Re: [PATCH 2/2] riscv: cfi: Only write envcfg CSR when task is current
From: Zong Li
Date: Thu Oct 08 2026 - 02:12:51 EST
On Wed, Oct 7, 2026 at 11:57 PM Samuel Holland
<samuel.holland@xxxxxxxxxx> wrote:
>
> set_shstk_status() and set_indir_lp_status() take a task argument, which
> lets them operate on tasks other than current, but they always write the
> envcfg CSR for the current task. Fix this with the envcfg_update_bits()
> helper, which only writes the envcfg CSR when operating on current.
>
> Fixes: 61a0200211d31e ("riscv: Implement arch-agnostic shadow stack prctls")
> Fixes: 8a9e22d2ca5855 ("riscv: Implement indirect branch tracking prctls")
> Signed-off-by: Samuel Holland <samuel.holland@xxxxxxxxxx>
> ---
>
> arch/riscv/kernel/usercfi.c | 15 +++------------
> 1 file changed, 3 insertions(+), 12 deletions(-)
>
> diff --git a/arch/riscv/kernel/usercfi.c b/arch/riscv/kernel/usercfi.c
> index 23c4d6d9d8cbc..86141e5bab822 100644
> --- a/arch/riscv/kernel/usercfi.c
> +++ b/arch/riscv/kernel/usercfi.c
> @@ -15,6 +15,7 @@
> #include <linux/syscalls.h>
> #include <linux/prctl.h>
> #include <asm/csr.h>
> +#include <asm/switch_to.h>
> #include <asm/usercfi.h>
>
> unsigned long riscv_nousercfi __read_mostly;
> @@ -66,12 +67,7 @@ void set_shstk_status(struct task_struct *task, bool enable)
>
> task->thread_info.user_cfi_state.ubcfi_en = enable ? 1 : 0;
>
> - if (enable)
> - task->thread.envcfg |= ENVCFG_SSE;
> - else
> - task->thread.envcfg &= ~ENVCFG_SSE;
> -
> - csr_write(CSR_ENVCFG, task->thread.envcfg);
> + envcfg_update_bits(task, ENVCFG_SSE, enable ? ENVCFG_SSE : 0);
> }
>
> void set_shstk_lock(struct task_struct *task, bool lock)
> @@ -96,12 +92,7 @@ void set_indir_lp_status(struct task_struct *task, bool enable)
>
> task->thread_info.user_cfi_state.ufcfi_en = enable ? 1 : 0;
>
> - if (enable)
> - task->thread.envcfg |= ENVCFG_LPE;
> - else
> - task->thread.envcfg &= ~ENVCFG_LPE;
> -
> - csr_write(CSR_ENVCFG, task->thread.envcfg);
> + envcfg_update_bits(task, ENVCFG_LPE, enable ? ENVCFG_LPE : 0);
> }
>
> void set_indir_lp_lock(struct task_struct *task, bool lock)
LGTM
Reviewed-by: Zong Li <zong.li@xxxxxxxxxx>
> --
> 2.52.0
>
> base-commit: a90ee4305c4a5df72c11b31dacfdc76e00fcf78a
> branch: up/cfi-fixes