This is an automated email from the ASF dual-hosted git repository.

xiaoxiang781216 pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/nuttx.git

commit fd57ce769570a32a8f403e65d8aecb9f2bb75db8
Author: Royyan Zahir <[email protected]>
AuthorDate: Wed Sep 30 11:27:20 2026 +0400

    arch/risc-v: refuse reserved syscalls from user mode
    
    Any ecall below CONFIG_SYS_RESERVED reached the context switch and signal
    return paths from U-mode: a process could crash the kernel or return to
    S-mode through a signal return nobody dispatched.
    
    Signed-off-by: Royyan Zahir <[email protected]>
---
 arch/risc-v/src/common/riscv_doirq.c | 13 +++++++++++++
 1 file changed, 13 insertions(+)

diff --git a/arch/risc-v/src/common/riscv_doirq.c 
b/arch/risc-v/src/common/riscv_doirq.c
index ee74b12f7ec..93677f6e1cf 100644
--- a/arch/risc-v/src/common/riscv_doirq.c
+++ b/arch/risc-v/src/common/riscv_doirq.c
@@ -28,6 +28,7 @@
 
 #include <stdint.h>
 #include <assert.h>
+#include <errno.h>
 
 #include <nuttx/irq.h>
 #include <nuttx/addrenv.h>
@@ -74,6 +75,18 @@ uintreg_t *riscv_doirq(int irq, uintreg_t *regs)
   if (irq >= RISCV_IRQ_ECALLU && irq <= RISCV_IRQ_ECALLM)
     {
       regs[REG_EPC] += 4;
+
+#ifndef CONFIG_BUILD_FLAT
+      if (irq == RISCV_IRQ_ECALLU &&
+          (regs[REG_A0] != SYS_signal_handler_return ||
+           tcb->xcp.sigreturn == 0))
+        {
+          regs[REG_A0] = -ENOSYS;
+          board_autoled_off(LED_INIRQ);
+          return regs;
+        }
+#endif
+
       if (regs[REG_A0] != SYS_restore_context)
         {
           (*running_task)->xcp.regs = regs;

Reply via email to