From nobody Fri Oct 2 10:08:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 29DEC3BBA05; Sun, 2 Aug 2026 15:51:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785685914; cv=none; b=kJZhxXXLeLgY4hd+gx/rXGSzdyxJ66KX7bXLv1RCay1hjILy3voEJCIL+O//He9SIpsnMk+O0x3/M9hG2yLHh0pVVyUlYGk650qYHTMhlIDfwvHLUcETEeUF+3p6zNXMVRjoCsog1KEHoXDdj5pcX7ex87ryk9qROdMSc084gMw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785685914; c=relaxed/simple; bh=kssaiTpuWaSTBvemdKDrGWLjRwD6PJPPxprkYN1MRtQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=sIkeNsmVCds79/8gYmgd1hgauTz+hy3AvBDZYXi5/y1Tn8MSe907xFloyjY7KpSTQKT5N5rJwAq4IF2/QKkI8bgQY7VQ4NKpNFAhY5mA7NcQen+oS1kDLAbe8z3krlUA1O+2rXuKYPFPNYvEpCK3pF2il57iLIA6+TDq1Porw7Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=I3FP+wgI; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="I3FP+wgI" Received: by smtp.kernel.org (Postfix) with ESMTPS id D3279C2BCF7; Sun, 2 Aug 2026 15:51:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785685913; bh=kssaiTpuWaSTBvemdKDrGWLjRwD6PJPPxprkYN1MRtQ=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=I3FP+wgIF7O6kvY2cQLAWY1vQX/aS660tYVZ9XIsgRrHbNaoHvkQsit1ZLS7iw6L2 3GaEY1kqklhoisrGHuuXPADe6GbmD8cXdhodUjbw2WTBAE5GZRWTkqzMBtHm7SZ2xP e580fnyKEQ6kLCM7lehSpBXd4kkJIRystME7R5EIYnDlw4MP/YOjHo7y2ty4cKTMYK 9gehlOONxWKOq0MWgE6mCWAiUMWAW7dwtazXm6Krv3+c48kAuvMk+Rn24uw12fXymx UHjlij87sTa0Mg285RNE1swXzW3nOVMRAGP4VHPc6azd+0Ym6D3T7Gy19w37f1wh2k GRYf6/ye5H/LA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B3AB8C55162; Sun, 2 Aug 2026 15:51:53 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Sun, 02 Aug 2026 23:51:39 +0800 Subject: [PATCH 1/6] powerpc/spufs: fix spu_context leak in coredump Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260802-fixes-v1-1-7368423440f4@outlook.com> References: <20260802-fixes-v1-0-7368423440f4@outlook.com> In-Reply-To: <20260802-fixes-v1-0-7368423440f4@outlook.com> To: Madhavan Srinivasan , Michael Ellerman , Nicholas Piggin , "Christophe Leroy (CS GROUP)" , Paul Mackerras , Arnd Bergmann , Al Viro Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1723; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=4NyNHOiKkA4MH4J7oCGRtB6kCVTq8tsAtxRO2bfYk0g=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrPz0aQ/f7o50yDxiLOf7RMF8+oaGq+FhITvXLakqa 71w6LqkQXtHKQuDGBeDrJgiy/GCS98sfLfobvHZkgwzh5UJZAgDF6cATGTeEUaGj6cyeValXTCt FQgxjG+NvjRv1+qIe0sdvrpwhDsuOve0gZFh4tb5rZyLDGb4ub3v2xMi7n3OzdKlwUjA08iycoJ F23dOAPdZSaI= X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo coredump_next_context() returns a spu_context with a reference taken by get_spu_context(), which the caller must drop. spufs_coredump_extra_notes_size() does so on all of its exits, but spufs_coredump_extra_notes_write() never calls put_spu_context(), so every context dumped through elf_coredump_extra_notes_write() leaks a reference, including on the success path. Fix by dropping the reference on each of the three exits of the loop, mirroring ..._size(). Fixes: 38b407be172d ("powerpc/spufs: Rework fcheck() usage") Reported-by: Yuhao Jiang Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo Reviewed-by: Arnd Bergmann --- arch/powerpc/platforms/cell/spufs/coredump.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/arch/powerpc/platforms/cell/spufs/coredump.c b/arch/powerpc/pl= atforms/cell/spufs/coredump.c index 301ee7d8b7df..f5964c9ebb3e 100644 --- a/arch/powerpc/platforms/cell/spufs/coredump.c +++ b/arch/powerpc/platforms/cell/spufs/coredump.c @@ -162,13 +162,16 @@ int spufs_coredump_extra_notes_write(struct coredump_= params *cprm) fd =3D 0; while ((ctx =3D coredump_next_context(&fd)) !