diff mbox series

MIPS: kernel: Clear FPU states when setting up kernel threads

Message ID 20231130163601.185270-1-tsbogend@alpha.franken.de (mailing list archive)
State Accepted
Commit a58a173444a68412bb08849bd81c679395f20ca0
Headers show
Series MIPS: kernel: Clear FPU states when setting up kernel threads | expand

Commit Message

Thomas Bogendoerfer Nov. 30, 2023, 4:36 p.m. UTC
io_uring sets up the io worker kernel thread via a syscall out of an
user space prrocess. This process might have used FPU and since
copy_thread() didn't clear FPU states for kernel threads a BUG()
is triggered for using FPU inside kernel. Move code around
to always clear FPU state for user and kernel threads.

Cc: stable@vger.kernel.org
Reported-by: Aurelien Jarno <aurel32@debian.org>
Closes: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1055021
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
---
 arch/mips/kernel/process.c | 25 +++++++++++++------------
 1 file changed, 13 insertions(+), 12 deletions(-)

Comments

Jiaxun Yang Dec. 1, 2023, 11:12 a.m. UTC | #1
在2023年11月30日十一月 下午4:36,Thomas Bogendoerfer写道:
> io_uring sets up the io worker kernel thread via a syscall out of an
> user space prrocess. This process might have used FPU and since
> copy_thread() didn't clear FPU states for kernel threads a BUG()
> is triggered for using FPU inside kernel. Move code around
> to always clear FPU state for user and kernel threads.
>
> Cc: stable@vger.kernel.org
> Reported-by: Aurelien Jarno <aurel32@debian.org>
> Closes: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1055021
> Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>

Reviewed-by: Jiaxun Yang <jiaxun.yang@flygoat.com>

Perhaps
Suggested-by: Jiaxun Yang <jiaxun.yang@flygoat.com>

As well :-)

Thanks
- Jiaxun
> ---
>  arch/mips/kernel/process.c | 25 +++++++++++++------------
>  1 file changed, 13 insertions(+), 12 deletions(-)
>
> diff --git a/arch/mips/kernel/process.c b/arch/mips/kernel/process.c
> index 5387ed0a5186..b630604c577f 100644
> --- a/arch/mips/kernel/process.c
> +++ b/arch/mips/kernel/process.c
> @@ -121,6 +121,19 @@ int copy_thread(struct task_struct *p, const 
> struct kernel_clone_args *args)
>  	/*  Put the stack after the struct pt_regs.  */
>  	childksp = (unsigned long) childregs;
>  	p->thread.cp0_status = (read_c0_status() & ~(ST0_CU2|ST0_CU1)) | 
> ST0_KERNEL_CUMASK;
> +
> +	/*
> +	 * New tasks lose permission to use the fpu. This accelerates context
> +	 * switching for most programs since they don't use the fpu.
> +	 */
> +	clear_tsk_thread_flag(p, TIF_USEDFPU);
> +	clear_tsk_thread_flag(p, TIF_USEDMSA);
> +	clear_tsk_thread_flag(p, TIF_MSA_CTX_LIVE);
> +
> +#ifdef CONFIG_MIPS_MT_FPAFF
> +	clear_tsk_thread_flag(p, TIF_FPUBOUND);
> +#endif /* CONFIG_MIPS_MT_FPAFF */
> +
>  	if (unlikely(args->fn)) {
>  		/* kernel thread */
>  		unsigned long status = p->thread.cp0_status;
> @@ -149,20 +162,8 @@ int copy_thread(struct task_struct *p, const 
> struct kernel_clone_args *args)
>  	p->thread.reg29 = (unsigned long) childregs;
>  	p->thread.reg31 = (unsigned long) ret_from_fork;
> 
> -	/*
> -	 * New tasks lose permission to use the fpu. This accelerates context
> -	 * switching for most programs since they don't use the fpu.
> -	 */
>  	childregs->cp0_status &= ~(ST0_CU2|ST0_CU1);
> 
> -	clear_tsk_thread_flag(p, TIF_USEDFPU);
> -	clear_tsk_thread_flag(p, TIF_USEDMSA);
> -	clear_tsk_thread_flag(p, TIF_MSA_CTX_LIVE);
> -
> -#ifdef CONFIG_MIPS_MT_FPAFF
> -	clear_tsk_thread_flag(p, TIF_FPUBOUND);
> -#endif /* CONFIG_MIPS_MT_FPAFF */
> -
>  #ifdef CONFIG_MIPS_FP_SUPPORT
>  	atomic_set(&p->thread.bd_emu_frame, BD_EMUFRAME_NONE);
>  #endif
> -- 
> 2.35.3
Thomas Bogendoerfer Dec. 5, 2023, 5:51 p.m. UTC | #2
On Thu, Nov 30, 2023 at 05:36:01PM +0100, Thomas Bogendoerfer wrote:
> io_uring sets up the io worker kernel thread via a syscall out of an
> user space prrocess. This process might have used FPU and since
> copy_thread() didn't clear FPU states for kernel threads a BUG()
> is triggered for using FPU inside kernel. Move code around
> to always clear FPU state for user and kernel threads.
> 
> Cc: stable@vger.kernel.org
> Reported-by: Aurelien Jarno <aurel32@debian.org>
> Closes: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1055021
> Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
> ---
>  arch/mips/kernel/process.c | 25 +++++++++++++------------
>  1 file changed, 13 insertions(+), 12 deletions(-)

