From nobody Sun Mar 15 06:58:01 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4fYTZK6wjQz6VFns for ; Sun, 15 Mar 2026 06:58:01 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4fYTZK6Flmz3D7C for ; Sun, 15 Mar 2026 06:58:01 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1773557881; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=1TyCpOZEe32vKJZT0uqI9xAVpiK4ZOGjiITJUC6VXRc=; b=INbHLivuU+d+NlWOfGYeaii1+Z+hAAF1vcYqjh8kyyuqGlHiNPyUAI0sbT4Ri3sibDrH+X cl2AODsCdgEcyrEFi7cLohGO47UBw8tSi2gbIPCF/V8jTtV6JjhhwL/ymBkwXCXMzHHJ38 63nuM4s0kvTevGxvw2qQHRIxOccvNoC1l1u+58xEtQ/ycbum/l1tic2bwO8MwNAU/YbLQe C0b79UGzF45IknQ/LaT/efAs8wO5DPPAscCiMhfUOFDcJx3w757kGvnKHe6x8R1BVOqZNP N5QKr1CrqmYVPe9kFqnb2V822FLoAhjeKs7AXVqfJSxyuu2ndyE210XTcj9dTg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1773557881; a=rsa-sha256; cv=none; b=AbFgZUNuDa1+J9fq9W6wVrdHPYkUHXsdXYJqzHki0pWxHgzJarO6bxIoIhOPgC1KIzPmus 88XitxFNqValMB5NCyQ0/CPslYwTClQ0eqJSEdlrgWLqRxKRDYORDS+FbISHVTKdS6oZZI w6ooVJ3a7X0fKNcbi126Bq1XfMYf9/FY1Z+lfPj7jSbzEgJJ7I3IbsmrTg5LZ/5HIetaH9 CSRkRZbL9c4hdNR2mnAJXyBQoI0mG+fsZLolC/GT8f9gm28jvG0GSUYysLZ1GMeQLIX5sn IMesLPZ8b7O0uM5xZelcKptamyIzniCa1ykScayjyUxfasC1572zRgHeRkaM9A== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1773557881; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=1TyCpOZEe32vKJZT0uqI9xAVpiK4ZOGjiITJUC6VXRc=; b=mZlStkbc3kuBBM0QEyx9cpUh4x2CamANWvA4XY1iOWLHZVJ2j3f1Xn9vdSociUF9HVpa9y Hgz/tsYKbl4fNiMwpNHCsS2zrl/kB96IpVYqxE5VgBHRaojlUxbTNy71n7fHRvnr6kubrX 7+in4I8oiQxnIdctIwHXohT90eRwfvqMB8n9ulLf0tjLv27ItmuJlEHoUMPNwaQE2LnxvW 1NWopjnW3ReEdZTErKL2G2z6FnNVOvX/5GEOvxuIPcPkKb4ax9W7Gd5aceLZbPoGVhew1x y95gxLTvzWRHF+YGdI34JcSw3kUJlDzxvLkmkVjm2DHMTtqiZ98YIZwo9bJexg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4fYTZK5LvJzdRb for ; Sun, 15 Mar 2026 06:58:01 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 27fa1 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sun, 15 Mar 2026 06:58:01 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Konstantin Belousov Subject: git: 8365f877b1e4 - main - amd64: do reset %rip after page fault if pcb_onfault is set List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kib X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 8365f877b1e4b6d4c30df72e0826ca60a412ce7d Auto-Submitted: auto-generated Date: Sun, 15 Mar 2026 06:58:01 +0000 Message-Id: <69b65879.27fa1.4fc60671@gitrepo.freebsd.org> The branch main has been updated by kib: URL: https://cgit.FreeBSD.org/src/commit/?id=8365f877b1e4b6d4c30df72e0826ca60a412ce7d commit 8365f877b1e4b6d4c30df72e0826ca60a412ce7d Author: Konstantin Belousov AuthorDate: 2026-03-14 11:40:07 +0000 Commit: Konstantin Belousov CommitDate: 2026-03-15 06:57:08 +0000 amd64: do reset %rip after page fault if pcb_onfault is set for any kernel page fault, and not only for EFIRT case. Reported and tested by: pho Fixes: 914a53570750ce5a104a5870403d7669656fddc3 Sponsored by: The FreeBSD Foundation MFC after: 1 week --- sys/amd64/amd64/trap.c | 33 ++++++++++++++++++++------------- 1 file changed, 20 insertions(+), 13 deletions(-) diff --git a/sys/amd64/amd64/trap.c b/sys/amd64/amd64/trap.c index 4bf56226d076..3a9323936d2d 100644 --- a/sys/amd64/amd64/trap.c +++ b/sys/amd64/amd64/trap.c @@ -219,15 +219,19 @@ trap_uprintf_signal(struct thread *td, struct trapframe *frame, register_t addr, } static bool -trap_check_efirt(struct thread *td, struct trapframe *frame) +trap_check_pcb_onfault(struct thread *td, struct trapframe *frame) { - /* - * Most likely, EFI RT faulted. This check prevents - * kdb from handling breakpoints set on the BIOS text, - * if such option is ever needed. - */ - if ((td->td_pflags & TDP_EFIRT) != 0 && - curpcb->pcb_onfault != NULL) { + bool res = false; + + if (curpcb->pcb_onfault == NULL) + return (res); + + if (__predict_false((td->td_pflags & TDP_EFIRT) != 0)) { + /* + * Most likely, EFI RT faulted. This check prevents + * kdb from handling breakpoints set on the BIOS text, + * if such option is ever needed. + */ u_long cnt = atomic_fetchadd_long(&cnt_efirt_faults, 1); if ((print_efirt_faults == 1 && cnt == 0) || @@ -236,10 +240,13 @@ trap_check_efirt(struct thread *td, struct trapframe *frame) traptype_to_msg(frame->tf_trapno)); trap_diag(frame, 0); } - frame->tf_rip = (long)curpcb->pcb_onfault; - return (true); + res = true; + } else if (frame->tf_trapno == T_PAGEFLT) { + res = true; } - return (false); + if (res) + frame->tf_rip = (register_t)curpcb->pcb_onfault; + return (res); } static void @@ -494,7 +501,7 @@ trap(struct trapframe *frame) KASSERT(cold || td->td_ucred != NULL, ("kernel trap doesn't have ucred")); - if (type != T_PAGEFLT && trap_check_efirt(td, frame)) + if (type != T_PAGEFLT && trap_check_pcb_onfault(td, frame)) return; switch (type) { @@ -904,7 +911,7 @@ trap_pfault(struct trapframe *frame, bool usermode, int *signo, int *ucode) return (1); after_vmfault: if (td->td_intr_nesting_level == 0 && - trap_check_efirt(td, frame)) + trap_check_pcb_onfault(td, frame)) return (0); trap_fatal(frame, eva); return (-1);