=3D NULL) { rc =3D spu_acquire_saved(ctx); - if (rc) + if (rc) { + put_spu_context(ctx); return rc; + } =20 for (j =3D 0; spufs_coredump_read[j].name !=3D NULL; j++) { rc =3D spufs_arch_write_note(ctx, j, cprm, fd); if (rc) { spu_release_saved(ctx); + put_spu_context(ctx); return rc; } } @@ -177,6 +180,7 @@ int spufs_coredump_extra_notes_write(struct coredump_pa= rams *cprm) =20 /* start searching the next fd next time */ fd++; + put_spu_context(ctx); } =20 return 0; --=20 2.51.2 From nobody Fri Oct 2 10:08:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 29F0D3BD629; Sun, 2 Aug 2026 15:51:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785685914; cv=none; b=RbfnZfMX0R7CfFtyME4KrV3USXZXqX51jF4QP/P/LEfc2cVDWFiov2dQHc5bJww/R0qOM/c6YjqHLHU5y5wt3rcTlQpAvC4cED3mkLWrFBz7Nwwf3AwAoQHgqWYw21Wa2T9tQeFWSBjwXuGo1YsEbngXyiBIO8iIhg/TrlxZpGk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785685914; c=relaxed/simple; bh=m9qYyZFPWHD8u5pzGA5bglHhVct9JFkiPueOzfG68c4=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=jRvbg2HMfPNKBqCkXk2RzADmye7b8ArtD2Z9QisPLcOBOzKb410DXXIWz94GYQhET+pJ2qW5sNxDq/LXI2JOGVGk/5bTfdHs6/4Bpjznh0k4PIk3/HUbjQiZSk69P/4rEb/aQQbFHReMNTmsP/7oEwdL/c1TiqGCNE947EcgZno= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=HT1TEx3L; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="HT1TEx3L" Received: by smtp.kernel.org (Postfix) with ESMTPS id DF71EC2BCFC; Sun, 2 Aug 2026 15:51:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785685914; bh=m9qYyZFPWHD8u5pzGA5bglHhVct9JFkiPueOzfG68c4=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=HT1TEx3LzVMlFIPHrO539PJgrk6KZ2iqRWj6o78PyzST2LisTa+5MdZrZ4CaH8/Qr BEXWXreFll8DwFqO7bapdJeEYpmyJI8huupkDo+iCGa3sz4F1cIdtIsZSMeqK0vZqB YDVIAkN43twkbVDaJbOf44M3vQA6FnkHhfdUjciBQfdhD015mth6VheKo7/5sYz6M+ /sAQlT5LbOT6w75FVlq8yp7nOZTSqepPf6Y16Fm5/zNvK4zfCXCHNXSti9BwojEE2E yrIYFINnpkBZTYyGWtvEwXFVdNCwUJGZNb6ItLs3pGGrJfrlqSH4p8cx4ZYdq9kF0v MAciI8dZ1NQwA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C0D0BC55175; Sun, 2 Aug 2026 15:51:53 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Sun, 02 Aug 2026 23:51:40 +0800 Subject: [PATCH 2/6] powerpc/spufs: don't leak kernel stack via spu_run Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260802-fixes-v1-2-7368423440f4@outlook.com> References: <20260802-fixes-v1-0-7368423440f4@outlook.com> In-Reply-To: <20260802-fixes-v1-0-7368423440f4@outlook.com> To: Madhavan Srinivasan , Michael Ellerman , Nicholas Piggin , "Christophe Leroy (CS GROUP)" , Paul Mackerras , Arnd Bergmann , Al Viro Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1557; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=JbhPcONN9PAPqWDS7IAW9bNoVq7Tog3058VmeC72cKQ=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrPz06RI7tzly3IkWCtuj8vPhkaZmvtV/ug8FBss8e HNfaFNiXWVHKQuDGBeDrJgiy/GCS98sfLfobvHZkgwzh5UJZAgDF6cATOTyLob/QRPi7m7dHi72 8PEzY7EU9eWi4novRY2vZ71cqXig1bj0EcN/f/XvderGXuX/vnytr1yyYlbW5zsPbLaw9t5d5K7 5e20hOwBtQk9E X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo do_spu_run() hands the address of an uninitialized local to spufs_run_spu() and then copies it out unconditionally: u32 npc, status; ... ret =3D spufs_run_spu(i->i_ctx, &npc, &status); ... if (ustatus && put_user(status, ustatus)) ret =3D -EFAULT; spufs_run_spu() writes through that pointer at exactly