* [PATCH v2] powerpc/irq: Fix missing r2 clobber in PCREL inline assembly
@ 2026-07-27 10:58 Saket Kumar Bhaskar
2026-07-27 12:09 ` Christophe Leroy (CS GROUP)
0 siblings, 1 reply; 3+ messages in thread
From: Saket Kumar Bhaskar @ 2026-07-27 10:58 UTC (permalink / raw)
To: linux-kernel, linuxppc-dev
Cc: maddy, mpe, npiggin, chleroy, segher, hbathini, venkat88,
yeswanth, skb99
In CONFIG_PPC_KERNEL_PCREL mode, r2 is no longer reserved for the TOC
pointer and is available as a caller-saved register [0].
Both call_do_irq() and call_do_softirq() use inline assembly to call
functions with stack switching, but fail to list r2 in their clobber
lists. This causes the compiler to assume r2 is preserved across these
calls, leading to register corruption when the called functions
(__do_irq and __do_softirq) clobber r2.
As a result of this kernel crash during interrupt handling is seen and
the kernel fails to boot:
BUG: Unable to handle kernel data access on write at 0xc000000404697638
Faulting instruction address: 0xc0000000000181ec
Oops: Kernel access of bad area, sig: 11 [#1]
NIP [c0000000000181ec] __do_IRQ+0x6c/0xc0
With older GCC, the compiler would conservatively allocate
callee-saved registers (like r31) for values spanning function calls,
accidentally avoiding the bug:
<__do_IRQ>:
00 00 00 60 nop
a6 02 08 7c mflr r0
f8 ff e1 fb std r31,-8(r1)
f0 ff c1 fb std r30,-16(r1)
2d 03 10 06 pla r31,53297316
...
3d e8 ff 4b bl c0000000000165ac <__do_irq>
00 00 21 e8 ld r1,0(r1)
28 00 4d e9 ld r10,40(r13)
40 00 21 38 addi r1,r1,64
2a f9 aa 7f stdx r29,r10,r31
With newer GCC 14, the compiler uses r2 for such values, exposing the
missing clobber specification:
<__do_IRQ>:
00 00 00 60 nop
a6 02 08 7c mflr r0
f0 ff c1 fb std r30,-16(r1)
f8 ff e1 fb std r31,-8(r1)
29 02 10 06 pla r2,36252592 # c0000000022aadc0 <__irq_regs>
...
85 dc ff 4b bl c000000000015ee0 <__do_irq>
00 00 21 e8 ld r1,0(r1)
28 00 2d e9 ld r9,40(r13)
30 00 21 38 addi r1,r1,48
2a 11 c9 7f stdx r30,r9,r2
Fix this by adding r2 to the clobber list for both call_do_irq() and
call_do_softirq() when CONFIG_PPC_KERNEL_PCREL is enabled.
[0]: https://www.mail-archive.com/gcc-patches@gcc.gnu.org/msg313226.html
Fixes: 7e3a68be42e1 ("powerpc/64: vmlinux support building with PCREL addresing")
Signed-off-by: Saket Kumar Bhaskar <skb99@linux.ibm.com>
---
Changes since v1:
Addressed comments from Segher:
* Modified comments to "clobber may happen"
v1: https://lore.kernel.org/all/dc021f42afa10396052499cbeda1772e30b7ca64.1784530547.git.skb99@linux.ibm.com/
arch/powerpc/kernel/irq.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
diff --git a/arch/powerpc/kernel/irq.c b/arch/powerpc/kernel/irq.c
index a0e8b998c9b5..b5343cfd6c9f 100644
--- a/arch/powerpc/kernel/irq.c
+++ b/arch/powerpc/kernel/irq.c
@@ -218,7 +218,12 @@ static __always_inline void call_do_softirq(const void *sp)
[callee] "i" (__do_softirq)
: // Clobbers
"lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6",
- "cr7", "r0", "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10",
+ "cr7", "r0",
+ /* r2 may be clobbered by the callee when using the ELFv2 ABI */
+#ifdef CONFIG_PPC_KERNEL_PCREL
+ "r2",
+#endif
+ "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10",
"r11", "r12"
);
}
@@ -276,7 +281,12 @@ static __always_inline void call_do_irq(struct pt_regs *regs, void *sp)
[callee] "i" (__do_irq)
: // Clobbers
"lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6",
- "cr7", "r0", "r4", "r5", "r6", "r7", "r8", "r9", "r10",
+ "cr7", "r0",
+ /* r2 may be clobbered by the callee when using the ELFv2 ABI */
+#ifdef CONFIG_PPC_KERNEL_PCREL
+ "r2",
+#endif
+ "r4", "r5", "r6", "r7", "r8", "r9", "r10",
"r11", "r12"
);
}
--
