# git rev-parse -q --verify 1344a232016dbb0492be81f8517c4bf8fc1c6610^{commit} 1344a232016dbb0492be81f8517c4bf8fc1c6610 already have revision, skipping fetch # git checkout -q -f -B kisskb 1344a232016dbb0492be81f8517c4bf8fc1c6610 # git clean -qxdf # < git log -1 # commit 1344a232016dbb0492be81f8517c4bf8fc1c6610 # Author: Michael Ellerman # Date: Wed Nov 4 22:17:42 2020 +1100 # # powerpc: Use asm_goto_volatile for put_user() # # Andreas reported that commit ee0a49a6870e ("powerpc/uaccess: Switch # __put_user_size_allowed() to __put_user_asm_goto()") broke # CLONE_CHILD_SETTID. # # Further inspection showed that the put_user() in schedule_tail() was # missing entirely, the store not emitted by the compiler. # # <.schedule_tail>: # mflr r0 # std r0,16(r1) # stdu r1,-112(r1) # bl <.finish_task_switch> # ld r9,2496(r3) # cmpdi cr7,r9,0 # bne cr7,<.schedule_tail+0x60> # ld r3,392(r13) # ld r9,1392(r3) # cmpdi cr7,r9,0 # beq cr7,<.schedule_tail+0x3c> # li r4,0 # li r5,0 # bl <.__task_pid_nr_ns> # nop # bl <.calculate_sigpending> # nop # addi r1,r1,112 # ld r0,16(r1) # mtlr r0 # blr # nop # nop # nop # bl <.__balance_callback> # b <.schedule_tail+0x1c> # # Notice there are no stores other than to the stack. There should be a # stw in there for the store to current->set_child_tid. # # This is only seen with GCC 4.9 era compilers (tested with 4.9.3 and # 4.9.4), and only when CONFIG_PPC_KUAP is disabled. # # When CONFIG_PPC_KUAP=y, the inline asm that's part of the isync() # and mtspr() inlined via allow_user_access() seems to be enough to # avoid the bug. # # We already have a macro to work around this (or a similar bug), called # asm_volatile_goto which includes an empty asm block to tickle the # compiler into generating the right code. So use that. # # With this applied the code generation looks more like it will work: # # <.schedule_tail>: # mflr r0 # std r31,-8(r1) # std r0,16(r1) # stdu r1,-144(r1) # std r3,112(r1) # bl <._mcount> # nop # ld r3,112(r1) # bl <.finish_task_switch> # ld r9,2624(r3) # cmpdi cr7,r9,0 # bne cr7,<.schedule_tail+0xa0> # ld r3,2408(r13) # ld r31,1856(r3) # cmpdi cr7,r31,0 # beq cr7,<.schedule_tail+0x80> # li r4,0 # li r5,0 # bl <.__task_pid_nr_ns> # nop # li r9,-1 # clrldi r9,r9,12 # cmpld cr7,r31,r9 # bgt cr7,<.schedule_tail+0x80> # lis r9,16 # rldicr r9,r9,32,31 # subf r9,r31,r9 # cmpldi cr7,r9,3 # ble cr7,<.schedule_tail+0x80> # li r9,0 # stw r3,0(r31) <-- stw # nop # bl <.calculate_sigpending> # nop # addi r1,r1,144 # ld r0,16(r1) # ld r31,-8(r1) # mtlr r0 # blr # nop # bl <.__balance_callback> # b <.schedule_tail+0x30> # # Fixes: ee0a49a6870e ("powerpc/uaccess: Switch __put_user_size_allowed() to __put_user_asm_goto()") # Reported-by: Andreas Schwab # Tested-by: Andreas Schwab # Suggested-by: Christophe Leroy # Signed-off-by: Michael Ellerman # Link: https://lore.kernel.org/r/20201104111742.672142-1-mpe@ellerman.id.au # < /opt/cross/kisskb/korg/gcc-4.9.4-nolibc/powerpc64-linux/bin/powerpc64-linux-gcc --version # < /opt/cross/kisskb/korg/gcc-4.9.4-nolibc/powerpc64-linux/bin/powerpc64-linux-ld --version # < git log --format=%s --max-count=1 1344a232016dbb0492be81f8517c4bf8fc1c6610 # < make -s -j 10 ARCH=powerpc O=/kisskb/build/powerpc-fixes_mvme5100_defconfig_powerpc-gcc4.9 CROSS_COMPILE=/opt/cross/kisskb/korg/gcc-4.9.4-nolibc/powerpc64-linux/bin/powerpc64-linux- mvme5100_defconfig # make -s -j 10 ARCH=powerpc O=/kisskb/build/powerpc-fixes_mvme5100_defconfig_powerpc-gcc4.9 CROSS_COMPILE=/opt/cross/kisskb/korg/gcc-4.9.4-nolibc/powerpc64-linux/bin/powerpc64-linux- INFO: Uncompressed kernel (size 0x50e1a8) overlaps the address of the wrapper(0x400000) INFO: Fixing the link_address of wrapper to (0x600000) Completed OK # rm -rf /kisskb/build/powerpc-fixes_mvme5100_defconfig_powerpc-gcc4.9 # Build took: 0:01:08.373647