Linux Audio

Check our new training course

Loading...
v4.17
  1// SPDX-License-Identifier: GPL-2.0
  2/*
  3 *  Copyright (C) 1991, 1992  Linus Torvalds
  4 *  Copyright (C) 2000, 2001, 2002 Andi Kleen SuSE Labs
  5 *
  6 *  1997-11-28  Modified for POSIX.1b signals by Richard Henderson
  7 *  2000-06-20  Pentium III FXSR, SSE support by Gareth Hughes
  8 *  2000-2002   x86-64 support by Andi Kleen
  9 */
 10
 11#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
 12
 13#include <linux/sched.h>
 14#include <linux/sched/task_stack.h>
 15#include <linux/mm.h>
 16#include <linux/smp.h>
 17#include <linux/kernel.h>
 18#include <linux/errno.h>
 19#include <linux/wait.h>
 20#include <linux/tracehook.h>
 21#include <linux/unistd.h>
 22#include <linux/stddef.h>
 23#include <linux/personality.h>
 24#include <linux/uaccess.h>
 25#include <linux/user-return-notifier.h>
 26#include <linux/uprobes.h>
 27#include <linux/context_tracking.h>
 28#include <linux/syscalls.h>
 29
 30#include <asm/processor.h>
 31#include <asm/ucontext.h>
 32#include <asm/fpu/internal.h>
 33#include <asm/fpu/signal.h>
 34#include <asm/vdso.h>
 35#include <asm/mce.h>
 36#include <asm/sighandling.h>
 37#include <asm/vm86.h>
 38
 39#ifdef CONFIG_X86_64
 40#include <asm/proto.h>
 41#include <asm/ia32_unistd.h>
 42#endif /* CONFIG_X86_64 */
 43
 44#include <asm/syscall.h>
 45#include <asm/syscalls.h>
 46
 47#include <asm/sigframe.h>
 48#include <asm/signal.h>
 49
 50#define COPY(x)			do {			\
 51	get_user_ex(regs->x, &sc->x);			\
 52} while (0)
 53
 54#define GET_SEG(seg)		({			\
 55	unsigned short tmp;				\
 56	get_user_ex(tmp, &sc->seg);			\
 57	tmp;						\
 58})
 59
 60#define COPY_SEG(seg)		do {			\
 61	regs->seg = GET_SEG(seg);			\
 62} while (0)
 63
 64#define COPY_SEG_CPL3(seg)	do {			\
 65	regs->seg = GET_SEG(seg) | 3;			\
 66} while (0)
 67
 68#ifdef CONFIG_X86_64
 69/*
 70 * If regs->ss will cause an IRET fault, change it.  Otherwise leave it
 71 * alone.  Using this generally makes no sense unless
 72 * user_64bit_mode(regs) would return true.
 73 */
 74static void force_valid_ss(struct pt_regs *regs)
 75{
 76	u32 ar;
 77	asm volatile ("lar %[old_ss], %[ar]\n\t"
 78		      "jz 1f\n\t"		/* If invalid: */
 79		      "xorl %[ar], %[ar]\n\t"	/* set ar = 0 */
 80		      "1:"
 81		      : [ar] "=r" (ar)
 82		      : [old_ss] "rm" ((u16)regs->ss));
 83
 84	/*
 85	 * For a valid 64-bit user context, we need DPL 3, type
 86	 * read-write data or read-write exp-down data, and S and P
 87	 * set.  We can't use VERW because VERW doesn't check the
 88	 * P bit.
 89	 */
 90	ar &= AR_DPL_MASK | AR_S | AR_P | AR_TYPE_MASK;
 91	if (ar != (AR_DPL3 | AR_S | AR_P | AR_TYPE_RWDATA) &&
 92	    ar != (AR_DPL3 | AR_S | AR_P | AR_TYPE_RWDATA_EXPDOWN))
 93		regs->ss = __USER_DS;
 94}
 95#endif
 96
 97static int restore_sigcontext(struct pt_regs *regs,
 98			      struct sigcontext __user *sc,
 99			      unsigned long uc_flags)
100{
101	unsigned long buf_val;
102	void __user *buf;
103	unsigned int tmpflags;
104	unsigned int err = 0;
105
106	/* Always make any pending restarted system calls return -EINTR */
107	current->restart_block.fn = do_no_restart_syscall;
108
109	get_user_try {
110
111#ifdef CONFIG_X86_32
112		set_user_gs(regs, GET_SEG(gs));
113		COPY_SEG(fs);
114		COPY_SEG(es);
115		COPY_SEG(ds);
116#endif /* CONFIG_X86_32 */
117
118		COPY(di); COPY(si); COPY(bp); COPY(sp); COPY(bx);
119		COPY(dx); COPY(cx); COPY(ip); COPY(ax);
120
121#ifdef CONFIG_X86_64
122		COPY(r8);
123		COPY(r9);
124		COPY(r10);
125		COPY(r11);
126		COPY(r12);
127		COPY(r13);
128		COPY(r14);
129		COPY(r15);
130#endif /* CONFIG_X86_64 */
131
132		COPY_SEG_CPL3(cs);
133		COPY_SEG_CPL3(ss);
134
135#ifdef CONFIG_X86_64
136		/*
137		 * Fix up SS if needed for the benefit of old DOSEMU and
138		 * CRIU.
139		 */
140		if (unlikely(!(uc_flags & UC_STRICT_RESTORE_SS) &&
141			     user_64bit_mode(regs)))
142			force_valid_ss(regs);
143#endif
144
145		get_user_ex(tmpflags, &sc->flags);
146		regs->flags = (regs->flags & ~FIX_EFLAGS) | (tmpflags & FIX_EFLAGS);
147		regs->orig_ax = -1;		/* disable syscall checks */
148
149		get_user_ex(buf_val, &sc->fpstate);
150		buf = (void __user *)buf_val;
151	} get_user_catch(err);
152
153	err |= fpu__restore_sig(buf, IS_ENABLED(CONFIG_X86_32));
154
155	force_iret();
156
157	return err;
158}
159
160int setup_sigcontext(struct sigcontext __user *sc, void __user *fpstate,
161		     struct pt_regs *regs, unsigned long mask)
162{
163	int err = 0;
164
165	put_user_try {
166
167#ifdef CONFIG_X86_32
168		put_user_ex(get_user_gs(regs), (unsigned int __user *)&sc->gs);
169		put_user_ex(regs->fs, (unsigned int __user *)&sc->fs);
170		put_user_ex(regs->es, (unsigned int __user *)&sc->es);
171		put_user_ex(regs->ds, (unsigned int __user *)&sc->ds);
172#endif /* CONFIG_X86_32 */
173
174		put_user_ex(regs->di, &sc->di);
175		put_user_ex(regs->si, &sc->si);
176		put_user_ex(regs->bp, &sc->bp);
177		put_user_ex(regs->sp, &sc->sp);
178		put_user_ex(regs->bx, &sc->bx);
179		put_user_ex(regs->dx, &sc->dx);
180		put_user_ex(regs->cx, &sc->cx);
181		put_user_ex(regs->ax, &sc->ax);
182#ifdef CONFIG_X86_64
183		put_user_ex(regs->r8, &sc->r8);
184		put_user_ex(regs->r9, &sc->r9);
185		put_user_ex(regs->r10, &sc->r10);
186		put_user_ex(regs->r11, &sc->r11);
187		put_user_ex(regs->r12, &sc->r12);
188		put_user_ex(regs->r13, &sc->r13);
189		put_user_ex(regs->r14, &sc->r14);
190		put_user_ex(regs->r15, &sc->r15);
191#endif /* CONFIG_X86_64 */
192
193		put_user_ex(current->thread.trap_nr, &sc->trapno);
194		put_user_ex(current->thread.error_code, &sc->err);
195		put_user_ex(regs->ip, &sc->ip);
196#ifdef CONFIG_X86_32
197		put_user_ex(regs->cs, (unsigned int __user *)&sc->cs);
198		put_user_ex(regs->flags, &sc->flags);
199		put_user_ex(regs->sp, &sc->sp_at_signal);
200		put_user_ex(regs->ss, (unsigned int __user *)&sc->ss);
201#else /* !CONFIG_X86_32 */
202		put_user_ex(regs->flags, &sc->flags);
203		put_user_ex(regs->cs, &sc->cs);
204		put_user_ex(0, &sc->gs);
205		put_user_ex(0, &sc->fs);
206		put_user_ex(regs->ss, &sc->ss);
207#endif /* CONFIG_X86_32 */
208
209		put_user_ex(fpstate, &sc->fpstate);
210
211		/* non-iBCS2 extensions.. */
212		put_user_ex(mask, &sc->oldmask);
213		put_user_ex(current->thread.cr2, &sc->cr2);
214	} put_user_catch(err);
215
216	return err;
217}
218
219/*
220 * Set up a signal frame.
