[PATCH RFC] arm64: entry: PSTATE_I_SET is leaking on pseudo NMI mode

Will Deacon will at kernel.org
Mon Aug 10 04:43:11 PDT 2026


On Fri, Aug 07, 2026 at 09:29:12AM -0700, Breno Leitao wrote:
> On Fri, Aug 07, 2026 at 07:58:21AM -0700, Breno Leitao wrote:
> > Meanwhile, I will try to ftrace the writes to PMR and regs->pmr to get
> > a better grasp of the states machine we are in (probably on Monday).
> 
> It seems LLM found a very easy to reproduce this:
> 
> 	bash-5.1# dmesg
> 
> 	bash-5.1#  cd /sys/kernel/tracing
> 	echo 'r:pmr vfs_read bad=+0($retval):u64' >> kprobe_events
> 	echo 1 > events/kprobes/pmr/enable

Nice, that triggers straightforwardly in QEMU for me. The diff below
(which implements my suggestion from [1]) seems to fix the issue, but
it would be good to hear feedback from one of the Arm folks.

Will

[1] https://lore.kernel.org/all/anXgWRmcjwPKG7N5@willie-the-truck/

--->8

diff --git a/arch/arm64/include/asm/daifflags.h b/arch/arm64/include/asm/daifflags.h
index 795b35128467..691ee5f86dbe 100644
--- a/arch/arm64/include/asm/daifflags.h
+++ b/arch/arm64/include/asm/daifflags.h
@@ -132,7 +132,7 @@ static __always_inline void local_daif_inherit(struct pt_regs *regs)
                trace_hardirqs_on();

        if (system_uses_irq_prio_masking())
-               gic_write_pmr(regs->pmr);
+               gic_write_pmr(regs->pmr & ~GIC_PRIO_PSR_I_SET);

        /*
         * We can't use local_daif_restore(regs->pstate) here as




More information about the linux-arm-kernel mailing list