2.54.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH v2] powerpc/irq: Fix missing r2 clobber in PCREL inline assembly 2026-07-27 10:58 [PATCH v2] powerpc/irq: Fix missing r2 clobber in PCREL inline assembly Saket Kumar Bhaskar @ 2026-07-27 12:09 ` Christophe Leroy (CS GROUP) 2026-07-29 16:47 ` Saket Kumar Bhaskar 0 siblings, 1 reply; 3+ messages in thread From: Christophe Leroy (CS GROUP) @ 2026-07-27 12:09 UTC (permalink / raw) To: Saket Kumar Bhaskar, linux-kernel, linuxppc-dev Cc: maddy, mpe, npiggin, segher, hbathini, venkat88, yeswanth Le 27/07/2026 à 12:58, Saket Kumar Bhaskar a écrit : > In CONFIG_PPC_KERNEL_PCREL mode, r2 is no longer reserved for the TOC > pointer and is available as a caller-saved register [0]. > > Both call_do_irq() and call_do_softirq() use inline assembly to call > functions with stack switching, but fail to list r2 in their clobber > lists. This causes the compiler to assume r2 is preserved across these > calls, leading to register corruption when the called functions > (__do_irq and __do_softirq) clobber r2. > > As a result of this kernel crash during interrupt handling is seen and > the kernel fails to boot: > > BUG: Unable to handle kernel data access on write at 0xc000000404697638 > Faulting instruction address: 0xc0000000000181ec > Oops: Kernel access of bad area, sig: 11 [#1] > NIP [c0000000000181ec] __do_IRQ+0x6c/0xc0 > > With older GCC, the compiler would conservatively allocate > callee-saved registers (like r31) for values spanning function calls, > accidentally avoiding the bug: > > <__do_IRQ>: > 00 00 00 60 nop > a6 02 08 7c mflr r0 > f8 ff e1 fb std r31,-8(r1) > f0 ff c1 fb std r30,-16(r1) > 2d 03 10 06 pla r31,53297316 > > ... > > 3d e8 ff 4b bl c0000000000165ac <__do_irq> > 00 00 21 e8 ld r1,0(r1) > 28 00 4d e9 ld r10,40(r13) > 40 00 21 38 addi r1,r1,64 > 2a f9 aa 7f stdx r29,r10,r31 > > With newer GCC 14, the compiler uses r2 for such values, exposing the > missing clobber specification: > > <__do_IRQ>: > 00 00 00 60 nop > a6 02 08 7c mflr r0 > f0 ff c1 fb std r30,-16(r1) > f8 ff e1 fb std r31,-8(r1) > 29 02 10 06 pla r2,36252592 # c0000000022aadc0 <__irq_regs> > > ... > > 85 dc ff 4b bl c000000000015ee0 <__do_irq> > 00 00 21 e8 ld r1,0(r1) > 28 00 2d e9 ld r9,40(r13) > 30 00 21 38 addi r1,r1,48 > 2a 11 c9 7f stdx r30,r9,r2 > > Fix this by adding r2 to the clobber list for both call_do_irq() and > call_do_softirq() when CONFIG_PPC_KERNEL_PCREL is enabled. > > [0]: https://www.mail-archive.com/gcc-patches@gcc.gnu.org/msg313226.html > > Fixes: 7e3a68be42e1 ("powerpc/64: vmlinux support building with PCREL addresing") > Signed-off-by: Saket Kumar Bhaskar <skb99@linux.ibm.com> > --- > Changes since v1: > Addressed comments from Segher: > * Modified comments to "clobber may happen" > > v1: https://lore.kernel.org/all/dc021f42afa10396052499cbeda1772e30b7ca64.1784530547.git.skb99@linux.ibm.com/ > > arch/powerpc/kernel/irq.c | 14 ++++++++++++-- > 1 file changed, 12 insertions(+), 2 deletions(-) > > diff --git a/arch/powerpc/kernel/irq.c b/arch/powerpc/kernel/irq.c > index a0e8b998c9b5..b5343cfd6c9f 100644 > --- a/arch/powerpc/kernel/irq.c > +++ b/arch/powerpc/kernel/irq.c > @@ -218,7 +218,12 @@ static __always_inline void call_do_softirq(const void *sp) > [callee] "i" (__do_softirq) > : // Clobbers > "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6", > - "cr7", "r0", "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10", > + "cr7", "r0", > + /* r2 may be clobbered by the callee when using the ELFv2 ABI */ Not sure the comment is correct. You get CONFIG_PPC64_ELF_ABI_V2 without CONFIG_PPC_KERNEL_PCREL. Kconfig help presents CONFIG_PPC_KERNEL_PCREL as an ABI extension. > +#ifdef CONFIG_PPC_KERNEL_PCREL > + "r2", > +#endif > + "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10", > "r11", "r12" To minimise number of small lines I'd prefer something like: "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6", "cr7", "r0", #ifdef CONFIG_PPC_KERNEL_PCREL "r2", #endif "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10", "r11", "r12" > ); > } > @@ -276,7 +281,12 @@ static __always_inline void call_do_irq(struct pt_regs *regs, void *sp) > [callee] "i" (__do_irq) > : // Clobbers > "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6", > - "cr7", "r0", "r4", "r5", "r6", "r7", "r8", "r9", "r10", > + "cr7", "r0", > + /* r2 