[PATCH 0/7] arm64: Batch PSTATE.TCO handling in kernel nofault loops
From: Muhammad Usama Anjum
Date: Mon Aug 24 2026 - 12:09:33 EST
With Hardware Tag-Based KASAN in asynchronous or asymmetric mode, kernel
nofault loops currently set and clear PSTATE.TCO around every access.
Introduce bare nofault accessors, batching hooks, and an internal scope
guard. Convert maccess page-fault cleanup to scoped form. Skip
page-fault setup for zero-sized kernel nofault copies and zero-length
BPF string operations. Then use bare primitives in the maccess and BPF
loops. For non-empty operations, this reduces the code-derived dynamic
MSR TCO execution count from 2N to 2. Two-string BPF comparisons fall
from 4N to 2.
The BPF changes and an earlier maccess implementation with explicit
cleanup were tested with QEMU arm64 using Hardware Tag-Based KASAN in
synchronous, asynchronous, and asymmetric modes. All nine arm64 MTE
kselftests passed in each mode, as did the 138 focused BPF string_kfuncs
and varlen subtests. The focused BPF tests also passed with the default
non-MTE arm64 CPU model. Both final maccess scoped-guard patches were
arm64 cross-built. Runtime tests have not been rerun after that
conversion.
Muhammad Usama Anjum (7):
arm64: uaccess: Add batched kernel nofault accessors
uaccess: Add scope guard for bare kernel nofault regions
maccess: Skip setup for zero-sized kernel nofault copies
maccess: Use a scoped guard for page faults
maccess: Batch TCO handling in kernel nofault loops
bpf: Skip setup for zero-length string kfunc operations
bpf: Batch TCO handling in string kfuncs
arch/arm64/include/asm/uaccess.h | 71 ++++++++++++++++++++++++--------
include/linux/uaccess.h | 20 +++++++++
kernel/bpf/helpers.c | 41 ++++++++++++------
mm/maccess.c | 68 ++++++++++++++++--------------
4 files changed, 139 insertions(+), 61 deletions(-)
--
2.47.3