From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
To: Peter Zijlstra <peterz@infradead.org>
Cc: Steven Rostedt <rostedt@goodmis.org>,
Ingo Molnar <mingo@kernel.org>,
Sean Christopherson <seanjc@google.com>,
Jinchao Wang <wangjinchao600@gmail.com>,
Mathieu Desnoyers <mathieu.desnoyers@efficios.com>,
Thomas Gleixner <tglx@linutronix.de>,
Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
"H . Peter Anvin" <hpa@zytor.com>,
Alexander Shishkin <alexander.shishkin@linux.intel.com>,
Ian Rogers <irogers@google.com>,
linux-kernel@vger.kernel.org, linux-trace-kernel@vger.kernel.org,
linux-doc@vger.kernel.org, linux-perf-users@vger.kernel.org,
x86@kernel.org, Paolo Bonzini <pbonzini@redhat.com>,
kvm@vger.kernel.org
Subject: Re: [PATCH v17 03/13] x86/hw_breakpoints: Make DR7 updates NMI safe
Date: Thu, 24 Sep 2026 21:56:46 +0900 [thread overview]
Message-ID: <20260924215646.be6a2abb78f3243cef008919@kernel.org> (raw)
In-Reply-To: <20260923091320.GW776954@noisy.programming.kicks-ass.net>
On Wed, 23 Sep 2026 11:13:20 +0200
Peter Zijlstra <peterz@infradead.org> wrote:
> On Tue, Sep 22, 2026 at 01:25:19PM +0900, Masami Hiramatsu (Google) wrote:
> > From: Jinchao Wang <wangjinchao600@gmail.com>
> >
> > Hardware breakpoint installation and removal run with IRQs disabled, but
> > an NMI can still enter the same code through KGDB. The interrupted
> > operation and the NMI can consequently claim the same slot or overwrite
> > each other's DR7 state.
> >
> > Claim and release per-CPU slots with cmpxchg. Update cpu_dr7 with
> > single-instruction per-CPU operations, and preserve hardware-first
> > disable and hardware-last enable ordering. Add a per-CPU sequence number
> > so interrupted DR7 writers and restore paths detect an NMI update and
> > retry from the latest shadow state.
>
> Bah, KGDB.. Aren't there far more problems with that thing?
Yes, it could be... Hmm, it looks like we need to take a closer
look at other issues related to KGDB as well.
>
>
> > diff --git a/arch/x86/include/asm/debugreg.h b/arch/x86/include/asm/debugreg.h
> > index 854d82b88ff4..515d2d313d0c 100644
> > --- a/arch/x86/include/asm/debugreg.h
> > +++ b/arch/x86/include/asm/debugreg.h
> > @@ -18,6 +18,7 @@
> > #define DR7_FIXED_1 0x00000400
> >
> > DECLARE_PER_CPU(unsigned long, cpu_dr7);
> > +DECLARE_PER_CPU(unsigned int, cpu_dr7_seq);
>
> Would it make sense to:
>
> typedef struct {
> unsigned long dr7;
> unsigned int seq;
> } dr7_save_t;
Yeah, thanks for the good idea :)
>
>
> > #ifndef CONFIG_PARAVIRT_XXL
> > /*
> > @@ -125,40 +126,69 @@ static __always_inline bool hw_breakpoint_active(void)
> >
> > extern void hw_breakpoint_restore(void);
> >
> > -static __always_inline unsigned long local_db_save(void)
> > +static __always_inline void local_db_save(unsigned long *dr7,
> > + unsigned int *dr7_seq)
>
> static __always_inline dr7_save_t local_db_save(void)
>
> > {
>
> > }
> >
> > -static __always_inline void local_db_restore(unsigned long dr7)
