Re: [PATCH v2 0/3] sparc64: fix a window fill fixup lockup and two fault bugs

From: Andreas Larsson

Date: Wed Oct 07 2026 - 08:10:14 EST


On 2026-10-07 10:53, Stian Halseth wrote:
> A register window fill that faults is mishandled in three ways on
> sparc64. The first wedges the CPU in kernel mode and takes the machine
> with it; the other two corrupt what the kernel reports about the fault,
> and were found while chasing the first.
>
> 1/3 is the lockup. user_rtt_fill_fixup_common() re-enters the kernel
> without passing through etrap, so %asi is left as the ASI_AIUP that
> rtrap set for the fill while the primary context has been restored to
> the kernel's. Every subsequent %asi-based user access then translates
> in the kernel context, and a user address below the VA hole can never be
> resolved: the fault repeats forever, the task survives SIGKILL, and RCU
> eventually reports the CPU stalled.
>
> The reproducer in the v1 cover letter moves %sp onto a page, flushes the
> register windows, mprotects that page PROT_NONE and takes a signal, so
> the fill on the signal return path faults. It needs no unusual
> configuration and wedges a stock kernel in a few seconds; mind where you
> run it, as the machine needs a hard reset afterwards. On a fixed kernel
> it prints PASS and exits.
>
> 2/3 and 3/3 came out of that investigation. do_fault_siginfo() decodes
> the instruction at regs->tpc to compute si_addr, which is not the
> faulting access when the fault came from a spill or fill; in one capture
> it decoded a branch and reported the contents of %g5. And the huge-page
> path in the TSB miss handler tested TL after switching the global
> register bank, so it consumed a fault code and a PTE that no longer
> existed and killed the task with SIGSEGV at an address that had never
> been mapped. That one needs CONFIG_TRANSPARENT_HUGEPAGE and only
> appears under load.
>
> 1/3 is reproduced and fixed on an UltraSPARC T4-1 (sun4v, Niagara4) and
> on a Sun Fire V240 (sun4u, UltraSPARC-IIIi), which between them cover
> both forms of the global register bank switch, SET_GL and the
> PSTATE_AG|PSTATE_MG write. 2/3 and 3/3 are tested on the T4-1, where
> with all three applied a Go toolchain build now completes five times
> running with THP enabled, having previously died within a minute.
>
> Link: https://github.com/sparclinux/issues/issues/87
>
> v2:
> - 1/3: reword the comment above the %asi write as suggested by
> Andreas: state the restored invariant first, phrase it as why the
> write is needed, and leave the failure-mode details to the commit
> message. No code change.
> - 2/3, 3/3: unchanged.
>
> v1: https://lore.kernel.org/all/20260828123707.1852437-1-stian@xxxxxx/
>
> Stian Halseth (3):
> sparc64: restore %asi in user_rtt_fill_fixup_common
> sparc64: use the fault address for si_addr on window fixup faults
> sparc64: decide the TSB huge-page window fixup before the bank switch
>
> arch/sparc/kernel/tsb.S | 24 ++++++++++++++++++++----
> arch/sparc/kernel/urtt_fill.S | 10 ++++++++++
> arch/sparc/mm/fault_64.c | 9 +++++++++
> 3 files changed, 39 insertions(+), 4 deletions(-)
>

The Tested-by from v1 was unfortunately not incorporated in this
version, so I add it here:

Tested-by: Imre Kaloz <kaloz@xxxxxxxxxx>


Reviewed-by: Andreas Larsson <andreas@xxxxxxxxxxx>

Picking this up to my for-next.

Thanks,
Andreas