Using __kuser_cmpxchg

Brian Swetland swetland@google.com
Fri Nov 16 10:51:00 GMT 2007


[Andrew Haley <aph@redhat.com>]
> Nicolas Pitre writes:
>  > 
>  > So we cheat a bit by simply performing the load+compare+store with 
>  > plain standard instructions as follows:
>  > 
>  >         teq     ip, ip                  @ set Z flag
>  >         ldr     ip, [r2]                @ load current val
>  >         add     r3, r2, #1              @ prepare store ptr
>  >         teqeq   ip, r0                  @ compare with oldval if still allowed
>  >         streq   r1, [r3, #-1]!          @ store newval if still allowed
>  >         subs    r0, r2, r3              @ if r2 == r3 the str occured
>  > 
>  > But there is a twist such that if ever an exception occurs during that 
>  > sequence, the Z flag is cleared by the exception handler before that 
>  > sequence is resumed and the store won't occur.
> 
> Ok, please stop there.  I don't understand this at all: if an
> exception occurs surely we'll save and restore the flags.  How is it
> possible for an exception to corrupt the user space Z flag?

Check out arch/arm/kernel/entry-armv.S

The code in question is in __kuser_cmpxchg.  The usr_entry macro
(near the top of the file) clears the Z flag if userspace PC is
high enough.  __kuser_cmpxchg is way up high at 0xffff0fc0.

It's a really cute trick.  The Z flag becomes a side-effect of
an exception, ensuring that the cmpxchg "fails" in that case,
and then can be called again to retry by the wrapping function.

Brian



More information about the Java mailing list