221 */
222
223/*
224 * Determine which stack to use..
225 */
226static unsigned long align_sigframe(unsigned long sp)
227{
228#ifdef CONFIG_X86_32
229	/*
230	 * Align the stack pointer according to the i386 ABI,
231	 * i.e. so that on function entry ((sp + 4) & 15) == 0.
232	 */
233	sp = ((sp + 4) & -16ul) - 4;
234#else /* !CONFIG_X86_32 */
235	sp = round_down(sp, 16) - 8;
236#endif
237	return sp;
238}
239
240static void __user *
241get_sigframe(struct k_sigaction *ka, struct pt_regs *regs, size_t frame_size,
242	     void __user **fpstate)
243{
244	/* Default to using normal stack */
245	unsigned long math_size = 0;
246	unsigned long sp = regs->sp;
247	unsigned long buf_fx = 0;
248	int onsigstack = on_sig_stack(sp);
249	struct fpu *fpu = &current->thread.fpu;
250
251	/* redzone */
252	if (IS_ENABLED(CONFIG_X86_64))
253		sp -= 128;
254
255	/* This is the X/Open sanctioned signal stack switching.  */
256	if (ka->sa.sa_flags & SA_ONSTACK) {
257		if (sas_ss_flags(sp) == 0)
258			sp = current->sas_ss_sp + current->sas_ss_size;
259	} else if (IS_ENABLED(CONFIG_X86_32) &&
260		   !onsigstack &&
261		   regs->ss != __USER_DS &&
262		   !(ka->sa.sa_flags & SA_RESTORER) &&
263		   ka->sa.sa_restorer) {
264		/* This is the legacy signal stack switching. */
265		sp = (unsigned long) ka->sa.sa_restorer;
266	}
267
268	if (fpu->initialized) {
269		sp = fpu__alloc_mathframe(sp, IS_ENABLED(CONFIG_X86_32),
270					  &buf_fx, &math_size);
271		*fpstate = (void __user *)sp;
272	}
273
274	sp = align_sigframe(sp - frame_size);
275
276	/*
277	 * If we are on the alternate signal stack and would overflow it, don't.
278	 * Return an always-bogus address instead so we will die with SIGSEGV.
279	 */
280	if (onsigstack && !likely(on_sig_stack(sp)))
281		return (void __user *)-1L;
282
283	/* save i387 and extended state */
284	if (fpu->initialized &&
285	    copy_fpstate_to_sigframe(*fpstate, (void __user *)buf_fx, math_size) < 0)
286		return (void __user *)-1L;
287
288	return (void __user *)sp;
289}
290
291#ifdef CONFIG_X86_32
292static const struct {
293	u16 poplmovl;
294	u32 val;
295	u16 int80;
296} __attribute__((packed)) retcode = {
297	0xb858,		/* popl %eax; movl $..., %eax */
298	__NR_sigreturn,
299	0x80cd,		/* int $0x80 */
300};
301
302static const struct {
303	u8  movl;
304	u32 val;
305	u16 int80;
306	u8  pad;
307} __attribute__((packed)) rt_retcode = {
308	0xb8,		/* movl $..., %eax */
309	__NR_rt_sigreturn,
310	0x80cd,		/* int $0x80 */
311	0
312};
313
314static int
315__setup_frame(int sig, struct ksignal *ksig, sigset_t *set,
316	      struct pt_regs *regs)
317{
318	struct sigframe __user *frame;
319	void __user *restorer;
320	int err = 0;
321	void __user *fpstate = NULL;
322
323	frame = get_sigframe(&ksig->ka, regs, sizeof(*frame), &fpstate);
324
325	if (!access_ok(VERIFY_WRITE, frame, sizeof(*frame)))
326		return -EFAULT;
327
328	if (__put_user(sig, &frame->sig))
329		return -EFAULT;
330
331	if (setup_sigcontext(&frame->sc, fpstate, regs, set->sig[0]))
332		return -EFAULT;
333
334	if (_NSIG_WORDS > 1) {
335		if (__copy_to_user(&frame->extramask, &set->sig[1],
336				   sizeof(frame->extramask)))
337			return -EFAULT;
338	}
339
340	if (current->mm->context.vdso)
341		restorer = current->mm->context.vdso +
342			vdso_image_32.sym___kernel_sigreturn;
343	else
344		restorer = &frame->retcode;
345	if (ksig->ka.sa.sa_flags & SA_RESTORER)
346		restorer = ksig->ka.sa.sa_restorer;
347
348	/* Set up to return from userspace.  */
349	err |= __put_user(restorer, &frame->pretcode);
350
351	/*
352	 * This is popl %eax ; movl $__NR_sigreturn, %eax ; int $0x80
353	 *
354	 * WE DO NOT USE IT ANY MORE! It's only left here for historical
355	 * reasons and because gdb uses it as a signature to notice
356	 * signal handler stack frames.
357	 */
358	err |= __put_user(*((u64 *)&retcode), (u64 *)frame->retcode);
359
360	if (err)
361		return -EFAULT;
362
363	/* Set up registers for signal handler */
364	regs->sp = (unsigned long)frame;
365	regs->ip = (unsigned long)ksig->ka.sa.sa_handler;
366	regs->ax = (unsigned long)sig;
367	regs->dx = 0;
368	regs->cx = 0;
369
370	regs->ds = __USER_DS;
371	regs->es = __USER_DS;
372	regs->ss = __USER_DS;
373	regs->cs = __USER_CS;
374
375	return 0;
376}
377
378static int __setup_rt_frame(int sig, struct ksignal *ksig,
379			    sigset_t *set, struct pt_regs *regs)
380{
381	struct rt_sigframe __user *frame;
382	void __user *restorer;
383	int err = 0;
384	void __user *fpstate = NULL;
385
386	frame = get_sigframe(&ksig->ka, regs, sizeof(*frame), &fpstate);
387
388	if (!access_ok(VERIFY_WRITE, frame, sizeof(*frame)))
389		return -EFAULT;
390
391	put_user_try {
392		put_user_ex(sig, &frame->sig);
393		put_user_ex(&frame->info, &frame->pinfo);
394		put_user_ex(&frame->uc, &frame->puc);
395
396		/* Create the ucontext.  */
397		if (boot_cpu_has(X86_FEATURE_XSAVE))
398			put_user_ex(UC_FP_XSTATE, &frame->uc.uc_flags);
399		else
400			put_user_ex(0, &frame->uc.uc_flags);
401		put_user_ex(0, &frame->uc.uc_link);
402		save_altstack_ex(&frame->uc.uc_stack, regs->sp);
403
404		/* Set up to return from userspace.  */
405		restorer = current->mm->context.vdso +
406			vdso_image_32.sym___kernel_rt_sigreturn;
407		if (ksig->ka.sa.sa_flags & SA_RESTORER)
408			restorer = ksig->ka.sa.sa_restorer;
409		put_user_ex(restorer, &frame->pretcode);
410
411		/*
412		 * This is movl $__NR_rt_sigreturn, %ax ; int $0x80
413		 *
414		 * WE DO NOT USE IT ANY MORE! It's only left here for historical
415		 * reasons and because gdb uses it as a signature to notice
416		 * signal handler stack frames.
