From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5C76186341 for ; Tue, 25 Aug 2026 03:00:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787626831; cv=none; b=APPT72fcbv4p0XjD05hPzTKEqPV1rB+vwX4WKdjwktRlWeEyyYLSeCbS47zXQE/sNQ2Sk5g0wlC8UCMU1y7Ev7mT0VGtMDmQJt+5O1ZhyoIfPtSDQ+uxO61nP3f1n/fAsXR8MObNB2FlZkgrHbun1G4HR5uPMU6j2j4qP/a9mPw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787626831; c=relaxed/simple; bh=TMpWxPGsLpIiwp6JBbahP0wchQ0DnC2IVgSLYBbW5cQ=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=HMshEGiKmQr/DrwLWxiFrzftuFo107dPK/thojtV9eye3GFyi9buLuYIBvfUH9ZdQMkpOlmKcoNcbJUPITx/e++K2wOnU2FHjrRqY8R9aMrHYUeyyGFfcb/N7I6pTN5XzsrYzdv+Kg8yW9g4Ccdq9zaPTNmA6mV0z6j8DoMOdV4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=h9YL+qjt; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="h9YL+qjt" Received: by smtp.kernel.org (Postfix) with ESMTPSA id C164F1F000E9; Tue, 25 Aug 2026 03:00:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1787626829; bh=cPAE4cVboM5hv9hjOhe0T85AlNSvm0KsZadonc2+Dfg=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=h9YL+qjt+Wq5n552AwwSzONHhIDT989J4+zgs+Gbk8zxo7E7B+auwiDDqD3rKDTSc nGHrAf8u62MTlQYE+YLo2xUHnesKV4DUmED5YFNYn3XKcZoffGixwmRmbfG+vqGFGs y3DOzxZuO5xpWn7/g4U/tRd+FxcJleyeKPTXG+uCG1/rvkgQBDvhz19q/kxUdNcGe7 YFY8XlAUbLcnitanNtDyQXwEMM9rAi6ha1hJBJuvxD05Z5DOil25fjEgPGqacJVGdr OujmiWdSE8M7ATCxpUcRHVtsbGVr4cyk1FlbNoMjkaVIMe1U5Cmhm9Jw9XNSGID4lb aNhuRy/VE2fSg== Message-ID: <0b3af924-6e87-484c-be0e-11279e28d77b@kernel.org> Date: Mon, 24 Aug 2026 20:00:29 -0700 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] ARC: check user addresses in unaligned access emulation To: =?UTF-8?B?SsOpcsOpbXkgSmVhbg==?= , Vineet Gupta Cc: linux-snps-arc@lists.infradead.org, linux-kernel@vger.kernel.org References: <20260824203740.3689400-2-Jeremy.Jean@oss.cyber.gouv.fr> From: Vineet Gupta Content-Language: en-US In-Reply-To: <20260824203740.3689400-2-Jeremy.Jean@oss.cyber.gouv.fr> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit On 8/24/26 13:37, Jérémy Jean wrote: > ARC700 raises an alignment exception before checking access permissions. > Consequently, a userspace load or store using a misaligned kernel address > reaches misaligned_fixup() before the processor rejects it. How do you know this for sure. Did you run into this issue yourself and were able to prove this ordering. And even if you found some documentation can you confirm this to be happening on real ARC700 hardware. I've been maintaining ARC forever and even do I don't have access to working ARC700 silicon. I can sympathize with your need to send a fix and it might actually be correct. But I can't take a fix that theoretically fixes something w/o demonstrating what real life case it caters so. So Nack, unless you have one of the valid reasons above. -Vineet > misaligned_fixup() decodes the instruction and repeats the access using > byte loads or stores. These accesses run in kernel mode, and exception > tables only handle accesses that fault. A mapped kernel address is > therefore read or written with supervisor permissions. > > Use access_ok() to reject addresses outside the user range before calling > the helpers. Check the whole 2- or 4-byte range and use the checked address > for the emulated operation. > > Fixes: 2e651ea1596b ("ARC: Unaligned access emulation") > Assisted-by: Codex:gpt-daybreak-blue > Signed-off-by: Jérémy Jean > --- > arch/arc/kernel/unaligned.c | 23 +++++++++++++++++++---- > 1 file changed, 19 insertions(+), 4 deletions(-) > > diff --git a/arch/arc/kernel/unaligned.c b/arch/arc/kernel/unaligned.c > index 3b2d8b1bd271..f6079dc89a6d 100644 > --- a/arch/arc/kernel/unaligned.c > +++ b/arch/arc/kernel/unaligned.c > @@ -133,6 +133,8 @@ int no_unaligned_warning __read_mostly = 1; /* Only 1 warning by default */ > static void fixup_load(struct disasm_state *state, struct pt_regs *regs, > struct callee_regs *cregs) > { > + unsigned long address; > + unsigned int size; > int val; > > /* register write back */ > @@ -143,10 +145,15 @@ static void fixup_load(struct disasm_state *state, struct pt_regs *regs, > state->src2 = 0; > } > > + address = state->src1 + state->src2; > + size = state->zz ? 2 : 4; > + if (!access_ok((void __user *)address, size)) > + goto fault; > + > if (state->zz == 0) { > - get32_unaligned_check(val, state->src1 + state->src2); > + get32_unaligned_check(val, address); > } else { > - get16_unaligned_check(val, state->src1 + state->src2); > + get16_unaligned_check(val, address); > > if (state->x) > val = (val << 16) >> 16; > @@ -163,6 +170,9 @@ fault: state->fault = 1; > static void fixup_store(struct disasm_state *state, struct pt_regs *regs, > struct callee_regs *cregs) > { > + unsigned long address; > + unsigned int size; > + > /* register write back */ > if ((state->aa == 1) || (state->aa == 2)) { > set_reg(state->wb_reg, state->src2 + state->src3, regs, cregs); > @@ -181,11 +191,16 @@ static void fixup_store(struct disasm_state *state, struct pt_regs *regs, > } > } > > + address = state->src2 + state->src3; > + size = state->zz ? 2 : 4; > + if (!access_ok((void __user *)address, size)) > + goto fault; > + > /* write fix-up */ > if (!state->zz) > - put32_unaligned_check(state->src1, state->src2 + state->src3); > + put32_unaligned_check(state->src1, address); > else > - put16_unaligned_check(state->src1, state->src2 + state->src3); > + put16_unaligned_check(state->src1, address); > > return; >