> > +static __always_inline void local_db_restore(unsigned long dr7,
> > + unsigned int dr7_seq)
>
> static __always_inline void local_db_restore(dr7_save_t dr7)
>
> > {
>
> > }
> >
> > #ifdef CONFIG_CPU_SUP_AMD
>
> > diff --git a/arch/x86/kernel/hw_breakpoint.c b/arch/x86/kernel/hw_breakpoint.c
> > index 0473a5c95856..901323ae7d6a 100644
> > --- a/arch/x86/kernel/hw_breakpoint.c
> > +++ b/arch/x86/kernel/hw_breakpoint.c
>
> > @@ -106,32 +108,25 @@ int arch_install_hw_breakpoint(struct perf_event *bp)
>
> > + do {
> > + seq = this_cpu_inc_return(cpu_dr7_seq);
> > + this_cpu_write(cpu_debugreg[i], info->address);
> > + barrier();
> > + set_debugreg(info->address, i);
> > + if (info->mask)
> > + amd_set_dr_addr_mask(info->mask, i);
> > + this_cpu_or(cpu_dr7, encode_dr7(i, info->len, info->type));
> > + barrier();
> > + set_debugreg(this_cpu_read(cpu_dr7) | DR7_FIXED_1, 7);
> > + barrier();
> > + } while (seq != this_cpu_read(cpu_dr7_seq));
> >
> > return 0;
> > }
> > @@ -149,36 +144,34 @@ void arch_uninstall_hw_breakpoint(struct perf_event *bp)
>
> > + do {
> > + seq = this_cpu_inc_return(cpu_dr7_seq);
> > + dr7 = this_cpu_read(cpu_dr7);
>
> You're inconsistent with the leading barrier().
Ah, OK.
>
> > + dr7 &= ~__encode_dr7(i, info->len, info->type);
> > + set_debugreg(dr7 | DR7_FIXED_1, 7);
> > + if (info->mask)
> > + amd_set_dr_addr_mask(0, i);
> > + barrier();
> > + this_cpu_and(cpu_dr7,
> > + ~__encode_dr7(i, info->len, info->type));
> > + barrier();
> > + } while (seq != this_cpu_read(cpu_dr7_seq));
> > +
> > + WARN_ONCE(this_cpu_cmpxchg(bp_per_reg[i], bp, NULL) != bp,
> > + "Can't release breakpoint slot");
> > }
>
> These loops should be far more similar. Note how the top one does:
>
> this_cpu_or(cpu_dr7, encode_dr7(...));
> set_debugreg(this_cpu_read(cpu_dr7) | ..., 7);
>
> while the bottom one does:
>
> dr7 &= ~encode_dr7(...)
> set_debugreg(dr7 | ...);
> this_cpu_and(cpu_dr7, ~encode_dr7(...));
>
> Why can't they both have the same shape and only one encode_dr7()
> instance?
Indeed. It should have the same shape.
>
>
> > @@ -486,12 +480,18 @@ void flush_ptrace_hw_breakpoint(struct task_struct *tsk)
> >
> > void hw_breakpoint_restore(void)
> > {
> > + unsigned int seq;
> > +
> > + do {
> > + seq = this_cpu_inc_return(cpu_dr7_seq);
>
> no barrier().
>
> > + set_debugreg(this_cpu_read(cpu_debugreg[0]), 0);
> > + set_debugreg(this_cpu_read(cpu_debugreg[1]), 1);
> > + set_debugreg(this_cpu_read(cpu_debugreg[2]), 2);
> > + set_debugreg(this_cpu_read(cpu_debugreg[3]), 3);
> > + set_debugreg(DR6_RESERVED, 6);
> > + set_debugreg(this_cpu_read(cpu_dr7) | DR7_FIXED_1, 7);
> > + barrier();
> > + } while (seq != this_cpu_read(cpu_dr7_seq));
> > }
> > EXPORT_SYMBOL_FOR_KVM(hw_breakpoint_restore);
>
> I really can't say I'm a fan of this. Is KGDB really a thing?
No, I would like to drop this patch (and KVM patch)from this series
since wprobe is not supporting to set the DR7 from NMI context.
