Commit e1432a52 authored by Peter Zijlstra's avatar Peter Zijlstra Committed by Yang Yingliang
Browse files

x86,static_call: Fix __static_call_return0 for i386

mainline inclusion
from mainline-v5.18-rc2
commit 1cd5f059
category: bugfix
bugzilla: https://gitee.com/openeuler/kernel/issues/I9JNPZ

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1cd5f059d956e6f614ba6666ecdbcf95db05d5f5



--------------------------------

Paolo reported that the instruction sequence that is used to replace:

    call __static_call_return0

namely:

    66 66 48 31 c0	data16 data16 xor %rax,%rax

decodes to something else on i386, namely:

    66 66 48		data16 dec %ax
    31 c0		xor    %eax,%eax

Which is a nonsensical sequence that happens to have the same outcome.
*However* an important distinction is that it consists of 2
instructions which is a problem when the thing needs to be overwriten
with a regular call instruction again.

As such, replace the instruction with something that decodes the same
on both i386 and x86_64.

Fixes: 3f2a8fc4 ("static_call/x86: Add __static_call_return0()")
Reported-by: default avatarPaolo Bonzini <pbonzini@redhat.com>
Signed-off-by: default avatarPeter Zijlstra (Intel) <peterz@infradead.org>
Link: https://lkml.kernel.org/r/20220318204419.GT8939@worktop.programming.kicks-ass.net


Signed-off-by: default avatarYang Yingliang <yangyingliang@huawei.com>
parent ae52f9c5
Loading
Loading
Loading
Loading
+2 −3
Original line number Diff line number Diff line
@@ -12,10 +12,9 @@ enum insn_type {
};

/*
 * data16 data16 xorq %rax, %rax - a single 5 byte instruction that clears %rax
 * The REX.W cancels the effect of any data16.
 * cs cs cs xorl %eax, %eax - a single 5 byte instruction that clears %[er]ax
 */
static const u8 xor5rax[] = { 0x66, 0x66, 0x48, 0x31, 0xc0 };
static const u8 xor5rax[] = { 0x2e, 0x2e, 0x2e, 0x31, 0xc0 };

/*
 * ud1 %esp, %ecx - a 3 byte #UD that is unique to trampolines, chosen such