From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
To: sashiko-reviews@lists.linux.dev
Cc: sashiko-bot@kernel.org, linux-trace-kernel@vger.kernel.org,
linux-perf-users@vger.kernel.org
Subject: Re: [PATCH v14 01/14] x86/mce: Fix hardware debug register corruption on task migration
Date: Sun, 6 Sep 2026 22:03:20 +0900 [thread overview]
Message-ID: <20260906220320.9d19131a69f3227fdd07e026@kernel.org> (raw)
In-Reply-To: <20260830144005.C28ED1F000E9@smtp.kernel.org>
On Sun, 30 Aug 2026 14:40:05 +0000
sashiko-bot@kernel.org wrote:
> > static __always_inline void exc_machine_check_kernel(struct pt_regs *regs)
> > {
> > irqentry_state_t irq_state;
> > + unsigned long dr7;
> >
> > WARN_ON_ONCE(user_mode(regs));
> >
> > @@ -2118,18 +2119,24 @@ static __always_inline void exc_machine_check_kernel(struct pt_regs *regs)
> > if (mca_cfg.initialized && mce_check_crashing_cpu())
> > return;
> >
> > + dr7 = local_db_save();
>
> [Severity: High]
> Does moving local_db_save() below the early checks in
> exc_machine_check_kernel() expose this early #MC entry code to hardware
> breakpoints?
>
> If a privileged user sets a hardware data breakpoint on a kernel variable
> accessed here, such as mca_cfg.initialized or variables inside
> mce_check_crashing_cpu(), a #DB exception could fire in kernel mode.
Ah, good catch! This can happen if we introduce wprobe.
>
> If a Machine Check Exception (#MC) then occurs and preempts the #DB handler,
> it switches to the #MC IST stack. Because local_db_save() is not called
> until after these variable accesses, the code could trigger a nested #DB
> exception.
>
> Since x86 uses a fixed-size Interrupt Stack Table (IST) for #DB exceptions
> that unconditionally resets the stack pointer to the top of the #DB IST
> stack, wouldn't the nested #DB overwrite the active stack frame of the
> interrupted #DB handler, leading to a fatal crash when it attempts to
> return?
>
> Could local_db_save() be called at the very beginning of
> exc_machine_check_kernel() to prevent this IST stack corruption?
Yes, I will fix it.
Thanks!
--
Masami Hiramatsu (Google) <mhiramat@kernel.org>
next prev parent reply other threads:[~2026-09-06 13:03 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-30 14:26 [PATCH v14 00/14] tracing: wprobe: x86: Add wprobe for watchpoint Masami Hiramatsu (Google)
2026-08-30 14:27 ` [PATCH v14 01/14] x86/mce: Fix hardware debug register corruption on task migration Masami Hiramatsu (Google)
2026-08-30 14:40 ` sashiko-bot
2026-09-06 13:03 ` Masami Hiramatsu [this message]
2026-08-30 14:27 ` [PATCH v14 02/14] tracing/probes: Fix BTF kflag check for anonymous struct member access Masami Hiramatsu (Google)
2026-08-30 14:38 ` sashiko-bot
2026-08-31 1:24 ` Masami Hiramatsu
2026-08-30 14:27 ` [PATCH v14 03/14] kprobes: Protect kprobe_blacklist with RCU Masami Hiramatsu (Google)
2026-08-30 14:33 ` sashiko-bot
2026-09-02 1:30 ` Masami Hiramatsu
2026-08-30 14:27 ` [PATCH v14 04/14] x86/hw_breakpoints: Make DR7 updates NMI safe Masami Hiramatsu (Google)
2026-08-30 14:45 ` sashiko-bot
2026-09-06 15:28 ` Masami Hiramatsu
2026-08-30 14:27 ` [PATCH v14 05/14] x86/hw_breakpoints: Add arch_modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-08-30 14:38 ` sashiko-bot
2026-09-06 15:42 ` Masami Hiramatsu
2026-08-30 14:27 ` [PATCH v14 06/14] HWBP: Add modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-08-30 14:40 ` sashiko-bot
2026-09-06 15:43 ` Masami Hiramatsu
2026-08-30 14:28 ` [PATCH v14 07/14] tracing/wprobe: Add wprobe (watchpoint probe) trace event support Masami Hiramatsu (Google)
2026-08-30 14:42 ` sashiko-bot
2026-08-30 14:28 ` [PATCH v14 08/14] x86: hw_breakpoint: Add a kconfig to clarify when a breakpoint fires Masami Hiramatsu (Google)
2026-08-30 14:33 ` sashiko-bot
2026-08-30 14:28 ` [PATCH v14 09/14] selftests: tracing: Add a basic testcase for wprobe Masami Hiramatsu (Google)
2026-08-30 14:34 ` sashiko-bot
2026-08-30 14:28 ` [PATCH v14 10/14] selftests: tracing: Add syntax " Masami Hiramatsu (Google)
2026-08-30 14:37 ` sashiko-bot
2026-08-30 14:28 ` [PATCH v14 11/14] tracing/wprobe: Add set_wprobe and clear_wprobe event triggers Masami Hiramatsu (Google)
2026-08-30 14:52 ` sashiko-bot
2026-09-06 15:50 ` Masami Hiramatsu
2026-08-30 14:29 ` [PATCH v14 12/14] selftests: ftrace: Add wprobe trigger testcase Masami Hiramatsu (Google)
2026-08-30 14:44 ` sashiko-bot
2026-08-30 14:29 ` [PATCH v14 13/14] tracing/wprobe: Support BTF typecast in fetchargs Masami Hiramatsu (Google)
2026-08-30 14:44 ` sashiko-bot
2026-08-30 14:29 ` [PATCH v14 14/14] tracing/wprobe: Support BTF struct offset resolution in set_wprobe trigger Masami Hiramatsu (Google)
2026-08-30 14:46 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260906220320.9d19131a69f3227fdd07e026@kernel.org \
--to=mhiramat@kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=sashiko-bot@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.