Re: [PATCH 1/3] sparc64: restore %asi in user_rtt_fill_fixup_common

From: Andreas Larsson

Date: Wed Oct 07 2026 - 03:22:10 EST


On 2026-08-28 14:37, Stian Halseth wrote:
> A window fill that faults re-enters the kernel through
> user_rtt_fill_fixup_common(), which does not pass through etrap. rtrap
> has already set %asi to ASI_AIUP for the fill, and etrap is what would
> normally re-establish ASI_AIUS from the TSTATE it synthesizes, so the
> kernel carries on with %asi = ASI_AIUP while the primary context has
> just been restored to the kernel's.
>
> Every %asi-based user access made from there - put_user(), get_user()
> and everything built on them - then translates in the kernel context.
> User addresses below the VA hole fault forever, because nothing ever
> fills a context-zero translation for them, and the CPU is wedged in
> kernel mode: the task survives SIGKILL, sits in state R at 100% CPU,
> and takes the machine down once RCU stalls. Addresses above the hole
> fail more quietly, silently aliasing the kernel linear mapping.
>
> Restore the invariant before any user access is attempted.
>
> Fixes: 7cafc0b8bf13 ("sparc64: Fix return from trap window fill crashes.")
> Reported-by: John Paul Adrian Glaubitz <glaubitz@xxxxxxxxxxxxxxxxxxx>
> Link: https://github.com/sparclinux/issues/issues/87
> Signed-off-by: Stian Halseth <stian@xxxxxx>
> ---
> arch/sparc/kernel/urtt_fill.S | 15 +++++++++++++++
> 1 file changed, 15 insertions(+)
>

Good catch!

> diff --git a/arch/sparc/kernel/urtt_fill.S b/arch/sparc/kernel/urtt_fill.S
> index e4cee7be5cd0..5acd27b18b1e 100644
> --- a/arch/sparc/kernel/urtt_fill.S
> +++ b/arch/sparc/kernel/urtt_fill.S
> @@ -1,4 +1,5 @@
> /* SPDX-License-Identifier: GPL-2.0 */
> +#include <asm/asi.h>
> #include <asm/thread_info.h>
> #include <asm/trap_block.h>
> #include <asm/spitfire.h>
> @@ -32,6 +33,20 @@ user_rtt_fill_fixup_common:
> sethi %hi(KERNBASE), %g1
> flush %g1
>
> + /* rtrap set %asi to ASI_AIUP for the window fill, and
> + * we re-enter the kernel here without passing through
> + * etrap, which would have re-established ASI_AIUS via
> + * the TSTATE it synthesizes. The primary context was
> + * just restored to the kernel's above,

Perhaps begin with the "Restore the kernel invariant" wording up here
and then continue with why it needs to be done (no strong opinion here).

> so a leftover
> + * ASI_AIUP makes every %asi-based user access (put_user,
> + * get_user) translate in the kernel context

The comment in the code itself should be from the point of view of why
the %asi update is being done, rather than having language as if the bug
was still in place. It could be as simple as "...so restore the kernel
invariant, as a leftover ASI_AIUP would make every..." or something like
that. I'll leave the exact language to you.

> : user
> + * addresses below the VA hole then fault forever
> + * (nothing ever fills a context-zero translation for
> + * them), and addresses above it silently alias the
> + * kernel linear mapping.

I think it is enough that these details are in the commit message. These
are details about the bug that now is no more. The short version on why
%asi needs to be set to ASI_AIUP is enough in the code.

> Restore the kernel invariant.
> + */
> + wr %g0, ASI_AIUS, %asi
> +
> mov %g4, %l4
> mov %g5, %l5
> brnz,pn %g3, 1f

Other than that, the series looks good to me.

Thanks,
Andreas