From nobody Fri Sep 04 05:22:47 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hblGb2zjcz6r4GC for ; Fri, 04 Sep 2026 05:22:47 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hblGb2Nmlz3LWP for ; Fri, 04 Sep 2026 05:22:47 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788499367; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=iOpTtXi7+G4SG35naSS+iNjmPD4qEKh5u3Qlqv+sE0I=; b=Hc3TGeVeWugrs3tIZ+KPBuCByv3ru5m2IuVEz50X8XOwVyIhH4jp9RDvV7q8UvD0OjHp7o B2osuqJAkwDVqKQo4H+Ub71ORg8/a5va+n9+PFEKFtOWWy5bcvKzDkpNcHGVH3qQbSyrQW NuZALM/V+8FDHgKsqi1Vhj24MYCW7yr5Yip+CdlBN/DQdytPK6QYfZ3UvNq0Hdlsay9bpa zxenRPkYIPf2S39/tjH3PgAVxHHp4C+7NiigPmh9nxs2zqle/sRGto6FCu45zqdRERMpRw 94DmfXqfbbJf+AquqxMkIdNfp3y+FWOEyVd4ClWUMv0AkEhgVWJFd5JujeQAFg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1788499367; a=rsa-sha256; cv=none; b=YWO5A+FRcz5PRv142M45rs02vzzGvfz+A6RTu68oe+yqiRZRJQoGz5vJDkgWK/v6WdEegt fCM/ZPkrHPIHN6TuSraqXETTA8D4PRvCcYuhHwvHKF5w7BG6Vu6A9tikTogKypRWRVAZNv EsHJmvp8IhohF7bX5+momytFI19mx854263toO/LwfyH2WbOiy/M2JJZQoCkCcFM+K5U0A ISLKl6ZXnYItjfjqd9P54XUqe++QMKMuF8rMyjuP4n3P9m5sba8vrOy612VyjQHW5tnb+V l9TrESqXyPIytKmUe4SJgWa6s11HB8dAyrDL6ui2UYKo6wcFD3KdANQThKMC4A== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788499367; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=iOpTtXi7+G4SG35naSS+iNjmPD4qEKh5u3Qlqv+sE0I=; b=gfvqjvN4qXCCi6VwHbiecg+YPpEqXUt8WtnHZggOQ/4JpDSpK4tjXvwXEdD6sL/QanTNVM YOErjn3EUpIl76wweFZJzXo++W3IdNNgNQvezcuE2VltNhuYpf9ZnluNRE3NxUclmqpomK clkGfE9yYw12Q/YB4hjbunXwg9N3vZsu8XUXhpGJalv8doqdrvrqvy46Eyzzv/leJCikKS g2jVPuBxH3HERqlE+jHcvoJqCSPwHfIsQx6YU3ZU3xWvNRSaHFTGo5CIHr2v5sXSgRgXe0 bymKIgZZSCKCUBBPvQPbRAb8gI2YbBWq1X/qZZx0dwrjM89Xc8jK7PlA+UG0VQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hblGb17Z8zmYM for ; Fri, 04 Sep 2026 05:22:47 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 1c15e by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Fri, 04 Sep 2026 05:22:47 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Alan Cox Subject: git: 57407179be43 - main - arm64 pmap: correct the condition for flushing the icache List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: alc X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 57407179be431dbe567de083aab5ce152163f4d3 Auto-Submitted: auto-generated Date: Fri, 04 Sep 2026 05:22:47 +0000 Message-Id: <6a9a55a7.1c15e.644e7104@gitrepo.freebsd.org> The branch main has been updated by alc: URL: https://cgit.FreeBSD.org/src/commit/?id=57407179be431dbe567de083aab5ce152163f4d3 commit 57407179be431dbe567de083aab5ce152163f4d3 Author: Alan Cox AuthorDate: 2026-08-29 07:08:01 +0000 Commit: Alan Cox CommitDate: 2026-09-04 05:19:13 +0000 arm64 pmap: correct the condition for flushing the icache Whenever we create a user-space mapping, we always set ATTR_S1_PXN in the PTE, which blocks execution of user-space code while running in kernel mode. However, when seeking to determine whether we need to perform an icache flush before installing the new PTE, we test whether sometimes the old PTE or other times the new PTE has ATTR_S1_XN set. The trouble is that ATTR_S1_XN is defined as the bitwise OR of ATTR_S1_PXN and ATTR_S1_UXN, and so the test for whether ATTR_S1_XN is set is satisfied if either of its constituent bits is set, i.e., we write (l3e & ATTR_S1_XN) != 0. Consequently, the test is always true. In practice, I believe that the ill effects of this bug are limited: In pmap_enter(), in rare circumstances, e.g., wiring a code page, an unnecessary icache flush will be performed. In pmap_enter_l2() and pmap_enter_l3c(), no icache flush will be performed. However, typically an icache flush would have already been performed on each of the constituent base pages. Reviewed by: kib, markj MFC after: 3 weeks Differential Revision: https://reviews.freebsd.org/D59265 --- sys/arm64/arm64/pmap.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/sys/arm64/arm64/pmap.c b/sys/arm64/arm64/pmap.c index 8f68be2fb272..a584812df0bb 100644 --- a/sys/arm64/arm64/pmap.c +++ b/sys/arm64/arm64/pmap.c @@ -5929,7 +5929,7 @@ validate: */ if ((prot & VM_PROT_EXECUTE) && pmap != kernel_pmap && m->md.pv_memattr == VM_MEMATTR_WRITE_BACK && - (opa != pa || (orig_l3 & ATTR_S1_XN))) { + (opa != pa || (orig_l3 & ATTR_S1_UXN) != 0)) { PMAP_ASSERT_STAGE1(pmap); cpu_icache_sync_range(PHYS_TO_DMAP(pa), PAGE_SIZE); } @@ -6242,8 +6242,8 @@ pmap_enter_l2(pmap_t pmap, vm_offset_t va, pd_entry_t new_l2, u_int flags, /* * Conditionally sync the icache. See pmap_enter() for details. */ - if ((new_l2 & ATTR_S1_XN) == 0 && (PTE_TO_PHYS(new_l2) != - PTE_TO_PHYS(old_l2) || (old_l2 & ATTR_S1_XN) != 0) && + if ((new_l2 & ATTR_S1_UXN) == 0 && (PTE_TO_PHYS(new_l2) != + PTE_TO_PHYS(old_l2) || (old_l2 & ATTR_S1_UXN) != 0) && pmap != kernel_pmap && m->md.pv_memattr == VM_MEMATTR_WRITE_BACK) { cpu_icache_sync_range(PHYS_TO_DMAP(PTE_TO_PHYS(new_l2)), L2_SIZE); @@ -6470,7 +6470,7 @@ have_l3p: /* * Sync the icache before the mapping is stored. */ - if ((l3e & ATTR_S1_XN) == 0 && pmap != kernel_pmap && + if ((l3e & ATTR_S1_UXN) == 0 && pmap != kernel_pmap && m->md.pv_memattr == VM_MEMATTR_WRITE_BACK) cpu_icache_sync_range(PHYS_TO_DMAP(pa), L3C_SIZE);