417		 */
418		put_user_ex(*((u64 *)&rt_retcode), (u64 *)frame->retcode);
419	} put_user_catch(err);
420	
421	err |= copy_siginfo_to_user(&frame->info, &ksig->info);
422	err |= setup_sigcontext(&frame->uc.uc_mcontext, fpstate,
423				regs, set->sig[0]);
424	err |= __copy_to_user(&frame->uc.uc_sigmask, set, sizeof(*set));
425
426	if (err)
427		return -EFAULT;
428
429	/* Set up registers for signal handler */
430	regs->sp = (unsigned long)frame;
431	regs->ip = (unsigned long)ksig->ka.sa.sa_handler;
432	regs->ax = (unsigned long)sig;
433	regs->dx = (unsigned long)&frame->info;
434	regs->cx = (unsigned long)&frame->uc;
435
436	regs->ds = __USER_DS;
437	regs->es = __USER_DS;
438	regs->ss = __USER_DS;
439	regs->cs = __USER_CS;
440
441	return 0;
442}
443#else /* !CONFIG_X86_32 */
444static unsigned long frame_uc_flags(struct pt_regs *regs)
445{
446	unsigned long flags;
447
448	if (boot_cpu_has(X86_FEATURE_XSAVE))
449		flags = UC_FP_XSTATE | UC_SIGCONTEXT_SS;
450	else
451		flags = UC_SIGCONTEXT_SS;
452
453	if (likely(user_64bit_mode(regs)))
454		flags |= UC_STRICT_RESTORE_SS;
455
456	return flags;
457}
458
459static int __setup_rt_frame(int sig, struct ksignal *ksig,
460			    sigset_t *set, struct pt_regs *regs)
461{
462	struct rt_sigframe __user *frame;
463	void __user *fp = NULL;
464	int err = 0;
465
466	frame = get_sigframe(&ksig->ka, regs, sizeof(struct rt_sigframe), &fp);
467
468	if (!access_ok(VERIFY_WRITE, frame, sizeof(*frame)))
469		return -EFAULT;
470
471	if (ksig->ka.sa.sa_flags & SA_SIGINFO) {
472		if (copy_siginfo_to_user(&frame->info, &ksig->info))
473			return -EFAULT;
474	}
475
476	put_user_try {
477		/* Create the ucontext.  */
478		put_user_ex(frame_uc_flags(regs), &frame->uc.uc_flags);
479		put_user_ex(0, &frame->uc.uc_link);
480		save_altstack_ex(&frame->uc.uc_stack, regs->sp);
481
482		/* Set up to return from userspace.  If provided, use a stub
483		   already in userspace.  */
484		/* x86-64 should always use SA_RESTORER. */
485		if (ksig->ka.sa.sa_flags & SA_RESTORER) {
486			put_user_ex(ksig->ka.sa.sa_restorer, &frame->pretcode);
487		} else {
488			/* could use a vstub here */
489			err |= -EFAULT;
490		}
491	} put_user_catch(err);
492
493	err |= setup_sigcontext(&frame->uc.uc_mcontext, fp, regs, set->sig[0]);
494	err |= __copy_to_user(&frame->uc.uc_sigmask, set, sizeof(*set));
495
496	if (err)
497		return -EFAULT;
498
499	/* Set up registers for signal handler */
500	regs->di = sig;
501	/* In case the signal handler was declared without prototypes */
502	regs->ax = 0;
503
504	/* This also works for non SA_SIGINFO handlers because they expect the
505	   next argument after the signal number on the stack. */
506	regs->si = (unsigned long)&frame->info;
507	regs->dx = (unsigned long)&frame->uc;
508	regs->ip = (unsigned long) ksig->ka.sa.sa_handler;
509
510	regs->sp = (unsigned long)frame;
511
512	/*
513	 * Set up the CS and SS registers to run signal handlers in
514	 * 64-bit mode, even if the handler happens to be interrupting
515	 * 32-bit or 16-bit code.
516	 *
517	 * SS is subtle.  In 64-bit mode, we don't need any particular
518	 * SS descriptor, but we do need SS to be valid.  It's possible
519	 * that the old SS is entirely bogus -- this can happen if the
520	 * signal we're trying to deliver is #GP or #SS caused by a bad
521	 * SS value.  We also have a compatbility issue here: DOSEMU
522	 * relies on the contents of the SS register indicating the
523	 * SS value at the time of the signal, even though that code in
524	 * DOSEMU predates sigreturn's ability to restore SS.  (DOSEMU
525	 * avoids relying on sigreturn to restore SS; instead it uses
526	 * a trampoline.)  So we do our best: if the old SS was valid,
527	 * we keep it.  Otherwise we replace it.
528	 */
529	regs->cs = __USER_CS;
530
531	if (unlikely(regs->ss != __USER_DS))
532		force_valid_ss(regs);
533
534	return 0;
535}
536#endif /* CONFIG_X86_32 */
537
538static int x32_setup_rt_frame(struct ksignal *ksig,
539			      compat_sigset_t *set,
540			      struct pt_regs *regs)
541{
542#ifdef CONFIG_X86_X32_ABI
543	struct rt_sigframe_x32 __user *frame;
544	void __user *restorer;
545	int err = 0;
546	void __user *fpstate = NULL;
547
548	frame = get_sigframe(&ksig->ka, regs, sizeof(*frame), &fpstate);
549
550	if (!access_ok(VERIFY_WRITE, frame, sizeof(*frame)))
551		return -EFAULT;
552
553	if (ksig->ka.sa.sa_flags & SA_SIGINFO) {
554		if (__copy_siginfo_to_user32(&frame->info, &ksig->info, true))
555			return -EFAULT;
556	}
557
558	put_user_try {
559		/* Create the ucontext.  */
560		put_user_ex(frame_uc_flags(regs), &frame->uc.uc_flags);
561		put_user_ex(0, &frame->uc.uc_link);
562		compat_save_altstack_ex(&frame->uc.uc_stack, regs->sp);
563		put_user_ex(0, &frame->uc.uc__pad0);
564
565		if (ksig->ka.sa.sa_flags & SA_RESTORER) {
566			restorer = ksig->ka.sa.sa_restorer;
567		} else {
568			/* could use a vstub here */
569			restorer = NULL;
570			err |= -EFAULT;
571		}
572		put_user_ex(restorer, &frame->pretcode);
573	} put_user_catch(err);
574
575	err |= setup_sigcontext(&frame->uc.uc_mcontext, fpstate,
576				regs, set->sig[0]);
577	err |= __copy_to_user(&frame->uc.uc_sigmask, set, sizeof(*set));
578
579	if (err)
580		return -EFAULT;
581
582	/* Set up registers for signal handler */
583	regs->sp = (unsigned long) frame;
584	regs->ip = (unsigned long) ksig->ka.sa.sa_handler;
585
586	/* We use the x32 calling convention here... */
587	regs->di = ksig->sig;
588	regs->si = (unsigned long) &frame->info;
589	regs->dx = (unsigned long) &frame->uc;
590
591	loadsegment(ds, __USER_DS);
592	loadsegment(es, __USER_DS);
593
594	regs->cs = __USER_CS;
595	regs->ss = __USER_DS;
596#endif	/* CONFIG_X86_X32_ABI */
597
598	return 0;
599}
600
601/*
602 * Do a signal return; undo the signal stack.
603 */
604#ifdef CONFIG_X86_32
605SYSCALL_DEFINE0(sigreturn)
606{
607	struct pt_regs *regs = current_pt_regs();
608	struct sigframe __user *frame;
609	sigset_t set;
610
611	frame = (struct sigframe __user *)(regs->sp - 8);
612
613	if (!access_ok(VERIFY_READ, frame, sizeof(*frame)))
614		goto badframe;
615	if (__get_user(set.sig[0], &frame->sc.oldmask) || (_NSIG_WORDS > 1
616		&& __copy_from_user(&set.sig[1], &frame->extramask,
617				    sizeof(frame->extramask))))
618		goto badframe;
619
620	set_current_blocked(&set);
621
622	/*
623	 * x86_32 has no uc_flags bits relevant to restore_sigcontext.
624	 * Save a few cycles by skipping the __get_user.
