Dec 2025 02:19:45 +0000 (03:19 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Mon, 19 Jan 2026 12:09:39 +0000 (13:09 +0100)
[ Upstream commit edb924a7211c9aa7a4a415e03caee4d875e46b8e ]

In the inline assembly inside load_unaligned_zeropad(), the "addr" is
constrained as input-only operand. The compiler assumes that on exit
from the asm statement these operands contain the same values as they
had before executing the statement, but when kernel page fault happened, the assembly fixup code "bic %2 %2, #0x3" modify the value of "addr", which may lead to an unexpected behavior.

Use a temporary variable "tmp" to handle it, instead of modifying the
input-only operand, just like what arm64's load_unaligned_zeropad()
does.

Fixes: b9a50f74905a ("ARM: 7450/1: dcache: select DCACHE_WORD_ACCESS for little-endian ARMv6+ CPUs")
Co-developed-by: Xie Yuanbin <xieyuanbin1@huawei.com>
Signed-off-by: Xie Yuanbin <xieyuanbin1@huawei.com>
Signed-off-by: Liyuan Pang <pangliyuan1@huawei.com>
Signed-off-by: Russell King (Oracle) <rmk+kernel@armlinux.org.uk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
arch/arm/include/asm/word-at-a-time.h

index 352ab213520d20948442ad229a93a310f6f0343a..2e6d0b4349f47264d107edd1d2647d54d3ee34c2 100644 (file)
@@ -66,7 +66,7 @@ static inline unsigned long find_zero(unsigned long mask)
  */
 static inline unsigned long load_unaligned_zeropad(const void *addr)
 {
-       unsigned long ret, offset;
+       unsigned long ret, tmp;
 
        /* Load word from unaligned pointer addr */
        asm(
@@ -74,9 +74,9 @@ static inline unsigned long load_unaligned_zeropad(const void *addr)
        "2:\n"
        "       .pushsection .text.fixup,\"ax\"\n"
        "       .align 2\n"
-       "3:     and     %1, %2, #0x3\n"
-       "       bic     %2, %2, #0x3\n"
-       "       ldr     %0, [%2]\n"
+       "3:     bic     %1, %2, #0x3\n"
+       "       ldr     %0, [%1]\n"
+       "       and     %1, %2, #0x3\n"
        "       lsl     %1, %1, #0x3\n"
 #ifndef __ARMEB__
        "       lsr     %0, %0, %1\n"
@@ -89,7 +89,7 @@ static inline unsigned long load_unaligned_zeropad(const void *addr)
        "       .align  3\n"
        "       .long   1b, 3b\n"
        "       .popsection"
-       : "=&r" (ret), "=&r" (offset)
+       : "=&r" (ret), "=&r" (tmp)
        : "r" (addr), "Qo" (*(unsigned long *)addr));
 
        return ret;