brintos

brintos / linux-shallow public Read only

0
0
Text · 1.6 KiB · 9f8c1ae Raw
65 lines · plain
1/* SPDX-License-Identifier: GPL-2.0 */2/* Copyright (C) 2019 ARM Limited */3 4#include <asm/unistd.h>5 6.section        .rodata, "a"7call_fmt:8	.asciz "Calling sigreturn with fake sigframe sized:%zd at SP @%08lX\n"9 10.text11 12.globl fake_sigreturn13 14/*	fake_sigreturn	x0:&sigframe,  x1:sigframe_size,  x2:misalign_bytes */15fake_sigreturn:16	stp	x29, x30, [sp, #-16]!17	mov	x29, sp18 19	mov	x20, x020	mov	x21, x121	mov	x22, x222 23	/* create space on the stack for fake sigframe 16 bytes-aligned */24	add	x0, x21, x2225	add	x0, x0, #1526	bic	x0, x0, #15 /* round_up(sigframe_size + misalign_bytes, 16) */27	sub	sp, sp, x028	add	x23, sp, x22 /* new sigframe base with misaligment if any */29 30	ldr	x0, =call_fmt31	mov	x1, x2132	mov	x2, x2333	bl	printf34 35	/* memcpy the provided content, while still keeping SP aligned */36	mov	x0, x2337	mov	x1, x2038	mov	x2, x2139	bl	memcpy40 41	/*42	 * Here saving a last minute SP to current->token acts as a marker:43	 * if we got here, we are successfully faking a sigreturn; in other44	 * words we are sure no bad fatal signal has been raised till now45	 * for unrelated reasons, so we should consider the possibly observed46	 * fatal signal like SEGV coming from Kernel restore_sigframe() and47	 * triggered as expected from our test-case.48	 * For simplicity this assumes that current field 'token' is laid out49	 * as first in struct tdescr50	 */51	ldr	x0, current52	str	x23, [x0]53	/* finally move SP to misaligned address...if any requested */54	mov	sp, x2355 56	mov	x8, #__NR_rt_sigreturn57	svc	#058 59	/*60	 * Above sigreturn should not return...looping here leads to a timeout61	 * and ensure proper and clean test failure, instead of jumping around62	 * on a potentially corrupted stack.63	 */64	b	.65