625	 */
626	if (restore_sigcontext(regs, &frame->sc, 0))
627		goto badframe;
628	return regs->ax;
629
630badframe:
631	signal_fault(regs, frame, "sigreturn");
632
633	return 0;
634}
635#endif /* CONFIG_X86_32 */
636
637SYSCALL_DEFINE0(rt_sigreturn)
638{
639	struct pt_regs *regs = current_pt_regs();
640	struct rt_sigframe __user *frame;
641	sigset_t set;
642	unsigned long uc_flags;
643
644	frame = (struct rt_sigframe __user *)(regs->sp - sizeof(long));
645	if (!access_ok(VERIFY_READ, frame, sizeof(*frame)))
646		goto badframe;
647	if (__copy_from_user(&set, &frame->uc.uc_sigmask, sizeof(set)))
648		goto badframe;
649	if (__get_user(uc_flags, &frame->uc.uc_flags))
650		goto badframe;
651
652	set_current_blocked(&set);
653
654	if (restore_sigcontext(regs, &frame->uc.uc_mcontext, uc_flags))
655		goto badframe;
656
657	if (restore_altstack(&frame->uc.uc_stack))
658		goto badframe;
659
660	return regs->ax;
661
662badframe:
663	signal_fault(regs, frame, "rt_sigreturn");
664	return 0;
665}
666
667static inline int is_ia32_compat_frame(struct ksignal *ksig)
668{
669	return IS_ENABLED(CONFIG_IA32_EMULATION) &&
670		ksig->ka.sa.sa_flags & SA_IA32_ABI;
671}
672
673static inline int is_ia32_frame(struct ksignal *ksig)
674{
675	return IS_ENABLED(CONFIG_X86_32) || is_ia32_compat_frame(ksig);
676}
677
678static inline int is_x32_frame(struct ksignal *ksig)
679{
680	return IS_ENABLED(CONFIG_X86_X32_ABI) &&
681		ksig->ka.sa.sa_flags & SA_X32_ABI;
682}
683
684static int
685setup_rt_frame(struct ksignal *ksig, struct pt_regs *regs)
686{
687	int usig = ksig->sig;
688	sigset_t *set = sigmask_to_save();
689	compat_sigset_t *cset = (compat_sigset_t *) set;
690
691	/* Set up the stack frame */
692	if (is_ia32_frame(ksig)) {
693		if (ksig->ka.sa.sa_flags & SA_SIGINFO)
694			return ia32_setup_rt_frame(usig, ksig, cset, regs);
695		else
696			return ia32_setup_frame(usig, ksig, cset, regs);
697	} else if (is_x32_frame(ksig)) {
698		return x32_setup_rt_frame(ksig, cset, regs);
699	} else {
700		return __setup_rt_frame(ksig->sig, ksig, set, regs);
701	}
702}
703
704static void
705handle_signal(struct ksignal *ksig, struct pt_regs *regs)
706{
707	bool stepping, failed;
708	struct fpu *fpu = &current->thread.fpu;
709
710	if (v8086_mode(regs))
711		save_v86_state((struct kernel_vm86_regs *) regs, VM86_SIGNAL);
712
713	/* Are we from a system call? */
714	if (syscall_get_nr(current, regs) >= 0) {
715		/* If so, check system call restarting.. */
716		switch (syscall_get_error(current, regs)) {
717		case -ERESTART_RESTARTBLOCK:
718		case -ERESTARTNOHAND:
719			regs->ax = -EINTR;
720			break;
721
722		case -ERESTARTSYS:
723			if (!(ksig->ka.sa.sa_flags & SA_RESTART)) {
724				regs->ax = -EINTR;
725				break;
726			}
727		/* fallthrough */
728		case -ERESTARTNOINTR:
729			regs->ax = regs->orig_ax;
730			regs->ip -= 2;
731			break;
732		}
733	}
734
735	/*
736	 * If TF is set due to a debugger (TIF_FORCED_TF), clear TF now
737	 * so that register information in the sigcontext is correct and
738	 * then notify the tracer before entering the signal handler.
739	 */
740	stepping = test_thread_flag(TIF_SINGLESTEP);
741	if (stepping)
742		user_disable_single_step(current);
743
744	failed = (setup_rt_frame(ksig, regs) < 0);
745	if (!failed) {
746		/*
747		 * Clear the direction flag as per the ABI for function entry.
748		 *
749		 * Clear RF when entering the signal handler, because
750		 * it might disable possible debug exception from the
751		 * signal handler.
752		 *
753		 * Clear TF for the case when it wasn't set by debugger to
754		 * avoid the recursive send_sigtrap() in SIGTRAP handler.
755		 */
756		regs->flags &= ~(X86_EFLAGS_DF|X86_EFLAGS_RF|X86_EFLAGS_TF);
757		/*
758		 * Ensure the signal handler starts with the new fpu state.
759		 */
760		if (fpu->initialized)
761			fpu__clear(fpu);
762	}
763	signal_setup_done(failed, ksig, stepping);
764}
765
766static inline unsigned long get_nr_restart_syscall(const struct pt_regs *regs)
767{
768	/*
769	 * This function is fundamentally broken as currently
770	 * implemented.
771	 *
772	 * The idea is that we want to trigger a call to the
773	 * restart_block() syscall and that we want in_ia32_syscall(),
774	 * in_x32_syscall(), etc. to match whatever they were in the
775	 * syscall being restarted.  We assume that the syscall
776	 * instruction at (regs->ip - 2) matches whatever syscall
777	 * instruction we used to enter in the first place.
778	 *
779	 * The problem is that we can get here when ptrace pokes
780	 * syscall-like values into regs even if we're not in a syscall
781	 * at all.
782	 *
783	 * For now, we maintain historical behavior and guess based on
784	 * stored state.  We could do better by saving the actual
785	 * syscall arch in restart_block or (with caveats on x32) by
786	 * checking if regs->ip points to 'int $0x80'.  The current
787	 * behavior is incorrect if a tracer has a different bitness
788	 * than the tracee.
789	 */
790#ifdef CONFIG_IA32_EMULATION
791	if (current_thread_info()->status & (TS_COMPAT|TS_I386_REGS_POKED))
792		return __NR_ia32_restart_syscall;
793#endif
794#ifdef CONFIG_X86_X32_ABI
795	return __NR_restart_syscall | (regs->orig_ax & __X32_SYSCALL_BIT);
796#else
797	return __NR_restart_syscall;
798#endif
799}
800
801/*
802 * Note that 'init' is a special process: it doesn't get signals it doesn't
803 * want to handle. Thus you cannot kill init even with a SIGKILL even by
804 * mistake.
805 */
806void do_signal(struct pt_regs *regs)
807{
808	struct ksignal ksig;
809
810	if (get_signal(&ksig)) {
811		/* Whee! Actually deliver the signal.  */
812		handle_signal(&ksig, regs);
813		return;
814	}
815
816	/* Did we come from a system call? */
817	if (syscall_get_nr(current, regs) >= 0) {
818		/* Restart the system call - no handlers present */
819		switch (syscall_get_error(current, regs)) {
820		case -ERESTARTNOHAND:
821		case -ERESTARTSYS:
822		case -ERESTARTNOINTR:
823			regs->ax = regs->orig_ax;
824			regs->ip -= 2;
825			break;
826
827		case -ERESTART_RESTARTBLOCK:
828			regs->ax = get_nr_restart_syscall(regs);
829			regs->ip -= 2;
830			break;
831		}
832	}
833
834	/*
835	 * If there's no signal to deliver, we just put the saved sigmask
836	 * back.
