[PATCH 2/2] riscv: cfi: Only write envcfg CSR when task is current

From: Samuel Holland

Date: Wed Oct 07 2026 - 11:58:32 EST


set_shstk_status() and set_indir_lp_status() take a task argument, which
lets them operate on tasks other than current, but they always write the
envcfg CSR for the current task. Fix this with the envcfg_update_bits()
helper, which only writes the envcfg CSR when operating on current.

Fixes: 61a0200211d31e ("riscv: Implement arch-agnostic shadow stack prctls")
Fixes: 8a9e22d2ca5855 ("riscv: Implement indirect branch tracking prctls")
Signed-off-by: Samuel Holland <samuel.holland@xxxxxxxxxx>
---

arch/riscv/kernel/usercfi.c | 15 +++------------
1 file changed, 3 insertions(+), 12 deletions(-)

diff --git a/arch/riscv/kernel/usercfi.c b/arch/riscv/kernel/usercfi.c
index 23c4d6d9d8cbc..86141e5bab822 100644
--- a/arch/riscv/kernel/usercfi.c
+++ b/arch/riscv/kernel/usercfi.c
@@ -15,6 +15,7 @@
#include <linux/syscalls.h>
#include <linux/prctl.h>
#include <asm/csr.h>
+#include <asm/switch_to.h>
#include <asm/usercfi.h>

unsigned long riscv_nousercfi __read_mostly;
@@ -66,12 +67,7 @@ void set_shstk_status(struct task_struct *task, bool enable)

task->thread_info.user_cfi_state.ubcfi_en = enable ? 1 : 0;

- if (enable)
- task->thread.envcfg |= ENVCFG_SSE;
- else
- task->thread.envcfg &= ~ENVCFG_SSE;
-
- csr_write(CSR_ENVCFG, task->thread.envcfg);
+ envcfg_update_bits(task, ENVCFG_SSE, enable ? ENVCFG_SSE : 0);
}

void set_shstk_lock(struct task_struct *task, bool lock)
@@ -96,12 +92,7 @@ void set_indir_lp_status(struct task_struct *task, bool enable)

task->thread_info.user_cfi_state.ufcfi_en = enable ? 1 : 0;

- if (enable)
- task->thread.envcfg |= ENVCFG_LPE;
- else
- task->thread.envcfg &= ~ENVCFG_LPE;
-
- csr_write(CSR_ENVCFG, task->thread.envcfg);
+ envcfg_update_bits(task, ENVCFG_LPE, enable ? ENVCFG_LPE : 0);
}

void set_indir_lp_lock(struct task_struct *task, bool lock)
--
2.52.0

base-commit: a90ee4305c4a5df72c11b31dacfdc76e00fcf78a
branch: up/cfi-fixes