From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6ACB731D39A for ; Mon, 27 Jul 2026 12:09:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785154157; cv=none; b=UVdC1qUlFwV0IHjqB4F13+SFf+QPQya7Rom0fe5AQbGutWL9U8y3Q7DqZ3dnjHoIvL5zw0iuuo9suO1Y3QsR6Sn5V0D4MDLyJcyvSANj6XdrgT3GChsvYhYFRju8DHnDoFZraIWEonZC+pkJBYkovYnL8gesLx0bGFD1NkKJML8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785154157; c=relaxed/simple; bh=c41VtCZT69nMxT9QkJQJFm92bBsiI7ENTGM0gWilmzo=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=pQ4LgJhNUPoEUu/swmugje0Iv5VoafippaNkSECNF1DSTCfmYwjZNoQ1rk+jKQl16aSviDn7q8rnoe9N3YClaYOs4IhTKZ4TyFiXe0lSc9yLM9+cbg1M3djRCkAOR9WlWu1wuAmAhS4uKdaSPIpVqDZ27m+zPK3/n1Car1dRO0U= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=MLOFOVUr; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="MLOFOVUr" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 12B031F000E9; Mon, 27 Jul 2026 12:09:13 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785154156; bh=es9szWdyIlsG4q+xS0+CmM6PVBbF7s3g2iIfm68cxO0=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=MLOFOVUrgZsCNGMNzBsEItbhkvABSU2ExXrWFgPl9lPvkOtSoETIjV1SR1SS9dWNH 2FPlVXGDxSiyJpPTNlfvR8lS2jP23yyI5pnucF21CirxcllLnThRYjfl6itqEi/BzF 3phhBjnEvKGtnp6RKqp2u4MuUE1KyDxNFL+MUKq0hKENt+2CTqzRbc075SNfUteqsz qmWOrByQoLbDnCdEWjEd5ilsp2ZCqcqyVmeahk5og1HwFFJxW/cS3iomVLsTQ+I+bq waNym11yaN6MLgiChjK6dp21vmvbod4R4UNo8u584GG+bfCEQaFXL4JcJ50ghDjIL4 Lg4seDXK5CfsA== Message-ID: <63007c21-4783-4a98-9853-62b36b737df3@kernel.org> Date: Mon, 27 Jul 2026 14:09:12 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v2] powerpc/irq: Fix missing r2 clobber in PCREL inline assembly To: Saket Kumar Bhaskar , linux-kernel@vger.kernel.org, linuxppc-dev@lists.ozlabs.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, segher@kernel.crashing.org, hbathini@linux.ibm.com, venkat88@linux.ibm.com, yeswanth@linux.ibm.com References: <7c84fa5e24263d8247b4723118e6130d63b40912.1785131859.git.skb99@linux.ibm.com> Content-Language: fr-FR From: "Christophe Leroy (CS GROUP)" In-Reply-To: <7c84fa5e24263d8247b4723118e6130d63b40912.1785131859.git.skb99@linux.ibm.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Le 27/07/2026 à 12:58, Saket Kumar Bhaskar a écrit : > In CONFIG_PPC_KERNEL_PCREL mode, r2 is no longer reserved for the TOC > pointer and is available as a caller-saved register [0]. > > Both call_do_irq() and call_do_softirq() use inline assembly to call > functions with stack switching, but fail to list r2 in their clobber > lists. This causes the compiler to assume r2 is preserved across these > calls, leading to register corruption when the called functions > (__do_irq and __do_softirq) clobber r2. > > As a result of this kernel crash during interrupt handling is seen and > the kernel fails to boot: > > BUG: Unable to handle kernel data access on write at 0xc000000404697638 > Faulting instruction address: 0xc0000000000181ec > Oops: Kernel access of bad area, sig: 11 [#1] > NIP [c0000000000181ec] __do_IRQ+0x6c/0xc0 > > With older GCC, the compiler would conservatively allocate > callee-saved registers (like