diff options
| author | Karl Mehltretter <kmehltretter@gmail.com> | 2026-08-20 00:27:12 +0200 |
|---|---|---|
| committer | Will Deacon <will@kernel.org> | 2026-08-27 14:16:04 +0000 |
| commit | f5b8b9037df387394a73aab47c5437bbac975077 (patch) | |
| tree | f900bfa50ab1a9d54f0da6c29ce1b5deeeb7a8fe /tools/perf/scripts/python/net_dropmonitor.py | |
| parent | b8f070ac3167595069feb1f794c127b805115645 (diff) | |
arm64: compat: Fix decrementing LDM/STM alignment emulation
The compat alignment emulator inherited unsigned long data addresses from
the 32-bit ARM implementation.
In do_alignment_ldmstm(), nr_regs is an unsigned int holding the transfer
size. The function uses the same address addition for both transfer
directions, negating nr_regs first for a decrementing LDM or STM. The
32-bit negation wraps before the addition, so the handler adds nearly
4 GiB instead of subtracting the transfer size.
The resulting address lies outside the compat task's address space, so
decrementing LDM/STM emulation fails, while incrementing forms work.
For example, a backwards-moving copy routine using decrementing LDM/STM can
take an alignment fault when called with unaligned pointers. The compat
handler should emulate the transfer, but this bug instead causes SIGBUS.
The offset negated in do_alignment_finish_ldst() is offset_union.un, which
is already unsigned long and does not have this width mismatch.
Make nr_regs unsigned long so its negation and the address arithmetic
use the same width.
Fixes: 3fc24ef32d3b ("arm64: compat: Implement misalignment fixups for multiword loads")
Cc: stable@vger.kernel.org
Suggested-by: Arnd Bergmann <arnd@arndb.de>
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Will Deacon <will@kernel.org>
Diffstat (limited to 'tools/perf/scripts/python/net_dropmonitor.py')
0 files changed, 0 insertions, 0 deletions