837	 */
838	restore_saved_sigmask();
839}
840
841void signal_fault(struct pt_regs *regs, void __user *frame, char *where)
842{
843	struct task_struct *me = current;
844
845	if (show_unhandled_signals && printk_ratelimit()) {
846		printk("%s"
847		       "%s[%d] bad frame in %s frame:%p ip:%lx sp:%lx orax:%lx",
848		       task_pid_nr(current) > 1 ? KERN_INFO : KERN_EMERG,
849		       me->comm, me->pid, where, frame,
850		       regs->ip, regs->sp, regs->orig_ax);
851		print_vma_addr(KERN_CONT " in ", regs->ip);
852		pr_cont("\n");
853	}
854
855	force_sig(SIGSEGV, me);
856}
857
858#ifdef CONFIG_X86_X32_ABI
859asmlinkage long sys32_x32_rt_sigreturn(void)
860{
861	struct pt_regs *regs = current_pt_regs();
862	struct rt_sigframe_x32 __user *frame;
863	sigset_t set;
864	unsigned long uc_flags;
865
866	frame = (struct rt_sigframe_x32 __user *)(regs->sp - 8);
867
868	if (!access_ok(VERIFY_READ, frame, sizeof(*frame)))
869		goto badframe;
870	if (__copy_from_user(&set, &frame->uc.uc_sigmask, sizeof(set)))
871		goto badframe;
872	if (__get_user(uc_flags, &frame->uc.uc_flags))
873		goto badframe;
874
875	set_current_blocked(&set);
876
877	if (restore_sigcontext(regs, &frame->uc.uc_mcontext, uc_flags))
878		goto badframe;
879
880	if (compat_restore_altstack(&frame->uc.uc_stack))
881		goto badframe;
882
883	return regs->ax;
884
885badframe:
886	signal_fault(regs, frame, "x32 rt_sigreturn");
887	return 0;
888}
889#endif
v4.10.11
 
  1/*
  2 *  Copyright (C) 1991, 1992  Linus Torvalds
  3 *  Copyright (C) 2000, 2001, 2002 Andi Kleen SuSE Labs
  4 *
  5 *  1997-11-28  Modified for POSIX.1b signals by Richard Henderson
  6 *  2000-06-20  Pentium III FXSR, SSE support by Gareth Hughes
  7 *  2000-2002   x86-64 support by Andi Kleen
  8 */
  9
 10#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
 11
 12#include <linux/sched.h>
 
 13#include <linux/mm.h>
 14#include <linux/smp.h>
 15#include <linux/kernel.h>
 16#include <linux/errno.h>
 17#include <linux/wait.h>
 18#include <linux/tracehook.h>
 19#include <linux/unistd.h>
 20#include <linux/stddef.h>
 21#include <linux/personality.h>
 22#include <linux/uaccess.h>
 23#include <linux/user-return-notifier.h>
 24#include <linux/uprobes.h>
 25#include <linux/context_tracking.h>
 
 26
 27#include <asm/processor.h>
 28#include <asm/ucontext.h>
 29#include <asm/fpu/internal.h>
 30#include <asm/fpu/signal.h>
 31#include <asm/vdso.h>
 32#include <asm/mce.h>
 33#include <asm/sighandling.h>
 34#include <asm/vm86.h>
 35
 36#ifdef CONFIG_X86_64
 37#include <asm/proto.h>
 38#include <asm/ia32_unistd.h>
 39#endif /* CONFIG_X86_64 */
 40
 41#include <asm/syscall.h>
 42#include <asm/syscalls.h>
 43
 44#include <asm/sigframe.h>
 45#include <asm/signal.h>
 46
 47#define COPY(x)			do {			\
 48	get_user_ex(regs->x, &sc->x);			\
 49} while (0)
 50
 51#define GET_SEG(seg)		({			\
 52	unsigned short tmp;				\
 53	get_user_ex(tmp, &sc->seg);			\
 54	tmp;						\
 55})
 56
 57#define COPY_SEG(seg)		do {			\
 58	regs->seg = GET_SEG(seg);			\
 59} while (0)
 60
 61#define COPY_SEG_CPL3(seg)	do {			\
 62	regs->seg = GET_SEG(seg) | 3;			\
 63} while (0)
 64
 65#ifdef CONFIG_X86_64
 66/*
 67 * If regs->ss will cause an IRET fault, change it.  Otherwise leave it
 68 * alone.  Using this generally makes no sense unless
 69 * user_64bit_mode(regs) would return true.
 70 */
 71static void force_valid_ss(struct pt_regs *regs)
 72{
 73	u32 ar;
 74	asm volatile ("lar %[old_ss], %[ar]\n\t"
 75		      "jz 1f\n\t"		/* If invalid: */
 76		      "xorl %[ar], %[ar]\n\t"	/* set ar = 0 */
 77		      "1:"
 78		      : [ar] "=r" (ar)
 79		      : [old_ss] "rm" ((u16)regs->ss));
 80
 81	/*
 82	 * For a valid 64-bit user context, we need DPL 3, type
 83	 * read-write data or read-write exp-down data, and S and P
 84	 * set.  We can't use VERW because VERW doesn't check the
 85	 * P bit.
 86	 */
 87	ar &= AR_DPL_MASK | AR_S | AR_P | AR_TYPE_MASK;
 88	if (ar != (AR_DPL3 | AR_S | AR_P | AR_TYPE_RWDATA) &&
 89	    ar != (AR_DPL3 | AR_S | AR_P | AR_TYPE_RWDATA_EXPDOWN))
 90		regs->ss = __USER_DS;
 91}
 92#endif
 93
 94static int restore_sigcontext(struct pt_regs *regs,
 95			      struct sigcontext __user *sc,
 96			      unsigned long uc_flags)
 97{
 98	unsigned long buf_val;
 99	void __user *buf;
100	unsigned int tmpflags;
101	unsigned int err = 0;
102
103	/* Always make any pending restarted system calls return -EINTR */
104	current->restart_block.fn = do_no_restart_syscall;
105
106	get_user_try {
107
108#ifdef CONFIG_X86_32
109		set_user_gs(regs, GET_SEG(gs));
110		COPY_SEG(fs);
111		COPY_SEG(es);
112		COPY_SEG(ds);
113#endif /* CONFIG_X86_32 */
114
115		COPY(di); COPY(si); COPY(bp); COPY(sp); COPY(bx);
116		COPY(dx); COPY(cx); COPY(ip); COPY(ax);
117
118#ifdef CONFIG_X86_64
119		COPY(r8);
120		COPY(r9);
121		COPY(r10);
122		COPY(r11);
123		COPY(r12);
124		COPY(r13);
125		COPY(r14);
126		COPY(r15);
127#endif /* CONFIG_X86_64 */
128
129		COPY_SEG_CPL3(cs);
130		COPY_SEG_CPL3(ss);
131
132#ifdef CONFIG_X86_64
133		/*
134		 * Fix up SS if needed for the benefit of old DOSEMU and
135		 * CRIU.
136		 */
137		if (unlikely(!(uc_flags & UC_STRICT_RESTORE_SS) &&
138			     user_64bit_mode(regs)))
139			force_valid_ss(regs);
140#endif
141
142		get_user_ex(tmpflags, &sc->flags);
143		regs->flags = (regs->flags & ~FIX_EFLAGS) | (tmpflags & FIX_EFLAGS);
144		regs->orig_ax = -1;		/* disable syscall checks */
145
146		get_user_ex(buf_val, &sc->fpstate);
147		buf = (void __user *)buf_val;
148	} get_user_catch(err);
149
150	err |= fpu__restore_sig(buf, IS_ENABLED(CONFIG_X86_32));
151
152	force_iret();
153
154	return err;
155}
156
157int setup_sigcontext(struct sigcontext __user *sc, void __user *fpstate,
158		     struct pt_regs *regs, unsigned long mask)
159{
160	int err = 0;
161
162	put_user_try {
163
164#ifdef CONFIG_X86_32
165		put_user_ex(get_user_gs(regs), (unsigned int __user *)&sc->gs);
166		put_user_ex(regs->fs, (unsigned int __user *)&sc->fs);
167		put_user_ex(regs->es, (unsigned int __user *)&sc->es);
168		put_user_ex(regs->ds, (unsigned int __user *)&sc->ds);
169#endif /* CONFIG_X86_32 */
170
171		put_user_ex(regs->di, &sc->di);
172		put_user_ex(regs->si, &sc->si);
173		put_user_ex(regs->bp, &sc->bp);
174		put_user_ex(regs->sp, &sc->sp);
175		put_user_ex(regs->bx, &sc->bx);
176		put_user_ex(regs->dx, &sc->dx);
177		put_user_ex(regs->cx, &sc->cx);
178		put_user_ex(regs->ax, &sc->ax);
179#ifdef CONFIG_X86_64
180		put_user_ex(regs->r8, &sc->r8);
181		put_user_ex(regs->r9, &sc->r9);
182		put_user_ex(regs->r10, &sc->r10);
183		put_user_ex(regs->r11, &sc->r11);
184		put_user_ex(regs->r12, &sc->r12);
185		put_user_ex(regs->r13, &sc->r13);
186		put_user_ex(regs->r14, &sc->r14);
187		put_user_ex(regs->r15, &sc->r15);
188#endif /* CONFIG_X86_64 */
189
190		put_user_ex(current->thread.trap_nr, &sc->trapno);
191		put_user_ex(current->thread.error_code, &sc->err);
192		put_user_ex(regs->ip, &sc->ip);
193#ifdef CONFIG_X86_32
194		put_user_ex(regs->cs, (unsigned int __user *)&sc->cs);
195		put_user_ex(regs->flags, &sc->flags);
196		put_user_ex(regs->sp, &sc->sp_at_signal);
197		put_user_ex(regs->ss, (unsigned int __user *)&sc->ss);
198#else /* !CONFIG_X86_32 */
199		put_user_ex(regs->flags, &sc->flags);
200		put_user_ex(regs->cs, &sc->cs);
201		put_user_ex(0, &sc->gs);
202		put_user_ex(0, &sc->fs);
203		put_user_ex(regs->ss, &sc->ss);
204#endif /* CONFIG_X86_32 */
205
206		put_user_ex(fpstate, &sc->fpstate);
207
208		/* non-iBCS2 extensions.. */
209		put_user_ex(mask, &sc->oldmask);
210		put_user_ex(current->thread.cr2, &sc->cr2);
211	} put_user_catch(err);
212
213	return err;
214}
215
216/*
217 * Set up a signal frame.
