]> rtime.felk.cvut.cz Git - zynq/linux.git/commitdiff
ARM: zynq: Use memcpy_toio instead of memcpy on smp bring-up zynq-soc-for-v5.4
authorLuis Araneda <luaraneda@gmail.com>
Thu, 8 Aug 2019 12:52:43 +0000 (08:52 -0400)
committerMichal Simek <michal.simek@xilinx.com>
Wed, 14 Aug 2019 07:40:43 +0000 (09:40 +0200)
This fixes a kernel panic on memcpy when
FORTIFY_SOURCE is enabled.

The initial smp implementation on commit aa7eb2bb4e4a
("arm: zynq: Add smp support")
used memcpy, which worked fine until commit ee333554fed5
("ARM: 8749/1: Kconfig: Add ARCH_HAS_FORTIFY_SOURCE")
enabled overflow checks at runtime, producing a read
overflow panic.

The computed size of memcpy args are:
- p_size (dst): 4294967295 = (size_t) -1
- q_size (src): 1
- size (len): 8

Additionally, the memory is marked as __iomem, so one of
the memcpy_* functions should be used for read/write.

Fixes: aa7eb2bb4e4a ("arm: zynq: Add smp support")
Signed-off-by: Luis Araneda <luaraneda@gmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Michal Simek <michal.simek@xilinx.com>
arch/arm/mach-zynq/platsmp.c

index 38728badabd43144b5cec9c4091def374a095168..a10085be9073b5e11c733fd5b82d07ec68be5e11 100644 (file)
@@ -57,7 +57,7 @@ int zynq_cpun_start(u32 address, int cpu)
                        * 0x4: Jump by mov instruction
                        * 0x8: Jumping address
                        */
-                       memcpy((__force void *)zero, &zynq_secondary_trampoline,
+                       memcpy_toio(zero, &zynq_secondary_trampoline,
                                                        trampoline_size);
                        writel(address, zero + trampoline_size);