From nobody Sat Sep 05 04:15:17 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hcKkF6fm8z6qs6d for ; Sat, 05 Sep 2026 04:15:17 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hcKkF4BDMz3bSV for ; Sat, 05 Sep 2026 04:15:17 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788581717; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=fSTvxY1iRooeMZd3baghIzz3bJgpX+SjVwQVjctoNeA=; b=Vh3VTJxdavcmPh/+QDnFBEIdz4QLDo6aZjBhTTWK6I1/qgtgUKEqpQEcUdrWecKKJw6TiZ L4/AYw4WlnbYPZr2awmlNseiUrozot/5KajTTY7VLZPaENMu+zfB7Lc6IlsWhAy/EcUbor IQT+MeKSSvB3LVnSHGQw5o3HPQaeGlC14+wwrwsNsCtP7tH9sgGSSExfjKwJUFQTbfY4OM BNV5sYISqwSijQZItNi7iIBS0B7DhUYEe4DWi/xMFMIsI56QRXWXIgBKiZMfEXyAPBpXyb WsGRPGeCeRwzLN4mVwxEAqUHl5Tn9Yr3oIqOvCXkWXCpG5awXVtnJhwVL5wjtw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1788581717; a=rsa-sha256; cv=none; b=wjLu1cFW5nZxqG7dGPG7AmjzVwdcWykNye2DoRZvkR9LjhNh0fMlW95IjM4A34PB5zh8Rj 1DDIPi/qznUwqN3OruDrYMNrw/XuwrQuJWfLjuu7P2NjVYigxCt4gRkLESPv45CrMC3hNP xuIxZ3++OY8epSGTBeXtbeotQIcqKMFFOFFC9OrRrl1cjyHd39x+2dTYWQevY9BmHHHy8/ o0TvhA9nHwWyA4Uy3UpisdDTNg97K8YdI2D3/CAr1R9m0CjPI3T6knbBKPd2aylpIekJF7 Fb56UKHvhACkkwJGvC0CSTuqZKqPY5R5gSIkaIunr0SBFIngsW805dp4LU/t4g== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788581717; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=fSTvxY1iRooeMZd3baghIzz3bJgpX+SjVwQVjctoNeA=; b=Oqi0pvdcmTwZQ8Y0MhbgHBB4t+5sYMiVZa3DzsYOEYbqjkGzGQyVGMvoHC9l22H9nlIpXh Q9tERXiy52uVcglp/w+AV8p0elSNlMqYYJmbR5LZn6vDeizx0XM1QX8b06awMQYBgfvZom DZJ1+E7bdmKFtw/lzc3qHN7neOD1NBOp6wKcwrXCyjZav8S8PewfxK8KCyER/nulHYOm5k p1O3gSwS5ubkfQwLwDBimhtahvI8zly1l4lTj2CM+DpNdH+DUwWXQVZgSVg6xYSAQiITR/ zGCbAmjsovCMt1Fw8X7SFXD3aZk2Vfzak5+PtVP+Pga7ygE8cByQFFEbFZYP3g== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hcKkF2dCNzVLJ for ; Sat, 05 Sep 2026 04:15:17 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3c8fe by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sat, 05 Sep 2026 04:15:17 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Justin Hibbits Subject: git: eef260752633 - main - powerpc/pmap(booke): Rework TID reuse List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: jhibbits X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: eef260752633fca72be1d03d58472f4890e00e1e Auto-Submitted: auto-generated Date: Sat, 05 Sep 2026 04:15:17 +0000 Message-Id: <6a9b9755.3c8fe.1a782726@gitrepo.freebsd.org> The branch main has been updated by jhibbits: URL: https://cgit.FreeBSD.org/src/commit/?id=eef260752633fca72be1d03d58472f4890e00e1e commit eef260752633fca72be1d03d58472f4890e00e1e Author: Justin Hibbits AuthorDate: 2026-09-05 04:11:34 +0000 Commit: Justin Hibbits CommitDate: 2026-09-05 04:11:34 +0000 powerpc/pmap(booke): Rework TID reuse If a pmap is freed and its memory is reused before its TID reference is taken, then arbitrary memory will be clobbered. Avoid this by never dereferencing the pmap pointer in the tidbusy array, and instead using it as a compare sentinel. --- sys/powerpc/booke/pmap.c | 28 ++++++++++++++++------------ 1 file changed, 16 insertions(+), 12 deletions(-) diff --git a/sys/powerpc/booke/pmap.c b/sys/powerpc/booke/pmap.c index ce16566a6f13..2872da55f1f2 100644 --- a/sys/powerpc/booke/pmap.c +++ b/sys/powerpc/booke/pmap.c @@ -207,6 +207,7 @@ extern int elf32_nxstack; /* Translation ID busy table (dynamically allocated) */ static __inline void tid_set_busy(int cpu, int tid, pmap_t pmap); +static __inline pmap_t tid_get_busy(int cpu, int tid); static volatile pmap_t *tidbusy; uint32_t tid_max; @@ -1649,7 +1650,12 @@ mmu_booke_activate(struct thread *td) CPU_SET_ATOMIC(cpuid, &pmap->pm_active); PCPU_SET(curpmap, pmap); - if (pmap->pm_tid[cpuid] == TID_NONE) + /* + * pm_tid is only a hint: another pmap may have stolen the TID since we + * last ran here, in which case tidbusy[] no longer names us. + */ + if (pmap->pm_tid[cpuid] == TID_NONE || + tid_get_busy(cpuid, pmap->pm_tid[cpuid]) != pmap) tid_alloc(pmap); /* Load PID0 register with pmap tid value. */ @@ -2493,17 +2499,15 @@ mmu_booke_page_array_startup(long pages) /* TID handling */ /**************************************************************************/ +/* + * tidbusy[] is the authoritative record of TID ownership; pm_tid is only a + * hint, validated against it by mmu_booke_activate(). Only the pointer + * matters, it's never dereferenced. + */ static __inline void tid_set_busy(int cpu, int tid, pmap_t pmap) { - volatile pmap_t *pm = &tidbusy[cpu * (tid_max + 1) + tid]; - - if (pmap == NULL) { - if (*pm != NULL) - (*pm)->pm_tid[cpu] = TID_NONE; - } else - pmap->pm_tid[cpu] = tid; - *pm = pmap; + tidbusy[cpu * (tid_max + 1) + tid] = pmap; } static __inline pmap_t @@ -2534,12 +2538,12 @@ tid_alloc(pmap_t pmap) tid = TID_MIN; PCPU_SET(booke.tid_next, tid + 1); - /* If we are stealing TID then clear the relevant pmap's field */ + /* + * If we are stealing the TID, drop the previous owner's translations. + */ if (tid_get_busy(thiscpu, tid) != NULL) { CTR2(KTR_PMAP, "%s: warning: stealing tid %d", __func__, tid); - tid_set_busy(thiscpu, tid, NULL); - /* Flush all entries from TLB0 matching this TID. */ tid_flush(tid); }