arm: Remove wrong ldr from _dl_start_user (BZ 31339)
The commit 49d877a8 (arm: Remove _dl_skip_args usage) removed the _SKIP_ARGS literal, which was previously loader to r4 on loader _start. However, the cleanup did not remove the following 'ldr r4, [sl, r4]' on _dl_start_user, used to check to skip the arguments after ld self-relocations. In my testing, the kernel initially set r4 to 0, which makes the ldr instruction just read the _GLOBAL_OFFSET_TABLE_. However, since r4 is a callee-saved register; a different runtime might not zero initialize it and thus trigger an invalid memory access. Checked on arm-linux-gnu. Reported-by:Adrian Ratiu <adrian.ratiu@collabora.com> Reviewed-by:
Szabolcs Nagy <szabolcs.nagy@arm.com> (cherry picked from commit 1e25112d)
Loading
Please register or sign in to comment