powerpc/tm: Block signal return setting invalid MSR state
authorMichael Neuling <mikey@neuling.org>
Thu, 19 Nov 2015 04:44:44 +0000 (15:44 +1100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Sun, 31 Jan 2016 19:23:38 +0000 (11:23 -0800)
commit567a215dd1586dae787f21b8f3e484018763a710
tree27e1fc5c838e8653513959c91082e314171a64c4
parenteeca98948d8c4922e6deb16bfc9ee0bd9902dbb0
powerpc/tm: Block signal return setting invalid MSR state

commit d2b9d2a5ad5ef04ff978c9923d19730cb05efd55 upstream.

Currently we allow both the MSR T and S bits to be set by userspace on
a signal return.  Unfortunately this is a reserved configuration and
will cause a TM Bad Thing exception if attempted (via rfid).

This patch checks for this case in both the 32 and 64 bit signals
code.  If both T and S are set, we mark the context as invalid.

Found using a syscall fuzzer.

Fixes: 2b0a576d15e0 ("powerpc: Add new transactional memory state to the signal context")
Signed-off-by: Michael Neuling <mikey@neuling.org>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
arch/powerpc/include/asm/reg.h
arch/powerpc/kernel/signal_32.c
arch/powerpc/kernel/signal_64.c