From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id C8841C53219 for ; Tue, 28 Jul 2026 01:17:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: Content-Type:In-Reply-To:From:References:CC:To:Subject:MIME-Version:Date: Message-ID:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=I3WZY5pE4MyrvdVsJ7lEyXvFZ7njqeEeoQdtEU0hhfU=; b=BZelWPPT7b/Y4QDyJI9ZOCJjYX v768ZxNd6GHF+2Y2SmqvBZyQjMByjCrw9qSZEA3zufYSB5w5BWpfldCN5iwkOueYEp1xBzrt2gapG +Ai3goyzz+XE2u0nOH/c02eU8LSLXNcqE8hIR6AsuUn0ToVgfXS7WMNdpT0lzbG2pDg4RTIU3rVVn fiO1+7DFIkvHgoOehQApaXYkUeAD2BTVKvpKEncpWpcK2ixxWT+Hc57+Qj4GlLJR4b+tLDKb5Kf26 StOgwm3WRUDaj2qNrKHMOBJdX4wwvqd6OEeIR49JgkTPH42SeeT8HWcy2APajuhP7clliffvBmwbu t9CjiPIg==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1woWRt-00000004BSV-47X5; Tue, 28 Jul 2026 01:17:38 +0000 Received: from canpmsgout08.his.huawei.com ([113.46.200.223]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1woWRr-00000004BRN-0SHG for linux-arm-kernel@lists.infradead.org; Tue, 28 Jul 2026 01:17:36 +0000 dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=I3WZY5pE4MyrvdVsJ7lEyXvFZ7njqeEeoQdtEU0hhfU=; b=IULsrJRNxQtxsw1k+RpV8VHOIQSDjVs6GvmI2Fid7DgjNd+os8QGncMXkvp60dEoHjcOejucd 9uNMXsT61l3yNWJ+K4aAsyfXoL0BjkllstC5mvRXBuXNpnckChhdX9QxQgyT6z6eIqtPT4PFxnL HtMyLZXVOzQm1C5QgRLPaZE= Received: from mail.maildlp.com (unknown [172.19.163.127]) by canpmsgout08.his.huawei.com (SkyGuard) with ESMTPS id 4h8HQF5HJRzmV99; Tue, 28 Jul 2026 09:08:05 +0800 (CST) Received: from dggpemf500011.china.huawei.com (unknown [7.185.36.131]) by mail.maildlp.com (Postfix) with ESMTPS id 1EA91402AB; Tue, 28 Jul 2026 09:17:32 +0800 (CST) Received: from [10.67.109.254] (10.67.109.254) by dggpemf500011.china.huawei.com (7.185.36.131) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Tue, 28 Jul 2026 09:17:31 +0800 Message-ID: Date: Tue, 28 Jul 2026 09:17:30 +0800 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [RFC PATCH v2 03/45] arm64: hibernate: mask DAIF before restoring hibernated kernel To: Vladimir Murzin , CC: , , , , References: <20260727163453.7969-1-vladimir.murzin@arm.com> <20260727163453.7969-4-vladimir.murzin@arm.com> From: Jinjie Ruan In-Reply-To: <20260727163453.7969-4-vladimir.murzin@arm.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 8bit X-Originating-IP: [10.67.109.254] X-ClientProxiedBy: kwepems200001.china.huawei.com (7.221.188.67) To dggpemf500011.china.huawei.com (7.185.36.131) X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260727_181735_461384_B6650577 X-CRM114-Status: GOOD ( 21.75 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org 在 2026/7/28 0:34, Vladimir Murzin 写道: > From: Ada Couprie Diaz > > The arm64 hibernate code manages the exception masking in an unsound > way, leading to potential crashes and/or warnings during resume. > > When a hibernation image is saved in `swsusp_arch_suspend()`, all DAIF > exceptions are masked (by virtue of `local_daif_save()`), and the > suspended image is saved assuming that all DAIF exceptions will remain > masked when the image is restored. > > When a hibernation image is resumed by `swsusp_arch_resume()`, only > interrupts are masked (by virtue of `local_irq_disable()` in > `resume_target_kernel()`). When pseudo-NMI is enabled the DAIF.IF bits > will be clear, and regardless of pseudo-NMI the DAIF.DA bits will be > clear. > > This means that there are two problems: > > (1) It is possible to take Debug, SError, or pseudo-NMI exceptions > during the resume process. This is unsafe, as during the resume > process both the old ane new kernels will tranisently be in an > inconsistent state, and swsusp_arch_suspend_exit() won't retain > an executable mapping of any exception vectors. > > Any exception taken here will be fatal and silent. > > (2) When re-entering the resumed kernel, some DAIF bits will be clear > unexpectedly. This permits Debug, SError, or pseudo-NMI exceptions > to be taken for a short period while the resumed kernel is not yet > in a consistent state. > > This is detected by CONFIG_ARM64_DEBUG_PRIORITY_MASKING. > > Avoid these issues by masking all DAIF exceptions during resume. > > Fixes: 82869ac57b5d ("arm64: kernel: Add support for hibernate/suspend-to-disk") > Signed-off-by: Ada Couprie Diaz > Signed-off-by: Vladimir Murzin > --- > arch/arm64/kernel/hibernate.c | 12 ++++++++++++ > 1 file changed, 12 insertions(+) > > diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c > index 9717568518ba..1eb1c1074c5b 100644 > --- a/arch/arm64/kernel/hibernate.c > +++ b/arch/arm64/kernel/hibernate.c > @@ -465,9 +465,21 @@ int __nocfi swsusp_arch_resume(void) > if (el2_reset_needed()) > __hyp_set_vectors(el2_vectors); > > + /* > + * It is necessary to mask all DAIF exceptions here as: > + * > + * - The copy of swsusp_arch_suspend_exit() in the hibernation > + * text cannot handle taking any exceptions. > + * > + * - The suspended kernel masked all DAIF exceptions in > + * swsusp_arch_resume(), and expects to be re-entered in the > + * same state : with all DAIF exceptions masked. > + */ > + local_daif_save(); > hibernate_exit(virt_to_phys(tmp_pg_dir), resume_hdr.ttbr1_el1, > resume_hdr.reenter_kernel, restore_pblist, > resume_hdr.__hyp_stub_vectors, virt_to_phys(zero_page)); > + unreachable(); Reviewed-by: Jinjie Ruan > > return 0; > }