218 */
219
220/*
221 * Determine which stack to use..
222 */
223static unsigned long align_sigframe(unsigned long sp)
224{
225#ifdef CONFIG_X86_32
226	/*
227	 * Align the stack pointer according to the i386 ABI,
228	 * i.e. so that on function entry ((sp + 4) & 15) == 0.
229	 */
230	sp = ((sp + 4) & -16ul) - 4;
231#else /* !CONFIG_X86_32 */
232	sp = round_down(sp, 16) - 8;
233#endif
234	return sp;
235}
236
237static void __user *
238get_sigframe(struct k_sigaction *ka, struct pt_regs *regs, size_t frame_size,
239	     void __user **fpstate)
240{
241	/* Default to using normal stack */
242	unsigned long math_size = 0;
243	unsigned long sp = regs->sp;
244	unsigned long buf_fx = 0;
245	int onsigstack = on_sig_stack(sp);
246	struct fpu *fpu = &current->thread.fpu;
247
248	/* redzone */
249	if (IS_ENABLED(CONFIG_X86_64))
250		sp -= 128;
251
252	/* This is the X/Open sanctioned signal stack switching.  */
253	if (ka->sa.sa_flags & SA_ONSTACK) {
254		if (sas_ss_flags(sp) == 0)
255			sp = current->sas_ss_sp + current->sas_ss_size;
256	} else if (IS_ENABLED(CONFIG_X86_32) &&
257		   !onsigstack &&
258		   (regs->ss & 0xffff) != __USER_DS &&
259		   !(ka->sa.sa_flags & SA_RESTORER) &&
260		   ka->sa.sa_restorer) {
261		/* This is the legacy signal stack switching. */
262		sp = (unsigned long) ka->sa.sa_restorer;
263	}
264
265	if (fpu->fpstate_active) {
266		sp = fpu__alloc_mathframe(sp, IS_ENABLED(CONFIG_X86_32),
267					  &buf_fx, &math_size);
268		*fpstate = (void __user *)sp;
269	}
270
271	sp = align_sigframe(sp - frame_size);
272
273	/*
274	 * If we are on the alternate signal stack and would overflow it, don't.
275	 * Return an always-bogus address instead so we will die with SIGSEGV.
276	 */
277	if (onsigstack && !likely(on_sig_stack(sp)))
278		return (void __user *)-1L;
279
280	/* save i387 and extended state */
281	if (fpu->fpstate_active &&
282	    copy_fpstate_to_sigframe(*fpstate, (void __user *)buf_fx, math_size) < 0)
283		return (void __user *)-1L;
284
285	return (void __user *)sp;
286}
287
288#ifdef CONFIG_X86_32
289static const struct {
290	u16 poplmovl;
291	u32 val;
292	u16 int80;
293} __attribute__((packed)) retcode = {
294	0xb858,		/* popl %eax; movl $..., %eax */
295	__NR_sigreturn,
296	0x80cd,		/* int $0x80 */
297};
298
299static const struct {
300	u8  movl;
301	u32 val;
302	u16 int80;
303	u8  pad;
304} __attribute__((packed)) rt_retcode = {
305	0xb8,		/* movl $..., %eax */
306	__NR_rt_sigreturn,
307	0x80cd,		/* int $0x80 */
308	0
309};
310
311static int
312__setup_frame(int sig, struct ksignal *ksig, sigset_t *set,
313	      struct pt_regs *regs)
314{
315	struct sigframe __user *frame;
316	void __user *restorer;
317	int err = 0;
318	void __user *fpstate = NULL;
319
320	frame = get_sigframe(&ksig->ka, regs, sizeof(*frame), &fpstate);
321
322	if (!access_ok(VERIFY_WRITE, frame, sizeof(*frame)))
323		return -EFAULT;
324
325	if (__put_user(sig, &frame->sig))
326		return -EFAULT;
327
328	if (setup_sigcontext(&frame->sc, fpstate, regs, set->sig[0]))
329		return -EFAULT;
330
331	if (_NSIG_WORDS > 1) {
332		if (__copy_to_user(&frame->extramask, &set->sig[1],
333				   sizeof(frame->extramask)))
334			return -EFAULT;
335	}
336
337	if (current->mm->context.vdso)
338		restorer = current->mm->context.vdso +
339			vdso_image_32.sym___kernel_sigreturn;
340	else
341		restorer = &frame->retcode;
342	if (ksig->ka.sa.sa_flags & SA_RESTORER)
343		restorer = ksig->ka.sa.sa_restorer;
344
345	/* Set up to return from userspace.  */
346	err |= __put_user(restorer, &frame->pretcode);
347
348	/*
349	 * This is popl %eax ; movl $__NR_sigreturn, %eax ; int $0x80
350	 *
351	 * WE DO NOT USE IT ANY MORE! It's only left here for historical
352	 * reasons and because gdb uses it as a signature to notice
353	 * signal handler stack frames.
354	 */
355	err |= __put_user(*((u64 *)&retcode), (u64 *)frame->retcode);
356
357	if (err)
358		return -EFAULT;
359
360	/* Set up registers for signal handler */
361	regs->sp = (unsigned long)frame;
362	regs->ip = (unsigned long)ksig->ka.sa.sa_handler;
363	regs->ax = (unsigned long)sig;
364	regs->dx = 0;
365	regs->cx = 0;
366
367	regs->ds = __USER_DS;
368	regs->es = __USER_DS;
369	regs->ss = __USER_DS;
370	regs->cs = __USER_CS;
371
372	return 0;
373}
374
375static int __setup_rt_frame(int sig, struct ksignal *ksig,
376			    sigset_t *set, struct pt_regs *regs)
377{
378	struct rt_sigframe __user *frame;
379	void __user *restorer;
380	int err = 0;
381	void __user *fpstate = NULL;
382
383	frame = get_sigframe(&ksig->ka, regs, sizeof(*frame), &fpstate);
384
385	if (!access_ok(VERIFY_WRITE, frame, sizeof(*frame)))
386		return -EFAULT;
387
388	put_user_try {
389		put_user_ex(sig, &frame->sig);
390		put_user_ex(&frame->info, &frame->pinfo);
391		put_user_ex(&frame->uc, &frame->puc);
392
393		/* Create the ucontext.  */
394		if (boot_cpu_has(X86_FEATURE_XSAVE))
395			put_user_ex(UC_FP_XSTATE, &frame->uc.uc_flags);
396		else
397			put_user_ex(0, &frame->uc.uc_flags);
398		put_user_ex(0, &frame->uc.uc_link);
399		save_altstack_ex(&frame->uc.uc_stack, regs->sp);
400
401		/* Set up to return from userspace.  */
402		restorer = current->mm->context.vdso +
403			vdso_image_32.sym___kernel_rt_sigreturn;
404		if (ksig->ka.sa.sa_flags & SA_RESTORER)
405			restorer = ksig->ka.sa.sa_restorer;
406		put_user_ex(restorer, &frame->pretcode);
407
408		/*
409		 * This is movl $__NR_rt_sigreturn, %ax ; int $0x80
410		 *
411		 * WE DO NOT USE IT ANY MORE! It's only left here for historical
412		 * reasons and because gdb uses it as a signature to notice
413		 * signal handler stack frames.