one place, the "out:" label, and two of its exits never reach it: the interruptible acquisition of ctx->run_mutex returns -ERESTARTSYS directly, and a failed spu_acquire() jumps to "out_unlock", which sits just after the assignment. Initialize status to 0, which is what userspace would have observed had the assignment been reached anyway: spufs_run_spu() resets ctx->event_return to 0 on entry, and 0 is the "no events pending" value for this word. Fixes: 67207b9664a8 ("[PATCH] spufs: The SPU file system, base") Reported-by: Yuhao Jiang Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo Reviewed-by: Arnd Bergmann --- arch/powerpc/platforms/cell/spufs/syscalls.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/powerpc/platforms/cell/spufs/syscalls.c b/arch/powerpc/pl= atforms/cell/spufs/syscalls.c index ea4ba1b6ce6a..549fcfbbc140 100644 --- a/arch/powerpc/platforms/cell/spufs/syscalls.c +++ b/arch/powerpc/platforms/cell/spufs/syscalls.c @@ -37,7 +37,7 @@ static long do_spu_run(struct file *filp, { long ret; struct spufs_inode_info *i; - u32 npc, status; + u32 npc, status =3D 0; =20 ret =3D -EFAULT; if (get_user(npc, unpc)) --=20 2.51.2 From nobody Fri Oct 2 10:08:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 29E763BD246; Sun, 2 Aug 2026 15:51:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785685914; cv=none; b=MwX2elBORMJfRaqkXgefcCZJAnmDHUo4DqAwOotrBGVfH4iwp9dm/lmygV3bWlVr05ND71NHe2Esl5RgizPiMz7jaOaN1U+/xuPtfjV2hnUQ8bUCgRV3UGdycfcmTR98YpgRH/OAZcLoVlDladZ3B7a6UX1dY2/hsMVWL/blAXk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785685914; c=relaxed/simple; bh=96mlfMUaIDgRh0Y8+8e2rqme1oeFIIMr4fN0Dk5+hRE=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=KV5dSGrueGEEUcxcTpm4nB6oB+mXxydyU771StSxk9Un6R1ygcLmbF4mzMqd4rMgCXoTtbmHF7IjwYi0HNEGBgYnCvjvKamskMq+ryOa77vucHI72uqpq9OaVlPxeL+JEicOsx7RYPJsKDsGEQhXivWHlojex1CIGbIrjWC3l98= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=IGrZEyBu; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="IGrZEyBu" Received: by smtp.kernel.org (Postfix) with ESMTPS id EA685C2BCFD; Sun, 2 Aug 2026 15:51:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785685914; bh=96mlfMUaIDgRh0Y8+8e2rqme1oeFIIMr4fN0Dk5+hRE=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=IGrZEyBu5ZVT81FcE3gE99cThUtlb2qi+9YwS2LJuCLDZ3VPzmCWibGMGbrThwrm0 1GFKPR1k9gKZ/CryGovWbMNs2tTbKANCsUHZ67qBtb+DvYNnROPvO3CSJQfnt+CiII wIyoggr5ZOEErgtDB1/JVqmmk4EVX8Hbom2lKb9tVCbz9ty5HuBSZhAio/yrkuCnEY LPBpgwhIrxnsgvo9Hocs83mIkii1l6gk1F41uWzivjpWTDVCJFNh5cyboNRnoYJgZa CHHJkpk0HtueQ6QzsrAtyQO4JVG2gvXuoCz8mGSSYPZamRS0indF/Wt7LVAz9/V1Za cV5F7A9Re4XaQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CDFA2C55180; Sun, 2 Aug 2026 15:51:53 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Sun, 02 Aug 2026 23:51:41 +0800 Subject: [PATCH 3/6] powerpc/spufs: bound NPC against local store size Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260802-fixes-v1-3-7368423440f4@outlook.com> References: <20260802-fixes-v1-0-7368423440f4@outlook.com> In-Reply-To: <20260802-fixes-v1-0-7368423440f4@outlook.com> To: Madhavan Srinivasan , Michael Ellerman , Nicholas Piggin , "Christophe Leroy (CS GROUP)" , Paul Mackerras , Arnd Bergmann , Al Viro Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1325; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=zn0rin21Vmi2aZsnEd8aIQAuyKtzsUFBfqpkfQqnfiw=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrPz06QKOEseezU055Jt+YN7t0MAV9xRPVU8XrJ79l