[PATCH v2 1/3] sparc64: restore %asi in user_rtt_fill_fixup_common
From: Stian Halseth
Date: Wed Oct 07 2026 - 04:59:22 EST
A window fill that faults re-enters the kernel through
user_rtt_fill_fixup_common(), which does not pass through etrap. rtrap
has already set %asi to ASI_AIUP for the fill, and etrap is what would
normally re-establish ASI_AIUS from the TSTATE it synthesizes, so the
kernel carries on with %asi = ASI_AIUP while the primary context has
just been restored to the kernel's.
Every %asi-based user access made from there - put_user(), get_user()
and everything built on them - then translates in the kernel context.
User addresses below the VA hole fault forever, because nothing ever
fills a context-zero translation for them, and the CPU is wedged in
kernel mode: the task survives SIGKILL, sits in state R at 100% CPU,
and takes the machine down once RCU stalls. Addresses above the hole
fail more quietly, silently aliasing the kernel linear mapping.
Restore the invariant before any user access is attempted.
Fixes: 7cafc0b8bf13 ("sparc64: Fix return from trap window fill crashes.")
Reported-by: John Paul Adrian Glaubitz <glaubitz@xxxxxxxxxxxxxxxxxxx>
Link: https://github.com/sparclinux/issues/issues/87
Signed-off-by: Stian Halseth <stian@xxxxxx>
---
v2: reword the comment as suggested by Andreas: state the restored
invariant first, phrase it as why the write is needed, and leave the
failure-mode details to the commit message. No code change.
arch/sparc/kernel/urtt_fill.S | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/arch/sparc/kernel/urtt_fill.S b/arch/sparc/kernel/urtt_fill.S
index e4cee7be5cd02..1ec67df9b59e3 100644
--- a/arch/sparc/kernel/urtt_fill.S
+++ b/arch/sparc/kernel/urtt_fill.S
@@ -1,4 +1,5 @@
/* SPDX-License-Identifier: GPL-2.0 */
+#include <asm/asi.h>
#include <asm/thread_info.h>
#include <asm/trap_block.h>
#include <asm/spitfire.h>
@@ -32,6 +33,15 @@ user_rtt_fill_fixup_common:
sethi %hi(KERNBASE), %g1
flush %g1
+ /* Restore the kernel's ASI_AIUS invariant, which etrap
+ * would have re-established had we passed through it.
+ * rtrap set %asi to ASI_AIUP for the window fill, and
+ * the primary context is now the kernel's, so a leftover
+ * ASI_AIUP would make %asi-based user accesses (put_user,
+ * get_user) translate in the kernel context.
+ */
+ wr %g0, ASI_AIUS, %asi
+
mov %g4, %l4
mov %g5, %l5
brnz,pn %g3, 1f
--
2.43.0