From nobody Sat Sep 05 04:15:16 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hcKkD6wKjz6qs8r for ; Sat, 05 Sep 2026 04:15:16 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hcKkD3Gsvz3bZv for ; Sat, 05 Sep 2026 04:15:16 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788581716; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=WpirosOIEPqKSopVjxKf2yRi//d1fQUxcHTrHsfh164=; b=NOyLmyur5PRa2+aARlFPmyyVztCxqXZJJ1ZaLxqY5tkAlv969JQIsPAhzODLMhXKrB4Fjb J3dY4LfPlpUwslK2RFgoIVAaWFoYI9UVkU8Px0D0kRq9YN/Ga0ylOfFBcd8u4HpfXHZQge wq1ha3jEy5uWRsGWgW5XAqokC8jI52wFV2wS/PrGDtITMbFJihzg0ckit7z25jWR9Ta3C0 Nt4Vy7HLV1+Kmp4uwgIQUzhOdvFINI3gd+CYMxooNoOJ5YTzG5UVhlHqx5+nG7E74iWBNo bORoQhzI6tRBIR6ZgBKpD5F72dwC8hpFZf/Ni3zGUjwR+Uachld32o4VnJnaSQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1788581716; a=rsa-sha256; cv=none; b=NqL7nlCUCLGrNXGph6JvDGn5HOvFv4VTlMOlVzemiIPCl41FYjQjTXtB4eWj2pQwi5ftvo Gja6u/fUMfCsO3ETB57vGvIIUzBBYYCI0PYROKhlt0vVUx461d7pfQYgRFMImteG3BvJwz 4LFRiy/EiHFei6ryrY0+swMUM1WtZe6lMh26Ob+osD2owx95AgJlwSWQ3Ckc9dr1cMHmLT p03Z1j78us04DtJygmIe+VXI+5xa/NqD4BissfgBGi8Dtw++QI/jqoEIeAOKIelw9LoiNi OmTgChe8Z9zPWGtA5K2U0ZBAbWVvRfBtgf18AcB/fQbX69Zm4Unu73sghHLUDg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788581716; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=WpirosOIEPqKSopVjxKf2yRi//d1fQUxcHTrHsfh164=; b=dcc/uyIIJ7J1DSNnLFXKhx2gXksbvsbccK02hiTI/1h/jBcrlxamsGwFglXQpMQ0zR228v gNxDXbnwWcC1yocJhGYopgOTucT7HORZMlKLiPrG0d5Gz1mgzD/tpu2/P1jv3UCtg/8AqV FlR6+H4kUHZB4As8Y+QmPQeiHSMbvhKJQ0QlKeHf7WrRJdAXQ5XfEVYSEnUFMvFeU+sAr4 ylzBnOEdgFWo+u2Pq6xnp3wZIaEQY0Es0Q2VZKbemMy29jhbdOzNDXB6RF8Uuu2F14H1VX SWvRi6RaIY/xoD8ktMKXJxtEzDkcjx9NoIAv0tRocdQaTJ1f1ICyKUDo5CbZoA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hcKkD1rTPzW0p for ; Sat, 05 Sep 2026 04:15:16 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3e6af by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sat, 05 Sep 2026 04:15:16 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Justin Hibbits Subject: git: 68ecb918a531 - main - powerpc/booke: Reorganize FRAME_LEAVE List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: jhibbits X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 68ecb918a5313150be660322c6686ae6292b4aac Auto-Submitted: auto-generated Date: Sat, 05 Sep 2026 04:15:16 +0000 Message-Id: <6a9b9754.3e6af.492fe936@gitrepo.freebsd.org> The branch main has been updated by jhibbits: URL: https://cgit.FreeBSD.org/src/commit/?id=68ecb918a5313150be660322c6686ae6292b4aac commit 68ecb918a5313150be660322c6686ae6292b4aac Author: Justin Hibbits AuthorDate: 2026-09-04 03:40:12 +0000 Commit: Justin Hibbits CommitDate: 2026-09-05 04:09:45 +0000 powerpc/booke: Reorganize FRAME_LEAVE There's a small window between when the SRR* registers are restore and the exception returns, in which a TLB miss exception may be triggered. Since there are not special SRR* registers for TLB miss exceptions, the registers from the frame will be ovwritten, and the FRAME_LEAVE block will effectively be re-entered on exit, leading to a very hard to diagnose panic or wedge. Minimize this chance by pushing the SRR* restore to the last possible moments, caching them in a PCPU save area instead until the end. This matches what the AIM side already does. --- sys/powerpc/booke/trap_subr.S | 42 +++++++++++++++++++++++++++++++----------- 1 file changed, 31 insertions(+), 11 deletions(-) diff --git a/sys/powerpc/booke/trap_subr.S b/sys/powerpc/booke/trap_subr.S index 10babefbb2f8..55e4d03639d4 100644 --- a/sys/powerpc/booke/trap_subr.S +++ b/sys/powerpc/booke/trap_subr.S @@ -314,13 +314,23 @@ /* * + * sprg_sp - SPRG{1-3} reg free to use as a scratch once r1 is restored + * savearea - temp save area (pc_{tempsave, critsave, mchksave, dbsave}) * isrr0-1 - save restore registers to restore CPU state to (may be * SRR0-1, CSRR0-1, MCSRR0-1 * * Notes: * - potential TLB miss: YES. The deref'd kstack may be not covered + * + * - xSRR0-1 are staged in the savearea rather than written to the SPRs up + * front. A DTLB miss on the kstack below is not maskable by wrteei, and + * the hardware overwrites SRR0-1 on entry to the miss handler, which then + * restores its own values -- so anything parked in SRR0-1 across the + * register reload is lost, and the rfi returns into the middle of this + * macro instead of to the interrupted context. Everything after the last + * kstack access touches only pcpu and SPRs, which cannot fault. */ -#define FRAME_LEAVE(isrr0, isrr1) \ +#define FRAME_LEAVE(sprg_sp, savearea, isrr0, isrr1) \ wrteei 0; \ /* restore CTR, XER, LR, CR */ \ LOAD %r4, FRAME_CTR+CALLSIZE(%r1); \ @@ -334,16 +344,26 @@ /* restore DBCR0 */ \ LOAD %r4, FRAME_BOOKE_DBCR0+CALLSIZE(%r1); \ mtspr SPR_DBCR0, %r4; \ - /* restore xSRR0-1 */ \ + /* stage xSRR0-1 where a TLB miss cannot reach them */ \ LOAD %r30, FRAME_SRR0+CALLSIZE(%r1); \ LOAD %r31, FRAME_SRR1+CALLSIZE(%r1); \ - mtspr isrr0, %r30; \ - mtspr isrr1, %r31; \ + GET_CPUINFO(%r4); \ + STORE %r30, (savearea+CPUSAVE_SRR0)(%r4); \ + STORE %r31, (savearea+CPUSAVE_SRR1)(%r4); \ /* restore R2-31, SP */ \ LD_REGS(%r1); \ LOAD %r2, FRAME_2+CALLSIZE(%r1); \ LOAD %r0, FRAME_0+CALLSIZE(%r1); \ LOAD %r1, FRAME_1+CALLSIZE(%r1); \ + /* no kstack references past here; park r3 to free a scratch */ \ + mtspr sprg_sp, %r3; \ + GET_CPUINFO(%r3); \ + LOAD %r3, (savearea+CPUSAVE_SRR0)(%r3); \ + mtspr isrr0, %r3; \ + GET_CPUINFO(%r3); \ + LOAD %r3, (savearea+CPUSAVE_SRR1)(%r3); \ + mtspr isrr1, %r3; \ + mfspr %r3, sprg_sp; \ isync /* @@ -541,7 +561,7 @@ INTERRUPT(int_critical_input) bl CNAME(powerpc_interrupt) TOC_RESTORE CRIT_SRR_RESTORE - FRAME_LEAVE(SPR_CSRR0, SPR_CSRR1) + FRAME_LEAVE(SPR_SPRG2, PC_BOOKE_CRITSAVE, SPR_CSRR0, SPR_CSRR1) rfci @@ -555,7 +575,7 @@ INTERRUPT(int_machine_check) addi %r3, %r1, CALLSIZE bl CNAME(powerpc_interrupt) TOC_RESTORE - FRAME_LEAVE(SPR_MCSRR0, SPR_MCSRR1) + FRAME_LEAVE(SPR_SPRG3, PC_BOOKE_MCHKSAVE, SPR_MCSRR0, SPR_MCSRR1) rfmci @@ -642,7 +662,7 @@ INTERRUPT(int_watchdog) bl CNAME(powerpc_interrupt) TOC_RESTORE CRIT_SRR_RESTORE - FRAME_LEAVE(SPR_CSRR0, SPR_CSRR1) + FRAME_LEAVE(SPR_SPRG2, PC_BOOKE_CRITSAVE, SPR_CSRR0, SPR_CSRR1) rfci @@ -964,14 +984,14 @@ INTERRUPT(int_debug) STANDARD_CRIT_PROLOG(SPR_SPRG2, PC_BOOKE_CRITSAVE, SPR_CSRR0, SPR_CSRR1) FRAME_SETUP(SPR_SPRG2, PC_BOOKE_CRITSAVE, EXC_DEBUG) bl int_debug_int - FRAME_LEAVE(SPR_CSRR0, SPR_CSRR1) + FRAME_LEAVE(SPR_SPRG2, PC_BOOKE_CRITSAVE, SPR_CSRR0, SPR_CSRR1) rfci INTERRUPT(int_debug_ed) STANDARD_CRIT_PROLOG(SPR_SPRG2, PC_BOOKE_CRITSAVE, SPR_DSRR0, SPR_DSRR1) FRAME_SETUP(SPR_SPRG2, PC_BOOKE_CRITSAVE, EXC_DEBUG) bl int_debug_int - FRAME_LEAVE(SPR_DSRR0, SPR_DSRR1) + FRAME_LEAVE(SPR_SPRG2, PC_BOOKE_CRITSAVE, SPR_DSRR0, SPR_DSRR1) rfdi /* .long 0x4c00004e */ @@ -1043,7 +1063,7 @@ CNAME(trapexit): CNAME(asttrapexit): b trapexit /* test ast ret value ? */ 1: - FRAME_LEAVE(SPR_SRR0, SPR_SRR1) + FRAME_LEAVE(SPR_SPRG1, PC_TEMPSAVE, SPR_SRR0, SPR_SRR1) rfi @@ -1097,7 +1117,7 @@ dbtrap: b trap_common dbleave: - FRAME_LEAVE(SPR_SRR0, SPR_SRR1) + FRAME_LEAVE(SPR_SPRG1, PC_DBSAVE, SPR_SRR0, SPR_SRR1) rfi ASEND(breakpoint) #endif /* KDB */