[POWERPC] Fix subtle FP state corruption bug in signal return on SMP

This fixes a bug which can cause corruption of the floating-point state
on return from a signal handler. If we have a signal handler that has
used the floating-point registers, and it happens to context-switch to
another task while copying the interrupted floating-point state from the
user stack into the thread struct (e.g. because of a page fault, or
because it gets preempted), the context switch code will think that the
FP registers contain valid FP state that needs to be copied into the
thread_struct, and will thus overwrite the values that the signal return
code has put into the thread_struct.

This can occur because we clear the MSR bits that indicate the presence
of valid FP state after copying the state into the thread_struct. To fix
this we just move the clearing of the MSR bits to before the copy. A
similar potential problem also occurs with the Altivec state, and this
fixes that in the same way.

Signed-off-by: Paul Mackerras <paulus@samba.org>

+7 -3
+7 -3
arch/powerpc/kernel/signal_64.c
··· 176 176 */ 177 177 discard_lazy_cpu_state(); 178 178 179 + /* 180 + * Force reload of FP/VEC. 181 + * This has to be done before copying stuff into current->thread.fpr/vr 182 + * for the reasons explained in the previous comment. 183 + */ 184 + regs->msr &= ~(MSR_FP | MSR_FE0 | MSR_FE1 | MSR_VEC); 185 + 179 186 err |= __copy_from_user(&current->thread.fpr, &sc->fp_regs, FP_REGS_SIZE); 180 187 181 188 #ifdef CONFIG_ALTIVEC ··· 203 196 else 204 197 current->thread.vrsave = 0; 205 198 #endif /* CONFIG_ALTIVEC */ 206 - 207 - /* Force reload of FP/VEC */ 208 - regs->msr &= ~(MSR_FP | MSR_FE0 | MSR_FE1 | MSR_VEC); 209 199 210 200 return err; 211 201 }