arch/risc-v: refuse reserved syscalls from user mode

Any ecall below CONFIG_SYS_RESERVED reached the context switch and signal
return paths from U-mode: a process could crash the kernel or return to
S-mode through a signal return nobody dispatched.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
This commit is contained in:
Royyan Zahir 2026-09-30 11:27:20 +04:00 • committed by Xiang Xiao
parent 50a4f8061d
commit fd57ce7695

View file

@ -28,6 +28,7 @@
#include <stdint.h>
#include <assert.h>
#include <errno.h>
#include <nuttx/irq.h>
#include <nuttx/addrenv.h>
@ -74,6 +75,18 @@ uintreg_t *riscv_doirq(int irq, uintreg_t *regs)
if (irq >= RISCV_IRQ_ECALLU && irq <= RISCV_IRQ_ECALLM)
{
regs[REG_EPC] += 4;
#ifndef CONFIG_BUILD_FLAT
if (irq == RISCV_IRQ_ECALLU &&
(regs[REG_A0] != SYS_signal_handler_return ||
tcb->xcp.sigreturn == 0))
{
regs[REG_A0] = -ENOSYS;
board_autoled_off(LED_INIRQ);
return regs;
}
#endif
if (regs[REG_A0] != SYS_restore_context)
{
(*running_task)->xcp.regs = regs;