mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: alexander.levin@verizon.com
To: "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"stable@vger.kernel.org" <stable@vger.kernel.org>
Cc: Jon Medhurst <tixy@linaro.org>, alexander.levin@verizon.com
Subject: [PATCH AUTOSEL for 4.9 008/100] arm: kprobes: Align stack to 8-bytes in test code
Date: Wed, 13 Dec 2017 01:56:15 +0000	[thread overview]
Message-ID: <20171213015606.6568-8-alexander.levin@verizon.com> (raw)
In-Reply-To: <20171213015606.6568-1-alexander.levin@verizon.com>

From: Jon Medhurst <tixy@linaro.org>

[ Upstream commit 974310d047f3c7788a51d10c8d255eebdb1fa857 ]

kprobes test cases need to have a stack that is aligned to an 8-byte
boundary because they call other functions (and the ARM ABI mandates
that alignment) and because test cases include 64-bit accesses to the
stack. Unfortunately, GCC doesn't ensure this alignment for inline
assembler and for the code in question seems to always misalign it by
pushing just the LR register onto the stack. We therefore need to
explicitly perform stack alignment at the start of each test case.

Without this fix, some test cases will generate alignment faults on
systems where alignment is enforced. Even if the kernel is configured to
handle these faults in software, triggering them is ugly. It also
exposes limitations in the fault handling code which doesn't cope with
writes to the stack. E.g. when handling this instruction

   strd r6, [sp, #-64]!

the fault handling code will write to a stack location below the SP
value at the point the fault occurred, which coincides with where the
exception handler has pushed the saved register context. This results in
corruption of those registers.

Signed-off-by: Jon Medhurst <tixy@linaro.org>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
---
 arch/arm/probes/kprobes/test-core.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

diff --git a/arch/arm/probes/kprobes/test-core.c b/arch/arm/probes/kprobes/test-core.c
index 9775de22e2ff..a48354de1aa1 100644
--- a/arch/arm/probes/kprobes/test-core.c
+++ b/arch/arm/probes/kprobes/test-core.c
@@ -976,7 +976,10 @@ static void coverage_end(void)
 void __naked __kprobes_test_case_start(void)
 {
 	__asm__ __volatile__ (
-		"stmdb	sp!, {r4-r11}				\n\t"
+		"mov	r2, sp					\n\t"
+		"bic	r3, r2, #7				\n\t"
+		"mov	sp, r3					\n\t"
+		"stmdb	sp!, {r2-r11}				\n\t"
 		"sub	sp, sp, #"__stringify(TEST_MEMORY_SIZE)"\n\t"
 		"bic	r0, lr, #1  @ r0 = inline data		\n\t"
 		"mov	r1, sp					\n\t"
@@ -996,7 +999,8 @@ void __naked __kprobes_test_case_end_32(void)
 		"movne	pc, r0					\n\t"
 		"mov	r0, r4					\n\t"
 		"add	sp, sp, #"__stringify(TEST_MEMORY_SIZE)"\n\t"
-		"ldmia	sp!, {r4-r11}				\n\t"
+		"ldmia	sp!, {r2-r11}				\n\t"
+		"mov	sp, r2					\n\t"
 		"mov	pc, r0					\n\t"
 	);
 }
@@ -1012,7 +1016,8 @@ void __naked __kprobes_test_case_end_16(void)
 		"bxne	r0					\n\t"
 		"mov	r0, r4					\n\t"
 		"add	sp, sp, #"__stringify(TEST_MEMORY_SIZE)"\n\t"
-		"ldmia	sp!, {r4-r11}				\n\t"
+		"ldmia	sp!, {r2-r11}				\n\t"
+		"mov	sp, r2					\n\t"
 		"bx	r0					\n\t"
 	);
 }
-- 
2.11.0

  parent reply	other threads:[~2017-12-13  1:57 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-12-13  1:56 [PATCH AUTOSEL for 4.9 001/100] cxl: Route eeh events to all slices for pci_channel_io_perm_failure state alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 003/100] ALSA: hda - add support for docking station for HP 840 G3 alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 002/100] ALSA: hda - add support for docking station for HP 820 G2 alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 004/100] kvm: fix usage of uninit spinlock in avic_vm_destroy() alexander.levin
2017-12-13  1:56 ` alexander.levin [this message]
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 007/100] arm: kprobes: Fix the return address of multiple kretprobes alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 006/100] HID: corsair: Add driver Scimitar Pro RGB gaming mouse 1b1c:1b3e support to hid-corsair alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 005/100] HID: corsair: support for K65-K70 Rapidfire and Scimitar Pro RGB alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 010/100] cpuidle: Validate cpu_dev in cpuidle_add_sysfs() alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 011/100] r8152: fix the list rx_done may be used without initialization alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 009/100] nvme-loop: handle cpu unplug when re-establishing the controller alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 012/100] crypto: deadlock between crypto_alg_sem/rtnl_mutex/genl_mutex alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 015/100] vsock: cancel packets when failing to connect alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 013/100] vsock: track pkt owner vsock alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 014/100] vhost-vsock: add pkt cancel capability alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 016/100] sch_dsmark: fix invalid skb_cow() usage alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 018/100] sctp: out_qlen should be updated when pruning unsent queue alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 019/100] net: qmi_wwan: Add USB IDs for MDM6600 modem on Motorola Droid 4 alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 017/100] bna: integer overflow bug in debugfs alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 021/100] usb: gadget: f_uvc: Sanity check wMaxPacketSize for SuperSpeed alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 023/100] netfilter: nfnl_cthelper: fix runtime expectation policy updates alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 020/100] hwmon: (max31790) Set correct PWM value alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 022/100] usb: gadget: udc: remove pointer dereference after free alexander.levin
2017-12-13  1:56 ` [PATCH AUTOSEL for 4.9 024/100] netfilter: nfnl_cthelper: Fix memory leak alexander.levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20171213015606.6568-8-alexander.levin@verizon.com \
    --to=alexander.levin@verizon.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=tixy@linaro.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®