[PATCH RFC] arm64: entry: PSTATE_I_SET is leaking on pseudo NMI mode

Jinjie Ruan ruanjinjie at huawei.com
Mon Aug 10 05:51:38 PDT 2026



在 2026/8/10 19:43, Will Deacon 写道:
> On Fri, Aug 07, 2026 at 09:29:12AM -0700, Breno Leitao wrote:
>> On Fri, Aug 07, 2026 at 07:58:21AM -0700, Breno Leitao wrote:
>>> Meanwhile, I will try to ftrace the writes to PMR and regs->pmr to get
>>> a better grasp of the states machine we are in (probably on Monday).
>>
>> It seems LLM found a very easy to reproduce this:
>>
>> 	bash-5.1# dmesg
>>
>> 	bash-5.1#  cd /sys/kernel/tracing
>> 	echo 'r:pmr vfs_read bad=+0($retval):u64' >> kprobe_events
>> 	echo 1 > events/kprobes/pmr/enable
> 
> Nice, that triggers straightforwardly in QEMU for me. The diff below
> (which implements my suggestion from [1]) seems to fix the issue, but
> it would be good to hear feedback from one of the Arm folks.
> 
> Will
> 
> [1] https://lore.kernel.org/all/anXgWRmcjwPKG7N5@willie-the-truck/
> 
> --->8
> 
> diff --git a/arch/arm64/include/asm/daifflags.h b/arch/arm64/include/asm/daifflags.h
> index 795b35128467..691ee5f86dbe 100644
> --- a/arch/arm64/include/asm/daifflags.h
> +++ b/arch/arm64/include/asm/daifflags.h
> @@ -132,7 +132,7 @@ static __always_inline void local_daif_inherit(struct pt_regs *regs)
>                 trace_hardirqs_on();
> 
>         if (system_uses_irq_prio_masking())
> -               gic_write_pmr(regs->pmr);
> +               gic_write_pmr(regs->pmr & ~GIC_PRIO_PSR_I_SET);

If the DAIF.I is restored below and the GIC_PRIO_PSR_I_SET in the pmr is
cleared here, it seems to introduce inconsistency with current Pseudo
NMI code.

> 
>         /*
>          * We can't use local_daif_restore(regs->pstate) here as
> 




More information about the linux-arm-kernel mailing list