From nobody Fri Sep 04 05:22:47 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hblGh4gS3z6r4Xd for ; Fri, 04 Sep 2026 05:22:52 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hblGh3rNJz3LSc for ; Fri, 04 Sep 2026 05:22:52 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788499372; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=iOpTtXi7+G4SG35naSS+iNjmPD4qEKh5u3Qlqv+sE0I=; b=wu9Be7T2wCEWZg+RsARUWMRUur5Tn6SSCBkpTa2+Ys9yOFXcQahJD+wPM2bB8s2YBow8aO liM9H49A5Mx23pDhVoMqAUmUciWCd6Lftz+nCEvYerFbmlK+a2zesKWeLpE7PopqaFahNa qHmHfoFNZ7NWTf4t0cTmMUpxVMkWM62kN3rlz+JzsV8u5BTiqPdBYTKrdWl3Vx7udmg9hr kugU+avnrEIJNlV4Les0Ok+AvxOthFAz/urSiIMEBAPLwjx3yTtHtBKvKvs3g8SH55t/8w NB5PHKAqqLozzKWUgcY4+LyP6Lz203iW+Cf3EAq4v1RE4/z30JVUQmJdcEtXwA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1788499372; a=rsa-sha256; cv=none; b=UmoSg+SwUvUlRhCnJFyuFivATl/RXqOim9KQB0fQ5PlDFFG0cyOZhx8+TjhTcfUMINMSvN UsIaAgPmf0BIkXt2zoHmixaOSLZ//iTajf1UNfZ7cyRImu+b3MMI3cvDA/smq93qXIF0qo tqQVUTvTUT9cTFH0qMVqN0reF+wUC8yfgOpYpYJfGCIyNG+BpPQk6TbWr6PinQKuNGFlc6 I3UBd2/reDvGy9aQF/Jpr4ZuAhDZAL9k3ZRjSgLjw4sm2EDLtgAo493vZUCZvhgOdVkKO+ oiOH+del5kYQrA0ePTVKPhc/kROxuQzu+R/BB0zJ1B+4exO53tw2O25+QI0T6Q== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788499372; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=iOpTtXi7+G4SG35naSS+iNjmPD4qEKh5u3Qlqv+sE0I=; b=Z7tNm7LKt4tEbfvY274cyFI1NuS3ffF4TbRS7iJf1GQsG2YHvCHFWtSMv6t+htFOcHWql9 ztmyYff2PNR4KycvL7KFzNjcEVwBPZYnOImgR2rxXPdfnz2Wpe7RBrh6eD6hsO/gypTYnQ YZ5ah8mL3mgZ6q5+R3FxX/9WqFVmo0Ih44s6c537T4TxIrvxdcZfRzuFC0/dofcfKUnhob 3HAGJMzyHpdYCEhlRCNDMVx38JZTfFplZOJIQso45Qo1mY/4XXVTwOlC8RmpbbClQn+HtJ 17ZBxPOggOct1fx81r1buZX0Q5lbOnm5XrmaQwggurHg2zwxF9ZEDgVXwmEP1g== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hblGh2TvKzlsg for ; Fri, 04 Sep 2026 05:22:52 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 1c15e by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Fri, 04 Sep 2026 05:22:47 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Alan Cox Subject: git: 57407179be43 - main - arm64 pmap: correct the condition for flushing the icache List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: alc X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 57407179be431dbe567de083aab5ce152163f4d3 Auto-Submitted: auto-generated Date: Fri, 04 Sep 2026 05:22:47 +0000 Message-Id: <6a9a55a7.1c15e.644e7104@gitrepo.freebsd.org> The branch main has been updated by alc: URL: https://cgit.FreeBSD.org/src/commit/?id=57407179be431dbe567de083aab5ce152163f4d3 commit 57407179be431dbe567de083aab5ce152163f4d3 Author: Alan Cox AuthorDate: 2026-08-29 07:08:01 +0000 Commit: Alan Cox CommitDate: 2026-09-04 05:19:13 +0000 arm64 pmap: correct the condition for flushing the icache Whenever we create a user-space mapping, we always set ATTR_S1_PXN in the PTE, which blocks execution of user-space code while running in kernel mode. However, when seeking to determine whether we need to perform an icache flush before installing the new PTE, we test whether sometimes the old PTE or other times the new PTE has ATTR_S1_XN set. The trouble is that ATTR_S1_XN is defined as the bitwise OR of ATTR_S1_PXN and ATTR_S1_UXN, and so the test for whether ATTR_S1_XN is set is satisfied if either of its constituent bits is set, i.e., we write (l3e & ATTR_S1_XN) != 0. Consequently, the test is always true. In practice, I believe that the ill effects of this bug are limited: In pmap_enter(), in rare circumstances, e.g., wiring a code page, an unnecessary icache flush will be performed. In pmap_enter_l2() and pmap_enter_l3c(), no icache flush will be performed. However, typically an icache flush would have already been performed on each of the constituent base pages. Reviewed by: kib, markj MFC after: 3 weeks Differential Revision: https://reviews.freebsd.org/D59265 --- sys/arm64/arm64/pmap.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/sys/arm64/arm64/pmap.c b/sys/arm64/arm64/pmap.c index 8f68be2fb272..a584812df0bb 100644 --- a/sys/arm64/arm64/pmap.c +++ b/sys/arm64/arm64/pmap.c @@ -5929,7 +5929,7 @@ validate: */ if ((prot & VM_PROT_EXECUTE) && pmap != kernel_pmap && m->md.pv_memattr == VM_MEMATTR_WRITE_BACK && - (opa != pa || (orig_l3 & ATTR_S1_XN))) { + (opa != pa || (orig_l3 & ATTR_S1_UXN) != 0)) { PMAP_ASSERT_STAGE1(pmap); cpu_icache_sync_range(PHYS_TO_DMAP(pa), PAGE_SIZE); } @@ -6242,8 +6242,8 @@ pmap_enter_l2(pmap_t pmap, vm_offset_t va, pd_entry_t new_l2, u_int flags, /* * Conditionally sync the icache. See pmap_enter() for details. */ - if ((new_l2 & ATTR_S1_XN) == 0 && (PTE_TO_PHYS(new_l2) != - PTE_TO_PHYS(old_l2) || (old_l2 & ATTR_S1_XN) != 0) && + if ((new_l2 & ATTR_S1_UXN) == 0 && (PTE_TO_PHYS(new_l2) != + PTE_TO_PHYS(old_l2) || (old_l2 & ATTR_S1_UXN) != 0) && pmap != kernel_pmap && m->md.pv_memattr == VM_MEMATTR_WRITE_BACK) { cpu_icache_sync_range(PHYS_TO_DMAP(PTE_TO_PHYS(new_l2)), L2_SIZE); @@ -6470,7 +6470,7 @@ have_l3p: /* * Sync the icache before the mapping is stored. */ - if ((l3e & ATTR_S1_XN) == 0 && pmap != kernel_pmap && + if ((l3e & ATTR_S1_UXN) == 0 && pmap != kernel_pmap && m->md.pv_memattr == VM_MEMATTR_WRITE_BACK) cpu_icache_sync_range(PHYS_TO_DMAP(pa), L3C_SIZE);