From fd57ce769570a32a8f403e65d8aecb9f2bb75db8 Mon Sep 17 00:00:00 2001 From: Royyan Zahir Date: Wed, 30 Sep 2026 11:27:20 +0400 Subject: [PATCH] arch/risc-v: refuse reserved syscalls from user mode Any ecall below CONFIG_SYS_RESERVED reached the context switch and signal return paths from U-mode: a process could crash the kernel or return to S-mode through a signal return nobody dispatched. Signed-off-by: Royyan Zahir --- arch/risc-v/src/common/riscv_doirq.c | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/arch/risc-v/src/common/riscv_doirq.c b/arch/risc-v/src/common/riscv_doirq.c index ee74b12f7ec..93677f6e1cf 100644 --- a/arch/risc-v/src/common/riscv_doirq.c +++ b/arch/risc-v/src/common/riscv_doirq.c @@ -28,6 +28,7 @@ #include #include +#include #include #include @@ -74,6 +75,18 @@ uintreg_t *riscv_doirq(int irq, uintreg_t *regs) if (irq >= RISCV_IRQ_ECALLU && irq <= RISCV_IRQ_ECALLM) { regs[REG_EPC] += 4; + +#ifndef CONFIG_BUILD_FLAT + if (irq == RISCV_IRQ_ECALLU && + (regs[REG_A0] != SYS_signal_handler_return || + tcb->xcp.sigreturn == 0)) + { + regs[REG_A0] = -ENOSYS; + board_autoled_off(LED_INIRQ); + return regs; + } +#endif + if (regs[REG_A0] != SYS_restore_context) { (*running_task)->xcp.regs = regs;