Re: [PATCH 1/2] riscv: cfi: Bounds check restore token before swap

From: Zong Li

Date: Thu Oct 08 2026 - 01:43:19 EST


On Wed, Oct 7, 2026 at 11:57 PM Samuel Holland
<samuel.holland@xxxxxxxxxx> wrote:
>
> Currently the user-provided shadow stack restore token is not checked
> before being used as the address in ssamoswap.d. While an invalid
> restore token will be caught and raise SIGSEGV, this happens after
> writing 4 bytes of zeroes anywhere in the address space. Check that the
> restore token is at least a valid user address before the swap to ensure
> we do not scribble over kernel memory.
>
> Fixes: 66c9c713de59 ("riscv/signal: save and restore the shadow stack on a signal")
> Signed-off-by: Samuel Holland <samuel.holland@xxxxxxxxxx>
> ---
>
> arch/riscv/kernel/usercfi.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/arch/riscv/kernel/usercfi.c b/arch/riscv/kernel/usercfi.c
> index dec0ba5eff5ea..23c4d6d9d8cbc 100644
> --- a/arch/riscv/kernel/usercfi.c
> +++ b/arch/riscv/kernel/usercfi.c
> @@ -206,10 +206,13 @@ int save_user_shstk(struct task_struct *tsk, unsigned long *saved_shstk_ptr)
> */
> int restore_user_shstk(struct task_struct *tsk, unsigned long shstk_ptr)
> {
> + unsigned long __user *token_ptr = (unsigned long __user *)shstk_ptr;
> unsigned long token = 0;
>
> - token = amo_user_shstk((unsigned long __user *)shstk_ptr, 0);
> + if (!access_ok(token_ptr, sizeof(token)))
> + return -EFAULT;
>
> + token = amo_user_shstk(token_ptr, 0);
> if (token == -1)
> return -EFAULT;
>

LGTM.

Reviewed-by: Zong Li <zong.li@xxxxxxxxxx>

> --
> 2.52.0
>
> base-commit: a90ee4305c4a5df72c11b31dacfdc76e00fcf78a
> branch: up/cfi-fixes