414		 */
415		put_user_ex(*((u64 *)&rt_retcode), (u64 *)frame->retcode);
416	} put_user_catch(err);
417	
418	err |= copy_siginfo_to_user(&frame->info, &ksig->info);
419	err |= setup_sigcontext(&frame->uc.uc_mcontext, fpstate,
420				regs, set->sig[0]);
421	err |= __copy_to_user(&frame->uc.uc_sigmask, set, sizeof(*set));
422
423	if (err)
424		return -EFAULT;
425
426	/* Set up registers for signal handler */
427	regs->sp = (unsigned long)frame;
428	regs->ip = (unsigned long)ksig->ka.sa.sa_handler;
429	regs->ax = (unsigned long)sig;
430	regs->dx = (unsigned long)&frame->info;
431	regs->cx = (unsigned long)&frame->uc;
432
433	regs->ds = __USER_DS;
434	regs->es = __USER_DS;
435	regs->ss = __USER_DS;
436	regs->cs = __USER_CS;
437
438	return 0;
439}
440#else /* !CONFIG_X86_32 */
441static unsigned long frame_uc_flags(struct pt_regs *regs)
442{
443	unsigned long flags;
444
445	if (boot_cpu_has(X86_FEATURE_XSAVE))
446		flags = UC_FP_XSTATE | UC_SIGCONTEXT_SS;
447	else
448		flags = UC_SIGCONTEXT_SS;
449
450	if (likely(user_64bit_mode(regs)))
451		flags |= UC_STRICT_RESTORE_SS;
452
453	return flags;
454}
455
456static int __setup_rt_frame(int sig, struct ksignal *ksig,
457			    sigset_t *set, struct pt_regs *regs)
458{
459	struct rt_sigframe __user *frame;
460	void __user *fp = NULL;
461	int err = 0;
462
463	frame = get_sigframe(&ksig->ka, regs, sizeof(struct rt_sigframe), &fp);
464
465	if (!access_ok(VERIFY_WRITE, frame, sizeof(*frame)))
466		return -EFAULT;
467
468	if (ksig->ka.sa.sa_flags & SA_SIGINFO) {
469		if (copy_siginfo_to_user(&frame->info, &ksig->info))
470			return -EFAULT;
471	}
472
473	put_user_try {
474		/* Create the ucontext.  */
475		put_user_ex(frame_uc_flags(regs), &frame->uc.uc_flags);
476		put_user_ex(0, &frame->uc.uc_link);
477		save_altstack_ex(&frame->uc.uc_stack, regs->sp);
478
479		/* Set up to return from userspace.  If provided, use a stub
480		   already in userspace.  */
481		/* x86-64 should always use SA_RESTORER. */
482		if (ksig->ka.sa.sa_flags & SA_RESTORER) {
483			put_user_ex(ksig->ka.sa.sa_restorer, &frame->pretcode);
484		} else {
485			/* could use a vstub here */
486			err |= -EFAULT;
487		}
488	} put_user_catch(err);
489
490	err |= setup_sigcontext(&frame->uc.uc_mcontext, fp, regs, set->sig[0]);
491	err |= __copy_to_user(&frame->uc.uc_sigmask, set, sizeof(*set));
492
493	if (err)
494		return -EFAULT;
495
496	/* Set up registers for signal handler */
497	regs->di = sig;
498	/* In case the signal handler was declared without prototypes */
499	regs->ax = 0;
500
501	/* This also works for non SA_SIGINFO handlers because they expect the
502	   next argument after the signal number on the stack. */
503	regs->si = (unsigned long)&frame->info;
504	regs->dx = (unsigned long)&frame->uc;
505	regs->ip = (unsigned long) ksig->ka.sa.sa_handler;
506
507	regs->sp = (unsigned long)frame;
508
509	/*
510	 * Set up the CS and SS registers to run signal handlers in
511	 * 64-bit mode, even if the handler happens to be interrupting
512	 * 32-bit or 16-bit code.
513	 *
514	 * SS is subtle.  In 64-bit mode, we don't need any particular
515	 * SS descriptor, but we do need SS to be valid.  It's possible
516	 * that the old SS is entirely bogus -- this can happen if the
517	 * signal we're trying to deliver is #GP or #SS caused by a bad
518	 * SS value.  We also have a compatbility issue here: DOSEMU
519	 * relies on the contents of the SS register indicating the
520	 * SS value at the time of the signal, even though that code in
521	 * DOSEMU predates sigreturn's ability to restore SS.  (DOSEMU
522	 * avoids relying on sigreturn to restore SS; instead it uses
523	 * a trampoline.)  So we do our best: if the old SS was valid,
524	 * we keep it.  Otherwise we replace it.
525	 */
526	regs->cs = __USER_CS;
527
528	if (unlikely(regs->ss != __USER_DS))
529		force_valid_ss(regs);
530
531	return 0;
532}
533#endif /* CONFIG_X86_32 */
534
535static int x32_setup_rt_frame(struct ksignal *ksig,
536			      compat_sigset_t *set,
537			      struct pt_regs *regs)
538{
539#ifdef CONFIG_X86_X32_ABI
540	struct rt_sigframe_x32 __user *frame;
541	void __user *restorer;
542	int err = 0;
543	void __user *fpstate = NULL;
544
545	frame = get_sigframe(&ksig->ka, regs, sizeof(*frame), &fpstate);
546
547	if (!access_ok(VERIFY_WRITE, frame, sizeof(*frame)))
548		return -EFAULT;
549
550	if (ksig->ka.sa.sa_flags & SA_SIGINFO) {
551		if (__copy_siginfo_to_user32(&frame->info, &ksig->info, true))
552			return -EFAULT;
553	}
554
555	put_user_try {
556		/* Create the ucontext.  */
557		put_user_ex(frame_uc_flags(regs), &frame->uc.uc_flags);
558		put_user_ex(0, &frame->uc.uc_link);
559		compat_save_altstack_ex(&frame->uc.uc_stack, regs->sp);
560		put_user_ex(0, &frame->uc.uc__pad0);
561
562		if (ksig->ka.sa.sa_flags & SA_RESTORER) {
563			restorer = ksig->ka.sa.sa_restorer;
564		} else {
565			/* could use a vstub here */
566			restorer = NULL;
567			err |= -EFAULT;
568		}
569		put_user_ex(restorer, &frame->pretcode);
570	} put_user_catch(err);
571
572	err |= setup_sigcontext(&frame->uc.uc_mcontext, fpstate,
573				regs, set->sig[0]);
574	err |= __copy_to_user(&frame->uc.uc_sigmask, set, sizeof(*set));
575
576	if (err)
577		return -EFAULT;
578
579	/* Set up registers for signal handler */
580	regs->sp = (unsigned long) frame;
581	regs->ip = (unsigned long) ksig->ka.sa.sa_handler;
582
583	/* We use the x32 calling convention here... */
584	regs->di = ksig->sig;
585	regs->si = (unsigned long) &frame->info;
586	regs->dx = (unsigned long) &frame->uc;
587
588	loadsegment(ds, __USER_DS);
589	loadsegment(es, __USER_DS);
590
591	regs->cs = __USER_CS;
592	regs->ss = __USER_DS;
593#endif	/* CONFIG_X86_X32_ABI */
594
595	return 0;
596}
597
598/*
599 * Do a signal return; undo the signal stack.
600 */
601#ifdef CONFIG_X86_32
602asmlinkage unsigned long sys_sigreturn(void)
603{
604	struct pt_regs *regs = current_pt_regs();
605	struct sigframe __user *frame;
606	sigset_t set;
607
608	frame = (struct sigframe __user *)(regs->sp - 8);
609
610	if (!access_ok(VERIFY_READ, frame, sizeof(*frame)))
611		goto badframe;
612	if (__get_user(set.sig[0], &frame->sc.oldmask) || (_NSIG_WORDS > 1
613		&& __copy_from_user(&set.sig[1], &frame->extramask,
614				    sizeof(frame->extramask))))
615		goto badframe;
616
617	set_current_blocked(&set);
618
619	/*
620	 * x86_32 has no uc_flags bits relevant to restore_sigcontext.
621	 * Save a few cycles by skipping the __get_user.