bnPia2Ft66jlIVBjItBVkyR5XjBpW8Wvlt0t/hsSYaZw8oEMoSBi1MAJiJpxMjwJSQhxPQeT+qa PmbB6w9T6zI+rX7FWf/mhWuTqt3DpYa/GBlmNs5n5JmYLSKaY2Iy48Gc5OVfS57f8ZVbUK/Pf/7 utBR2AOnlSKw= X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo spu_process_callback() masks the low bits of the NPC register and uses the result as an offset into the SPU local store: `ls_pointer =3D in_be32(ls + npc)`. The following guard validates ls_pointer against LS_SIZE, but npc itself is never bounds-checked. Fix by rejecting npc greater than LS_SIZE - sizeof(ls_pointer) before the read, mirroring the adjacent ls_pointer guard and returning the same -EFAULT. Fixes: 2dd14934c913 ("[PATCH] spufs: allow SPU code to do syscalls") Reported-by: Yuhao Jiang Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo --- arch/powerpc/platforms/cell/spufs/run.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/arch/powerpc/platforms/cell/spufs/run.c b/arch/powerpc/platfor= ms/cell/spufs/run.c index ce52b87496d2..87497316d128 100644 --- a/arch/powerpc/platforms/cell/spufs/run.c +++ b/arch/powerpc/platforms/cell/spufs/run.c @@ -317,6 +317,8 @@ static int spu_process_callback(struct spu_context *ctx) /* get syscall block from local store */ npc =3D ctx->ops->npc_read(ctx) & ~3; ls =3D (void __iomem *)ctx->ops->get_ls(ctx); + if (npc > (LS_SIZE - sizeof(ls_pointer))) + return -EFAULT; ls_pointer =3D in_be32(ls + npc); if (ls_pointer > (LS_SIZE - sizeof(s))) return -EFAULT; --=20 2.51.2 From nobody Fri Oct 2 10:08:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 325EC3BFACC; Sun, 2 Aug 2026 15:51:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785685914; cv=none; b=D5BT0ynrD9SNei1QWLG6R9QUo24BmYIxP9F8tiGL5zcMTn9bf0bGOy8JI0hBVhGfeQw9b9LsKDhTVptkTMQHmn359dTYSF6OvDL5PPm1NJjc5PzbxjvG267fdnLeqTelrJ/PhWt7OWJmOCNn9yllTKjiBFXK3bZ4bk1DZjJ2urg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785685914; c=relaxed/simple; bh=vXE2AV78Cf4cBIpFGvjs0Jox33f1sFJXn10xcbgQjPo=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=KUV2Z6XWF2cS/ZQry5OrAystItl9EHcLQKGaeihCg6t1gz5kQc1XhjDcrNII1OWzuQDlFr9TDmF2aQ9u9GkppYsFvnCTPB/KY8bIbqOdXjh3GG2xPgMrV9kNqhA6jLRS2jc5iJ0yTxHQi7ryN8vmJPmuYB5Cza5Bxa1GcaFQIyM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=BPQ5qquV; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="BPQ5qquV" Received: by smtp.kernel.org (Postfix) with ESMTPS id EF73DC2BCFB; Sun, 2 Aug 2026 15:51:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785685914; bh=vXE2AV78Cf4cBIpFGvjs0Jox33f1sFJXn10xcbgQjPo=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=BPQ5qquVL2yBC7IgjHhyEXmaZ33lBl76MgJwFZZmVlN89ZabMrOELqx2zkOZUQT6v KBEt9xvewY146oze/t5oITyCztfrlHHTJ7I48EnHmSHjcqc+3MAeUrGDuYILLhdqdk PQZO1v0bUYy2YD3ILlSnNyzoqd01AqnkADZlLSICunQzFy2errMfg4MafrNMxaHcd7 kCqmWOpxRt/IqUvyKgq32Bf137oLcsKSMXHdGlyLFP3xoKkYvsXeQkyrSvFnLS2svU YAMfXmyKE4iit4Qwx7NkbyVldD2ruUiZ5h0EbE7amwCQm/rYbbuBn9p1uU51PMSCR/ jJrDUAkSPMIyw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DB682C55177; Sun, 2 Aug 2026 15:51:53 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Sun, 02 Aug 2026 23:51:42 +0800 Subject: [PATCH 4/6] powerpc/spufs: check permissions in spufs_setattr() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260802-fixes-v1-4-7368423440f4@outlook.com> References: <20260802-fixes-v1-0-7368423440f4@outlook.com> In-Reply-To: <20260802-fixes-v1-0-7368423440f4@outlook.com> To: Madhavan Srinivasan , Michael Ellerman , Nicholas Piggin , "Christophe Leroy (CS GROUP)" , Paul Mackerras , Arnd Bergmann , Al Viro Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1679; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=bHGF2umld4asI61QtFVSR8rrvQgLxL9YyHNp5cEh3fE=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrPz06U/5amU+1+kqnpvxr2m3yL3X705r3d7mFa16n O2jFc9a+eyOUhYGMS4GWTFFluMFl75Z+G7R3eKzJRlmDisTyBAGLk4BmEh3ACPDgdXfpr6aZ7lX qGydSJf7a52yL29mya46IF605ubD/HB9XoZ/xmZmju/PyLE2+p6uiWR1iT8W9Xj+3Xs3LpXUXnW adfohCwAnQk23 X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo spufs_setattr() applies the caller's attributes with setattr_copy() but never calls setattr_prepare(). notify_change() leaves that to the filesystem: it runs only may_setattr(), while inode_owner_or_capable() and the CAP_CHOWN test live inside setattr_prepare(). setattr_copy() performs no checking of its own. The handler is installed for every regular spufs file, so mode and ownership of another user's context files can be changed without the usual authorization. Call setattr_prepare() before setattr_copy(). The existing ATTR_SIZE test stays ahead of it so that resizing a spufs file keeps returning -EINVAL. &nop_mnt_idmap matches the adjacent setattr_copy() call. Fixes: 67207b9664a8 ("[PATCH] spufs: The SPU file system, base") Reported-by: Yuhao Jiang Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo Reviewed-by: Arnd Bergmann --- arch/powerpc/platforms/cell/spufs/inode.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/arch/powerpc/platforms/cell/spufs/inode.c b/arch/powerpc/platf= orms/cell/spufs/inode.c index 2b54afb31529..c2b15c30f7c0 100644 --- a/arch/powerpc/platforms/cell/spufs/inode.c +++ b/arch/powerpc/platforms/cell/spufs/inode.c @@ -96,10 +96,14 @@ spufs_setattr(struct mnt_idmap *idmap, struct dentry *d= entry, struct iattr *attr) { struct inode *inode =3D d_inode(dentry); + int ret; =20 if ((attr->ia_valid & ATTR_SIZE) && (attr->ia_size !=3D inode->i_size)) return -EINVAL; + ret =3D setattr_prepare(&nop_mnt_idmap, dentry, attr); + if (ret) + return ret; setattr_copy(&nop_mnt_idmap, inode, attr); mark_inode_dirty(inode); return 0; --=20 2.51.2 From nobody Fri Oct 2 10:08:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5A38C3C198A; Sun, 2 Aug 2026 15:51:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785685914; cv=none; b=gNB5BpVZFXc7jnzFrl5i5uYhapDsXUABkcvIFo+6jCBXTorva6s4VRUjuacyIXMjmHmWjBSFTOvcaPWy8X7KOr6yHVjLAcEU9logM9oKpGZeyQYrY/TZ2ro21+lLq6dGlmXuc62UFvPYcf1jua5LmZz220GD1zhoeXHMmwVdUb0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785685914; c=relaxed/simple; bh=eVXM7QowylgrgD+vcRMf0idml36/gIDDYuz2MC7clJg=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=tshfPk7b2m83VPOC1ZYhADyqsMY5HYsOpNXar2q1Lc/JWjkTPtrkPR/QLhfyzNk6ZlUqXp0gsnHJXL1Le+kc+MUMN3Lif/YVty5A3W4f1majaGeWz23Y6OCIdlRn2xsrnQrdESBhpVvtr1cTJqlkbE04xRMj7Hj29uBfBo18vtQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Frir8NSP; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Frir8NSP" Received: by smtp.kernel.org (Postfix) with ESMTPS id 0AAB4C2BD00; Sun, 2 Aug 2026 15:51:54 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785685914; bh=eVXM7QowylgrgD+vcRMf0idml36/gIDDYuz2MC7clJg=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=Frir8NSPaKOz5yWyhazR4f8aMsKwU667Q529WBjhoHljUoiQRbRuUxNSxoxJ5KpXR UNuXFhZ6kCPEuLGxktM81XgczYAA8lgk/98MumZk+2KT2ZoWIyGyKYprTqD/CGQHSG A+/zPa4DwdDI0zOFqfWNNCdsJYpc7AkoGSWoFaIO9OPn04J2pCtofp4TLjFaHzPoHu yDSKWQzZg/XNb1h9+C5AJJpyH9lXKNz6sp4zehVmmRF60Oe/Vbc1T8LQo0BhCL1CLM