applied to mips-fixes.

Thomas.
Thomas Bogendoerfer Dec. 5, 2023, 5:52 p.m. UTC | #3
On Fri, Dec 01, 2023 at 11:12:21AM +0000, Jiaxun Yang wrote:
> 
> 
> 在2023年11月30日十一月 下午4:36,Thomas Bogendoerfer写道:
> > io_uring sets up the io worker kernel thread via a syscall out of an
> > user space prrocess. This process might have used FPU and since
> > copy_thread() didn't clear FPU states for kernel threads a BUG()
> > is triggered for using FPU inside kernel. Move code around
> > to always clear FPU state for user and kernel threads.
> >
> > Cc: stable@vger.kernel.org
> > Reported-by: Aurelien Jarno <aurel32@debian.org>
> > Closes: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1055021
> > Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
> 
> Reviewed-by: Jiaxun Yang <jiaxun.yang@flygoat.com>
> 
> Perhaps
> Suggested-by: Jiaxun Yang <jiaxun.yang@flygoat.com>
> 
> As well :-)

I've added both

Thomas.
diff mbox series

Patch

diff --git a/arch/mips/kernel/process.c b/arch/mips/kernel/process.c
index 5387ed0a5186..b630604c577f 100644
--- a/arch/mips/kernel/process.c
+++ b/arch/mips/kernel/process.c
@@ -121,6 +121,19 @@  int copy_thread(struct task_struct *p, const struct kernel_clone_args *args)
 	/*  Put the stack after the struct pt_regs.  */
 	childksp = (unsigned long) childregs;
 	p->thread.cp0_status = (read_c0_status() & ~(ST0_CU2|ST0_CU1)) | ST0_KERNEL_CUMASK;
+
+	/*
+	 * New tasks lose permission to use the fpu. This accelerates context
+	 * switching for most programs since they don't use the fpu.
+	 */
+	clear_tsk_thread_flag(p, TIF_USEDFPU);
+	clear_tsk_thread_flag(p, TIF_USEDMSA);
+	clear_tsk_thread_flag(p, TIF_MSA_CTX_LIVE);
+
+#ifdef CONFIG_MIPS_MT_FPAFF
+	clear_tsk_thread_flag(p, TIF_FPUBOUND);
+#endif /* CONFIG_MIPS_MT_FPAFF */
+
 	if (unlikely(args->fn)) {
 		/* kernel thread */
 		unsigned long status = p->thread.cp0_status;
@@ -149,20 +162,8 @@  int copy_thread(struct task_struct *p, const struct kernel_clone_args *args)
 	p->thread.reg29 = (unsigned long) childregs;
 	p->thread.reg31 = (unsigned long) ret_from_fork;
 
-	/*
-	 * New tasks lose permission to use the fpu. This accelerates context
-	 * switching for most programs since they don't use the fpu.
-	 */
 	childregs->cp0_status &= ~(ST0_CU2|ST0_CU1);
 
-	clear_tsk_thread_flag(p, TIF_USEDFPU);
-	clear_tsk_thread_flag(p, TIF_USEDMSA);
-	clear_tsk_thread_flag(p, TIF_MSA_CTX_LIVE);
-
-#ifdef CONFIG_MIPS_MT_FPAFF
-	clear_tsk_thread_flag(p, TIF_FPUBOUND);
-#endif /* CONFIG_MIPS_MT_FPAFF */
-
 #ifdef CONFIG_MIPS_FP_SUPPORT
 	atomic_set(&p->thread.bd_emu_frame, BD_EMUFRAME_NONE);
 #endif