622	 */
623	if (restore_sigcontext(regs, &frame->sc, 0))
624		goto badframe;
625	return regs->ax;
626
627badframe:
628	signal_fault(regs, frame, "sigreturn");
629
630	return 0;
631}
632#endif /* CONFIG_X86_32 */
633
634asmlinkage long sys_rt_sigreturn(void)
635{
636	struct pt_regs *regs = current_pt_regs();
637	struct rt_sigframe __user *frame;
638	sigset_t set;
639	unsigned long uc_flags;
640
641	frame = (struct rt_sigframe __user *)(regs->sp - sizeof(long));
642	if (!access_ok(VERIFY_READ, frame, sizeof(*frame)))
643		goto badframe;
644	if (__copy_from_user(&set, &frame->uc.uc_sigmask, sizeof(set)))
645		goto badframe;
646	if (__get_user(uc_flags, &frame->uc.uc_flags))
647		goto badframe;
648
649	set_current_blocked(&set);
650
651	if (restore_sigcontext(regs, &frame->uc.uc_mcontext, uc_flags))
652		goto badframe;
653
654	if (restore_altstack(&frame->uc.uc_stack))
655		goto badframe;
656
657	return regs->ax;
658
659badframe:
660	signal_fault(regs, frame, "rt_sigreturn");
661	return 0;
662}
663
664static inline int is_ia32_compat_frame(struct ksignal *ksig)
665{
666	return IS_ENABLED(CONFIG_IA32_EMULATION) &&
667		ksig->ka.sa.sa_flags & SA_IA32_ABI;
668}
669
670static inline int is_ia32_frame(struct ksignal *ksig)
671{
672	return IS_ENABLED(CONFIG_X86_32) || is_ia32_compat_frame(ksig);
673}
674
675static inline int is_x32_frame(struct ksignal *ksig)
676{
677	return IS_ENABLED(CONFIG_X86_X32_ABI) &&
678		ksig->ka.sa.sa_flags & SA_X32_ABI;
679}
680
681static int
682setup_rt_frame(struct ksignal *ksig, struct pt_regs *regs)
683{
684	int usig = ksig->sig;
685	sigset_t *set = sigmask_to_save();
686	compat_sigset_t *cset = (compat_sigset_t *) set;
687
688	/* Set up the stack frame */
689	if (is_ia32_frame(ksig)) {
690		if (ksig->ka.sa.sa_flags & SA_SIGINFO)
691			return ia32_setup_rt_frame(usig, ksig, cset, regs);
692		else
693			return ia32_setup_frame(usig, ksig, cset, regs);
694	} else if (is_x32_frame(ksig)) {
695		return x32_setup_rt_frame(ksig, cset, regs);
696	} else {
697		return __setup_rt_frame(ksig->sig, ksig, set, regs);
698	}
699}
700
701static void
702handle_signal(struct ksignal *ksig, struct pt_regs *regs)
703{
704	bool stepping, failed;
705	struct fpu *fpu = &current->thread.fpu;
706
707	if (v8086_mode(regs))
708		save_v86_state((struct kernel_vm86_regs *) regs, VM86_SIGNAL);
709
710	/* Are we from a system call? */
711	if (syscall_get_nr(current, regs) >= 0) {
712		/* If so, check system call restarting.. */
713		switch (syscall_get_error(current, regs)) {
714		case -ERESTART_RESTARTBLOCK:
715		case -ERESTARTNOHAND:
716			regs->ax = -EINTR;
717			break;
718
719		case -ERESTARTSYS:
720			if (!(ksig->ka.sa.sa_flags & SA_RESTART)) {
721				regs->ax = -EINTR;
722				break;
723			}
724		/* fallthrough */
725		case -ERESTARTNOINTR:
726			regs->ax = regs->orig_ax;
727			regs->ip -= 2;
728			break;
729		}
730	}
731
732	/*
733	 * If TF is set due to a debugger (TIF_FORCED_TF), clear TF now
734	 * so that register information in the sigcontext is correct and
735	 * then notify the tracer before entering the signal handler.
736	 */
737	stepping = test_thread_flag(TIF_SINGLESTEP);
738	if (stepping)
739		user_disable_single_step(current);
740
741	failed = (setup_rt_frame(ksig, regs) < 0);
742	if (!failed) {
743		/*
744		 * Clear the direction flag as per the ABI for function entry.
745		 *
746		 * Clear RF when entering the signal handler, because
747		 * it might disable possible debug exception from the
748		 * signal handler.
749		 *
750		 * Clear TF for the case when it wasn't set by debugger to
751		 * avoid the recursive send_sigtrap() in SIGTRAP handler.
752		 */
753		regs->flags &= ~(X86_EFLAGS_DF|X86_EFLAGS_RF|X86_EFLAGS_TF);
754		/*
755		 * Ensure the signal handler starts with the new fpu state.
756		 */
757		if (fpu->fpstate_active)
758			fpu__clear(fpu);
759	}
760	signal_setup_done(failed, ksig, stepping);
761}
762
763static inline unsigned long get_nr_restart_syscall(const struct pt_regs *regs)
764{
765	/*
766	 * This function is fundamentally broken as currently
767	 * implemented.
768	 *
769	 * The idea is that we want to trigger a call to the
770	 * restart_block() syscall and that we want in_ia32_syscall(),
771	 * in_x32_syscall(), etc. to match whatever they were in the
772	 * syscall being restarted.  We assume that the syscall
773	 * instruction at (regs->ip - 2) matches whatever syscall
774	 * instruction we used to enter in the first place.
775	 *
776	 * The problem is that we can get here when ptrace pokes
777	 * syscall-like values into regs even if we're not in a syscall
778	 * at all.
779	 *
780	 * For now, we maintain historical behavior and guess based on
781	 * stored state.  We could do better by saving the actual
782	 * syscall arch in restart_block or (with caveats on x32) by
783	 * checking if regs->ip points to 'int $0x80'.  The current
784	 * behavior is incorrect if a tracer has a different bitness
785	 * than the tracee.
786	 */
787#ifdef CONFIG_IA32_EMULATION
788	if (current->thread.status & (TS_COMPAT|TS_I386_REGS_POKED))
789		return __NR_ia32_restart_syscall;
790#endif
791#ifdef CONFIG_X86_X32_ABI
792	return __NR_restart_syscall | (regs->orig_ax & __X32_SYSCALL_BIT);
793#else
794	return __NR_restart_syscall;
795#endif
796}
797
798/*
799 * Note that 'init' is a special process: it doesn't get signals it doesn't
800 * want to handle. Thus you cannot kill init even with a SIGKILL even by
801 * mistake.
802 */
803void do_signal(struct pt_regs *regs)
804{
805	struct ksignal ksig;
806
807	if (get_signal(&ksig)) {
808		/* Whee! Actually deliver the signal.  */
809		handle_signal(&ksig, regs);
810		return;
811	}
812
813	/* Did we come from a system call? */
814	if (syscall_get_nr(current, regs) >= 0) {
815		/* Restart the system call - no handlers present */
816		switch (syscall_get_error(current, regs)) {
817		case -ERESTARTNOHAND:
818		case -ERESTARTSYS:
819		case -ERESTARTNOINTR:
820			regs->ax = regs->orig_ax;
821			regs->ip -= 2;
822			break;
823
824		case -ERESTART_RESTARTBLOCK:
825			regs->ax = get_nr_restart_syscall(regs);
826			regs->ip -= 2;
827			break;
828		}
829	}
830
831	/*
832	 * If there's no signal to deliver, we just put the saved sigmask
833	 * back.
834	 */
835	restore_saved_sigmask();
836}
837
838void signal_fault(struct pt_regs *regs, void __user *frame, char *where)
839{
840	struct task_struct *me = current;
841
842	if (show_unhandled_signals && printk_ratelimit()) {
843		printk("%s"
844		       "%s[%d] bad frame in %s frame:%p ip:%lx sp:%lx orax:%lx",
845		       task_pid_nr(current) > 1 ? KERN_INFO : KERN_EMERG,
846		       me->comm, me->pid, where, frame,
847		       regs->ip, regs->sp, regs->orig_ax);
848		print_vma_addr(" in ", regs->ip);
849		pr_cont("\n");
850	}
851
852	force_sig(SIGSEGV, me);
853}
854
855#ifdef CONFIG_X86_X32_ABI
856asmlinkage long sys32_x32_rt_sigreturn(void)
857{
858	struct pt_regs *regs = current_pt_regs();
859	struct rt_sigframe_x32 __user *frame;
860	sigset_t set;
861	unsigned long uc_flags;
862
863	frame = (struct rt_sigframe_x32 __user *)(regs->sp - 8);
864
865	if (!access_ok(VERIFY_READ, frame, sizeof(*frame)))
866		goto badframe;
867	if (__copy_from_user(&set, &frame->uc.uc_sigmask, sizeof(set)))
868		goto badframe;
869	if (__get_user(uc_flags, &frame->uc.uc_flags))
870		goto badframe;
871
872	set_current_blocked(&set);
873
874	if (restore_sigcontext(regs, &frame->uc.uc_mcontext, uc_flags))
875		goto badframe;
876
877	if (compat_restore_altstack(&frame->uc.uc_stack))
878		goto badframe;
879
880	return regs->ax;
881
882badframe:
883	signal_fault(regs, frame, "x32 rt_sigreturn");
884	return 0;
885}
886#endif