dSE0OgZj1khr5rpaIkz7FEX1pISTbunOujpm+DuZAmX+Ye9AMNR28MKvvlRfZAbl1P NhvDC1uTvZMdg== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E86A3C55184; Sun, 2 Aug 2026 15:51:53 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Sun, 02 Aug 2026 23:51:43 +0800 Subject: [PATCH 5/6] powerpc/spufs: fix deadlock on gang creation failure Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260802-fixes-v1-5-7368423440f4@outlook.com> References: <20260802-fixes-v1-0-7368423440f4@outlook.com> In-Reply-To: <20260802-fixes-v1-0-7368423440f4@outlook.com> To: Madhavan Srinivasan , Michael Ellerman , Nicholas Piggin , "Christophe Leroy (CS GROUP)" , Paul Mackerras , Arnd Bergmann , Al Viro Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=3003; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=sNBdhSvUH4Nc3dR73ItBK/i22i57aFEVzgsW9ggCOvU=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrPz0Gclb/hnZ73M34u+Z98Hd5tv8zilH/im72ka++ tOTstn0f29HKQuDGBeDrJgiy/GCS98sfLfobvHZkgwzh5UJZAgDF6cATOTdaoZ/Zuu1/l+XiNMx UrZ9kXfhSUREkWY3o9Zz6b5TZ59vFrbOYGToDXcT3+ZlMS+zZcIE09yLzc1na74u/ahmVyiW43m ibQsvAE8LS9o= X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo do_spu_create() enters spufs with the parent directory's i_rwsem held for write, taken as I_MUTEX_PARENT by start_creating_user_path() and dropped only by end_creating_path(). When spufs_gang_open() fails inside that window, spufs_create_gang() cleans up by calling unuse_gang(). The gang was just created, so gang->alive drops to 0 and unuse_gang() proceeds to simple_recursive_removal(), which takes the parent inode's i_rwsem as I_MUTEX_CHILD. This leads to the task blocking on an rwsem it already holds, leaving the spufs directory write-locked. The other two callers of unuse_gang() do not hold the parent lock: spufs_gang_close() runs from ->release, and spufs_dir_close() drops the parent lock first. Tell unuse_gang() which context it is called from, and use locked_recursive_removal() when the parent is already held. This matches spufs_rmdir(), which spufs_create_context() already uses for the same cleanup under the same lock. Fixes: c134deabf478 ("spufs: fix gang directory lifetimes") Reported-by: Yuhao Jiang Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo --- arch/powerpc/platforms/cell/spufs/inode.c | 17 +++++++++++------ 1 file changed, 11 insertions(+), 6 deletions(-) diff --git a/arch/powerpc/platforms/cell/spufs/inode.c b/arch/powerpc/platf= orms/cell/spufs/inode.c index c2b15c30f7c0..998512409552 100644 --- a/arch/powerpc/platforms/cell/spufs/inode.c +++ b/arch/powerpc/platforms/cell/spufs/inode.c @@ -175,7 +175,8 @@ static int spufs_fill_dir(struct dentry *dir, return 0; } =20 -static void unuse_gang(struct dentry *dir) +/* @parent_locked: caller holds dir->d_parent's i_rwsem as I_MUTEX_PARENT = */ +static void unuse_gang(struct dentry *dir, bool parent_locked) { struct inode *inode =3D dir->d_inode; struct spu_gang *gang =3D SPUFS_I(inode)->i_gang; @@ -187,8 +188,12 @@ static void unuse_gang(struct dentry *dir) dead =3D !