r31) for values spanning function calls, > accidentally avoiding the bug: > > <__do_IRQ>: > 00 00 00 60 nop > a6 02 08 7c mflr r0 > f8 ff e1 fb std r31,-8(r1) > f0 ff c1 fb std r30,-16(r1) > 2d 03 10 06 pla r31,53297316 > > ... > > 3d e8 ff 4b bl c0000000000165ac <__do_irq> > 00 00 21 e8 ld r1,0(r1) > 28 00 4d e9 ld r10,40(r13) > 40 00 21 38 addi r1,r1,64 > 2a f9 aa 7f stdx r29,r10,r31 > > With newer GCC 14, the compiler uses r2 for such values, exposing the > missing clobber specification: > > <__do_IRQ>: > 00 00 00 60 nop > a6 02 08 7c mflr r0 > f0 ff c1 fb std r30,-16(r1) > f8 ff e1 fb std r31,-8(r1) > 29 02 10 06 pla r2,36252592 # c0000000022aadc0 <__irq_regs> > > ... > > 85 dc ff 4b bl c000000000015ee0 <__do_irq> > 00 00 21 e8 ld r1,0(r1) > 28 00 2d e9 ld r9,40(r13) > 30 00 21 38 addi r1,r1,48 > 2a 11 c9 7f stdx r30,r9,r2 > > Fix this by adding r2 to the clobber list for both call_do_irq() and > call_do_softirq() when CONFIG_PPC_KERNEL_PCREL is enabled. > > [0]: https://www.mail-archive.com/gcc-patches@gcc.gnu.org/msg313226.html > > Fixes: 7e3a68be42e1 ("powerpc/64: vmlinux support building with PCREL addresing") > Signed-off-by: Saket Kumar Bhaskar > --- > Changes since v1: > Addressed comments from Segher: > * Modified comments to "clobber may happen" > > v1: https://lore.kernel.org/all/dc021f42afa10396052499cbeda1772e30b7ca64.1784530547.git.skb99@linux.ibm.com/ > > arch/powerpc/kernel/irq.c | 14 ++++++++++++-- > 1 file changed, 12 insertions(+), 2 deletions(-) > > diff --git a/arch/powerpc/kernel/irq.c b/arch/powerpc/kernel/irq.c > index a0e8b998c9b5..b5343cfd6c9f 100644 > --- a/arch/powerpc/kernel/irq.c > +++ b/arch/powerpc/kernel/irq.c > @@ -218,7 +218,12 @@ static __always_inline void call_do_softirq(const void *sp) > [callee] "i" (__do_softirq) > : // Clobbers > "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6", > - "cr7", "r0", "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10", > + "cr7", "r0", > + /* r2 may be clobbered by the callee when using the ELFv2 ABI */ Not sure the comment is correct. You get CONFIG_PPC64_ELF_ABI_V2 without CONFIG_PPC_KERNEL_PCREL. Kconfig help presents CONFIG_PPC_KERNEL_PCREL as an ABI extension. > +#ifdef CONFIG_PPC_KERNEL_PCREL > + "r2", > +#endif > + "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10", > "r11", "r12" To minimise number of small lines I'd prefer something like: "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6", "cr7", "r0", #ifdef CONFIG_PPC_KERNEL_PCREL "r2", #endif "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10", "r11", "r12" > ); > } > @@ -276,7 +281,12 @@ static __always_inline void call_do_irq(struct pt_regs *regs, void *sp) > [callee] "i" (__do_irq) > : // Clobbers > "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6", > - "cr7", "r0", "r4", "r5", "r6", "r7", "r8", "r9", "r10", > + "cr7", "r0", > + /* r2 may be clobbered by the callee when using the ELFv2 ABI */ > +#ifdef CONFIG_PPC_KERNEL_PCREL > + "r2", > +#endif > + "r4", "r5", "r6", "r7", "r8", "r9", "r10", Same > "r11", "r12" > ); > } Reviewed-by: Christophe Leroy (CS GROUP)