From: Oleksii Kurochko <oleksii.kurochko@gmail.com>
To: Baptiste Le Duc <baptiste.le-duc@vates.tech>
Cc: xen-devel@lists.xenproject.org, "Julien Grall" <julien@xen.org>,
"Alistair Francis" <alistair.francis@wdc.com>,
"Anthony PERARD" <anthony.perard@vates.tech>,
"Andrew Cooper" <andrew.cooper3@citrix.com>,
"Jan Beulich" <jbeulich@suse.com>,
"Michal Orzel" <michal.orzel@amd.com>,
"Stefano Stabellini" <sstabellini@kernel.org>,
"Roger Pau Monné" <roger@xenproject.org>,
"Connor Davis" <connojdavis@gmail.com>
Subject: Re: [PATCH v2 5/6] xen/riscv: flush speculatively cached Bare-mode TLB entries in turn_on_mmu()
Date: Tue, 22 Sep 2026 16:21:54 +0200 [thread overview]
Message-ID: <1a1d21cb-20c5-4b11-af1e-995d31fd2995@gmail.com> (raw)
In-Reply-To: <1789032899.8631fc262581453bbf619ec5b2062170.1a08aaba238000c4f3@vates.tech>
On 9/10/26 11:34 AM, Baptiste Le Duc wrote:
> The existing SFENCE.VMA before the satp write only orders the page table
> stores from setup_initial_pagetables() against subsequent implicit reads.
> It does not prevent the CPU from speculatively caching translations after
> the fence retires.
>
> According to the RISC-V Privileged specification, implementations are
> permitted to speculatively cache Bare-mode identity mappings. Furthermore,
> selecting MODE=Bare (which happens during check_pgtbl_mode_support())
> requires zeroing the remaining fields of satp, causing ASID=0 to be
> actively used in Bare mode. Consequently, the TLB can be polluted with Bare
> identity mappings tagged with ASID=0.
>
> Once satp is written to enable Sv39 translation, these cached identity
> mappings (tagged with ASID=0) can shadow the true Sv39 translations. This
> would lead to translation failures since turn_on_mmu() jumps to a
> non-identity-mapped linker address.
>
> Fix this by adding a post-satp-write SFENCE.VMA to invalidate any stale
> translations (including Bare-mode identity mappings under ASID=0) before
> jumping to the virtual address space.
>
> Assisted-by: Claude:claude-opus-5
> Signed-off-by: Baptiste Le Duc <baptiste.le-duc@vates.tech>
> ---
> Changes since v1:
> - rewrite commit message
> ---
> xen/arch/riscv/riscv64/head.S | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/xen/arch/riscv/riscv64/head.S b/xen/arch/riscv/riscv64/head.S
> index 9c40512e61..7f6edc972f 100644
> --- a/xen/arch/riscv/riscv64/head.S
> +++ b/xen/arch/riscv/riscv64/head.S
> @@ -98,6 +98,7 @@ FUNC(turn_on_mmu)
> srli t1, t1, PAGE_SHIFT
> or t1, t1, t0
> csrw CSR_SATP, t1
> + sfence.vma
>
> jr a0
> END(turn_on_mmu)
>
Reviewed-by: Oleksii Kurochko <oleksii.kurochko@gmail.com>
~ Oleksii
next prev parent reply other threads:[~2026-09-22 14:22 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-10 9:30 [PATCH v2 0/6] xen/riscv: fix boot on missing extensions and MMU setup bugs Baptiste Le Duc
2026-09-10 9:34 ` [PATCH v2 1/6] xen/riscv: fix Svade/Svadu A/D bit handling Baptiste Le Duc
2026-09-21 15:26 ` Jan Beulich
2026-09-21 17:03 ` Baptiste Le Duc
2026-09-22 6:24 ` Jan Beulich
2026-09-22 9:17 ` Baptiste Le Duc
2026-09-22 15:14 ` Oleksii Kurochko
2026-09-22 15:18 ` Baptiste Le Duc
2026-09-23 7:31 ` Oleksii Kurochko
2026-09-22 15:29 ` Oleksii Kurochko
2026-09-23 10:06 ` Baptiste Le Duc
2026-09-23 10:41 ` Oleksii Kurochko
2026-09-10 9:34 ` [PATCH v2 2/6] xen/riscv: set A/D bits in Xen's page-table mappings under Svade Baptiste Le Duc
2026-09-16 8:54 ` Zhang Zheng
2026-09-21 15:35 ` Jan Beulich
2026-09-22 15:05 ` Oleksii Kurochko
2026-09-10 9:34 ` [PATCH v2 3/6] xen/riscv: make Svpbmt no longer a required extension Baptiste Le Duc
2026-09-21 15:57 ` Jan Beulich
2026-09-22 14:38 ` Oleksii Kurochko
2026-09-28 13:21 ` Baptiste Le Duc
2026-09-22 14:48 ` Oleksii Kurochko
2026-09-10 9:34 ` [PATCH v2 4/6] xen/riscv: make Zihintpause " Baptiste Le Duc
2026-09-22 12:27 ` Jan Beulich
2026-09-22 14:26 ` Oleksii Kurochko
2026-09-22 15:10 ` Jan Beulich
2026-09-22 14:50 ` Oleksii Kurochko
2026-09-10 9:34 ` [PATCH v2 5/6] xen/riscv: flush speculatively cached Bare-mode TLB entries in turn_on_mmu() Baptiste Le Duc
2026-09-22 12:31 ` Jan Beulich
2026-09-22 14:21 ` Oleksii Kurochko [this message]
2026-09-10 9:34 ` [PATCH v2 6/6] xen/riscv: fix level_map_mask truncation on load_start Baptiste Le Duc
2026-09-16 8:54 ` Zhang Zheng
2026-09-22 12:43 ` Jan Beulich
2026-09-22 14:21 ` Oleksii Kurochko
2026-09-10 9:47 ` [PATCH v2 0/6] xen/riscv: fix boot on missing extensions and MMU setup bugs Jan Beulich
2026-09-10 9:56 ` Baptiste Le Duc
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1a1d21cb-20c5-4b11-af1e-995d31fd2995@gmail.com \
--to=oleksii.kurochko@gmail.com \
--cc=alistair.francis@wdc.com \
--cc=andrew.cooper3@citrix.com \
--cc=anthony.perard@vates.tech \
--cc=baptiste.le-duc@vates.tech \
--cc=connojdavis@gmail.com \
--cc=jbeulich@suse.com \
--cc=julien@xen.org \
--cc=michal.orzel@amd.com \
--cc=roger@xenproject.org \
--cc=sstabellini@kernel.org \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.