--gang->alive; inode_unlock(inode); =20 - if (dead) - simple_recursive_removal(dir, NULL); + if (dead) { + if (parent_locked) + locked_recursive_removal(dir, NULL); + else + simple_recursive_removal(dir, NULL); + } } } =20 @@ -204,7 +209,7 @@ static int spufs_dir_close(struct inode *inode, struct = file *file) spufs_rmdir(parent, dir); inode_unlock(parent); =20 - unuse_gang(dir->d_parent); + unuse_gang(dir->d_parent, false); return dcache_dir_close(inode, file); } =20 @@ -483,7 +488,7 @@ spufs_mkgang(struct inode *dir, struct dentry *dentry, = umode_t mode) =20 static int spufs_gang_close(struct inode *inode, struct file *file) { - unuse_gang(file->f_path.dentry); + unuse_gang(file->f_path.dentry, false); return dcache_dir_close(inode, file); } =20 @@ -520,7 +525,7 @@ static int spufs_create_gang(struct inode *inode, if (!ret) { ret =3D spufs_gang_open(&path); if (ret < 0) - unuse_gang(dentry); + unuse_gang(dentry, true); } return ret; } --=20 2.51.2 From nobody Fri Oct 2 10:08:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5A2633C10B6 for ; Sun, 2 Aug 2026 15:51:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785685914; cv=none; b=ggOy8ILxhU6YvpVmE0kCPfsRv2nc5d21bH9s3hX2B46MHvw5l/CbjkDoBcfyqXEaTApyAc1MAJMADRK9f0OgXagGYWb7fMS2juGP5qlJiZuCJT9Lo3D6JNFrhveH8WXIvBBHE/asigNlt62L0cZF1VP23Dwty+gdjLACP4cV6lc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785685914; c=relaxed/simple; bh=0/POHxMnwRqE3ITFA8w+z2Q7B0vIwOI/AChWEwTMH/w=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=kAUHlqCpxYa3gAQ33yselMiRCm5VpnZE1o+SvNW8xjPbznF7Swkhi7P5F9CXxrkPHkWCobpopyfwvmiP0KR8N3oMa6mrikG9c0QXCFYZsnHkpqCz3W2+Iw32lo3ezY9fT0D7mgl7LiGCwZMBged3sYDKMgx6U1DfZ9dwA5skhpQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=JmAZZbrD; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="JmAZZbrD" Received: by smtp.kernel.org (Postfix) with ESMTPS id 1831DC32781; Sun, 2 Aug 2026 15:51:54 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785685914; bh=0/POHxMnwRqE3ITFA8w+z2Q7B0vIwOI/AChWEwTMH/w=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=JmAZZbrDzPqllK5jsnd1bZx7CNxz2eVk+40V671JTD+jeUiJyrXhrlFs16+P/9Zu9 1NGHnGCNXkzVu5C6H0/OtlXEsTsfZpOpzDtitpU7NIbgKW2olOG/zZ8ALe3wwP9+FK 5k/YGWSjNAd6t2zpCjgpFI+scso/dHW6e0DEppIXYzI3xxQRoudgBQTgCo1RBQjRhm mkZ0KnYazqRt0taCQ+wr6YtMwnGlN1p8y5gOtIbslDdhD7WLAr/a7AbEwzNimG7g10 9FLJ26QdsdYzH5k1dCCVV0hWcqS6tXHlDedYRphpPkgmHLBcM1yLG6n5lePlzEUhig 4NCdLSaa5LC3A== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 01453C55162; Sun, 2 Aug 2026 15:51:54 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Sun, 02 Aug 2026 23:51:44 +0800 Subject: [PATCH 6/6] powerpc/spufs: don't hold state_mutex during user access Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260802-fixes-v1-6-7368423440f4@outlook.com> References: <20260802-fixes-v1-0-7368423440f4@outlook.com> In-Reply-To: <20260802-fixes-v1-0-7368423440f4@outlook.com> To: Madhavan Srinivasan , Michael Ellerman , Nicholas Piggin , "Christophe Leroy (CS GROUP)" , Paul Mackerras , Arnd Bergmann , Al Viro Cc: linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, Junrui Luo , Yuhao Jiang X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=4070; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=NzneP8KvCjHXivWs94zRxQBae+0khgOio5T2NiN1ITc=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrPz0GVPY35VtNGF5GLi7mJXjXtr053r18pZCaac/T AqX95VZ8aujlIVBjItBVkyR5XjBpW8Wvlt0t/hsSYaZw8oEMoSBi1MAJmJ/nJHhVtznD0tjUoRM 7BfG7bgsvTrR/0rEgo7AhCnbt3w13GSpzcjQPmVuqmqexcbzslnXIhUdl+pfXfjKU3txDWOSztI FLB7MANWBR3s= X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo spufs_mbox_read(), spufs_ibox_read() and spufs_wbox_write() take the context state_mutex with spu_acquire() and only drop it once their transfer loop has finished, so every put_user()/get_user() in those loops runs with the mutex held. The faulting address comes from userspace, so the fault can be made to take arbitrarily