This is an automated email from the ASF dual-hosted git repository.

xiaoxiang781216 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/nuttx.git

commit 50a4f8061daec54c4ed085d25ca6d0e6c746cc17
Author: Royyan Zahir <[email protected]>
AuthorDate: Wed Sep 30 11:26:20 2026 +0400

    arch/arm64: refuse reserved syscalls from user space
    
    Any svc below CONFIG_SYS_RESERVED reached the context switch and signal
    return paths from EL0: a process could crash the kernel or return to
    EL1 through a signal return nobody dispatched.
    
    Signed-off-by: Royyan Zahir <[email protected]>
---
 arch/arm64/src/common/arm64_syscall.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/arch/arm64/src/common/arm64_syscall.c 
b/arch/arm64/src/common/arm64_syscall.c
index e8a34cf505b..312444b018b 100644
--- a/arch/arm64/src/common/arm64_syscall.c
+++ b/arch/arm64/src/common/arm64_syscall.c
@@ -30,6 +30,7 @@
 #include <stdint.h>
 #include <string.h>
 #include <assert.h>
+#include <errno.h>
 #include <nuttx/debug.h>
 #include <syscall.h>
 
@@ -180,6 +181,15 @@ uint64_t *arm64_syscall(uint64_t *regs)
 
   cmd = regs[REG_X0];
 
+#ifdef CONFIG_BUILD_KERNEL
+  if ((regs[REG_SPSR] & SPSR_MODE_MASK) == SPSR_MODE_EL0T &&
+      (cmd != SYS_signal_handler_return || tcb->xcp.sigreturn == 0))
+    {
+      regs[REG_X0] = -ENOSYS;
+      return regs;
+    }
+#endif
+
   /* if cmd == SYS_restore_context (*running_task)->xcp.regs is valid
    * should not be overwritten
    */

Reply via email to