I think it is better to split the series into 2 threads,
- wprobe related features/improvements. ([4/13]-[13/13])
- NMI-safe DR7 for KGDB. ([2/13] and [3/13])
Thank you,
--
Masami Hiramatsu (Google) <mhiramat@kernel.org>
next prev parent reply other threads:[~2026-09-24 12:56 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 4:24 [PATCH v17 00/13] tracing: wprobe: x86: Add wprobe for watchpoint Masami Hiramatsu (Google)
2026-09-22 4:24 ` [PATCH v17 01/13] x86/mce: Fix hardware debug register corruption on task migration Masami Hiramatsu (Google)
2026-09-23 0:27 ` Borislav Petkov
2026-09-23 8:46 ` Peter Zijlstra
2026-09-23 8:56 ` Masami Hiramatsu
2026-09-23 18:36 ` [tip: x86/urgent] " tip-bot2 for Masami Hiramatsu (Google)
2026-09-22 4:25 ` [PATCH v17 02/13] perf/x86, KVM: Prevent host debug register leak into guest OS on NMI Masami Hiramatsu (Google)
2026-09-23 8:51 ` Peter Zijlstra
2026-09-23 14:33 ` Sean Christopherson
2026-09-24 1:31 ` Masami Hiramatsu
2026-09-24 9:18 ` Peter Zijlstra
2026-09-23 9:15 ` Peter Zijlstra
2026-09-23 15:32 ` Sean Christopherson
2026-09-24 0:56 ` Masami Hiramatsu
2026-09-24 9:23 ` Peter Zijlstra
2026-09-22 4:25 ` [PATCH v17 03/13] x86/hw_breakpoints: Make DR7 updates NMI safe Masami Hiramatsu (Google)
2026-09-23 9:13 ` Peter Zijlstra
2026-09-24 12:56 ` Masami Hiramatsu [this message]
2026-09-22 4:25 ` [PATCH v17 04/13] x86/hw_breakpoints: Add arch_modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-09-22 4:25 ` [PATCH v17 05/13] HWBP: Add modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-09-22 4:25 ` [PATCH v17 06/13] tracing/wprobe: Add wprobe (watchpoint probe) trace event support Masami Hiramatsu (Google)
2026-09-22 4:26 ` [PATCH v17 07/13] x86: hw_breakpoint: Add a kconfig to clarify when a breakpoint fires Masami Hiramatsu (Google)
2026-09-22 4:26 ` [PATCH v17 08/13] selftests: tracing: Add a basic testcase for wprobe Masami Hiramatsu (Google)
2026-09-22 4:26 ` [PATCH v17 09/13] selftests: tracing: Add syntax " Masami Hiramatsu (Google)
2026-09-22 4:26 ` [PATCH v17 10/13] tracing/wprobe: Add set_wprobe and clear_wprobe event triggers Masami Hiramatsu (Google)
2026-09-22 4:26 ` [PATCH v17 11/13] selftests: tracing: Add wprobe trigger testcases Masami Hiramatsu (Google)
2026-09-22 4:27 ` [PATCH v17 12/13] tracing/wprobe: Support BTF typecast in fetchargs Masami Hiramatsu (Google)
2026-09-22 4:27 ` [PATCH v17 13/13] tracing/wprobe: Support BTF struct offset resolution in set_wprobe trigger Masami Hiramatsu (Google)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924215646.be6a2abb78f3243cef008919@kernel.org \
--to=mhiramat@kernel.org \
--cc=alexander.shishkin@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=irogers@google.com \
--cc=kvm@vger.kernel.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=mathieu.desnoyers@efficios.com \
--cc=mingo@kernel.org \
--cc=pbonzini@redhat.com \
--cc=peterz@infradead.org \
--cc=rostedt@goodmis.org \
--cc=seanjc@google.com \
--cc=tglx@linutronix.de \
--cc=wangjinchao600@gmail.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®