long via userfaultfd region or a FUSE-backed mapping. Drop the mutex around the user accesses: acquire it per mailbox element, just long enough for the ctx->ops mailbox operation, and release it before touching the user buffer. spufs_switch_log_read() has the same problem but its loop needs the lock for more than just the copy. Fixes: cdcc89bb1c6e ("[POWERPC] spufs: make mailbox functions handle multip= le elements") Reported-by: Yuhao Jiang Signed-off-by: Junrui Luo Reviewed-by: Arnd Bergmann --- arch/powerpc/platforms/cell/spufs/file.c | 52 ++++++++++++++++++----------= ---- 1 file changed, 29 insertions(+), 23 deletions(-) diff --git a/arch/powerpc/platforms/cell/spufs/file.c b/arch/powerpc/platfo= rms/cell/spufs/file.c index de7494748fec..c8c3b6e8affb 100644 --- a/arch/powerpc/platforms/cell/spufs/file.c +++ b/arch/powerpc/platforms/cell/spufs/file.c @@ -602,13 +602,17 @@ static ssize_t spufs_mbox_read(struct file *file, cha= r __user *buf, if (len < 4) return -EINVAL; =20 - count =3D spu_acquire(ctx); - if (count) - return count; - for (count =3D 0; (count + 4) <=3D len; count +=3D 4, udata++) { int ret; + + ret =3D spu_acquire(ctx); + if (ret) { + if (!count) + count =3D ret; + break; + } ret =3D ctx->ops->mbox_read(ctx, &mbox_data); + spu_release(ctx); if (ret =3D=3D 0) break; =20 @@ -624,7 +628,6 @@ static ssize_t spufs_mbox_read(struct file *file, char = __user *buf, break; } } - spu_release(ctx); =20 if (!count) count =3D -EAGAIN; @@ -705,29 +708,34 @@ static ssize_t spufs_ibox_read(struct file *file, cha= r __user *buf, =20 count =3D spu_acquire(ctx); if (count) - goto out; + return count; =20 /* wait only for the first element */ - count =3D 0; if (file->f_flags & O_NONBLOCK) { if (!spu_ibox_read(ctx, &ibox_data)) { - count =3D -EAGAIN; - goto out_unlock; + spu_release(ctx); + return -EAGAIN; } } else { count =3D spufs_wait(ctx->ibox_wq, spu_ibox_read(ctx, &ibox_data)); if (count) - goto out; + return count; } + spu_release(ctx); =20 /* if we can't write at all, return -EFAULT */ count =3D put_user(ibox_data, udata); if (count) - goto out_unlock; + return count; =20 for (count =3D 4, udata++; (count + 4) <=3D len; count +=3D 4, udata++) { int ret; + + ret =3D spu_acquire(ctx); + if (ret) + break; ret =3D ctx->ops->ibox_read(ctx, &ibox_data); + spu_release(ctx); if (ret =3D=3D 0) break; /* @@ -740,9 +748,6 @@ static ssize_t spufs_ibox_read(struct file *file, char = __user *buf, break; } =20 -out_unlock: - spu_release(ctx); -out: return count; } =20 @@ -839,40 +844,41 @@ static ssize_t spufs_wbox_write(struct file *file, co= nst char __user *buf, =20 count =3D spu_acquire(ctx); if (count) - goto out; + return count; =20 /* * make sure we can at least write one element, by waiting * in case of !O_NONBLOCK */ - count =3D 0; if (file->f_flags & O_NONBLOCK) { if (!spu_wbox_write(ctx, wbox_data)) { - count =3D -EAGAIN; - goto out_unlock; + spu_release(ctx); + return -EAGAIN; } } else { count =3D spufs_wait(ctx->wbox_wq, spu_wbox_write(ctx, wbox_data)); if (count) - goto out; + return count; } - + spu_release(ctx); =20 /* write as much as possible */ for (count =3D 4, udata++; (count + 4) <=3D len; count +=3D 4, udata++) { int ret; + ret =3D get_user(wbox_data, udata); if (ret) break; =20 + ret =3D spu_acquire(ctx); + if (ret) + break; ret =3D spu_wbox_write(ctx, wbox_data); + spu_release(ctx); if (ret =3D=3D 0) break; } =20 -out_unlock: - spu_release(ctx); -out: return count; } =20 --=20 2.51.2