On failure get_user() is supposed to zero out the destination variable.
This is documented in the kdoc of the microblaze get_user()
implementation and validated in lib/tests/usercopy_kunit.c.
Currently that zeroing is missing.
Add it.
Fixes:
0d6de9532663 ("microblaze_mmu_v2: uaccess MMU update")
Signed-off-by: Thomas Weißschuh <linux@weissschuh.net>
Reviewed-by: David Gow <david@davidgow.net>
Link: https://patch.msgid.link/20260914-kunit-microblaze-v2-1-7d5756e858f8@weissschuh.net
Signed-off-by: Michal Simek <michal.simek@amd.com>
#define get_user(x, ptr) ({ \
const typeof(*(ptr)) __user *__gu_ptr = (ptr); \
access_ok(__gu_ptr, sizeof(*__gu_ptr)) ? \
- __get_user(x, __gu_ptr) : -EFAULT; \
+ __get_user(x, __gu_ptr) : \
+ ((x) = 0, -EFAULT); \
})
#define __get_user(x, ptr) \