may be clobbered by the callee when using the ELFv2 ABI */ > +#ifdef CONFIG_PPC_KERNEL_PCREL > + "r2", > +#endif > + "r4", "r5", "r6", "r7", "r8", "r9", "r10", Same > "r11", "r12" > ); > } Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org> ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH v2] powerpc/irq: Fix missing r2 clobber in PCREL inline assembly 2026-07-27 12:09 ` Christophe Leroy (CS GROUP) @ 2026-07-29 16:47 ` Saket Kumar Bhaskar 0 siblings, 0 replies; 3+ messages in thread From: Saket Kumar Bhaskar @ 2026-07-29 16:47 UTC (permalink / raw) To: Christophe Leroy (CS GROUP) Cc: linux-kernel, linuxppc-dev, maddy, mpe, npiggin, segher, hbathini, venkat88, yeswanth On Mon, Jul 27, 2026 at 02:09:12PM +0200, Christophe Leroy (CS GROUP) wrote: > Hi Christophe, thanks for reviewing. > > Le 27/07/2026 à 12:58, Saket Kumar Bhaskar a écrit : > > In CONFIG_PPC_KERNEL_PCREL mode, r2 is no longer reserved for the TOC > > pointer and is available as a caller-saved register [0]. > > > > Both call_do_irq() and call_do_softirq() use inline assembly to call > > functions with stack switching, but fail to list r2 in their clobber > > lists. This causes the compiler to assume r2 is preserved across these > > calls, leading to register corruption when the called functions > > (__do_irq and __do_softirq) clobber r2. > > > > As a result of this kernel crash during interrupt handling is seen and > > the kernel fails to boot: > > > > BUG: Unable to handle kernel data access on write at 0xc000000404697638 > > Faulting instruction address: 0xc0000000000181ec > > Oops: Kernel access of bad area, sig: 11 [#1] > > NIP [c0000000000181ec] __do_IRQ+0x6c/0xc0 > > > > With older GCC, the compiler would conservatively allocate > > callee-saved registers (like r31) for values spanning function calls, > > accidentally avoiding the bug: > > > > <__do_IRQ>: > > 00 00 00 60 nop > > a6 02 08 7c mflr r0 > > f8 ff e1 fb std r31,-8(r1) > > f0 ff c1 fb std r30,-16(r1) > > 2d 03 10 06 pla r31,53297316 > > > > ... > > > > 3d e8 ff 4b bl c0000000000165ac <__do_irq> > > 00 00 21 e8 ld r1,0(r1) > > 28 00 4d e9 ld r10,40(r13) > > 40 00 21 38 addi r1,r1,64 > > 2a f9 aa 7f stdx r29,r10,r31 > > > > With newer GCC 14, the compiler uses r2 for such values, exposing the > > missing clobber specification: > > > > <__do_IRQ>: > > 00 00 00 60 nop > > a6 02 08 7c mflr r0 > > f0 ff c1 fb std r30,-16(r1) > > f8 ff e1 fb std r31,-8(r1) > > 29 02 10 06 pla r2,36252592 # c0000000022aadc0 <__irq_regs> > > > > ... > > > > 85 dc ff 4b bl c000000000015ee0 <__do_irq> > > 00 00 21 e8 ld r1,0(r1) > > 28 00 2d e9 ld r9,40(r13) > > 30 00 21 38 addi r1,r1,48 > > 2a 11 c9 7f stdx r30,r9,r2 > > > > Fix this by adding r2 to the clobber list for both call_do_irq() and > > call_do_softirq() when CONFIG_PPC_KERNEL_PCREL is enabled. > > > > [0]: https://www.mail-archive.com/gcc-patches@gcc.gnu.org/msg313226.html > > > > Fixes: 7e3a68be42e1 ("powerpc/64: vmlinux support building with PCREL addresing") > > Signed-off-by: Saket Kumar Bhaskar <skb99@linux.ibm.com> > > --- > > Changes since v1: > > Addressed comments from Segher: > > * Modified comments to "clobber may happen" > > > > v1: https://lore.kernel.org/all/dc021f42afa10396052499cbeda1772e30b7ca64.1784530547.git.skb99@linux.ibm.com/ > > > > arch/powerpc/kernel/irq.c | 14 ++++++++++++-- > > 1 file changed, 12 insertions(+), 2 deletions(-) > > > > diff --git a/arch/powerpc/kernel/irq.c b/arch/powerpc/kernel/irq.c > > index a0e8b998c9b5..b5343cfd6c9f 100644 > > --- a/arch/powerpc/kernel/irq.c > > +++ b/arch/powerpc/kernel/irq.c > > @@ -218,7 +218,12 @@ static __always_inline void call_do_softirq(const void *sp) > > [callee] "i" (__do_softirq) > > : // Clobbers > > "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6", > > - "cr7", "r0", "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10", > > + "cr7", "r0", > > + /* r2 may be clobbered by the callee when using the ELFv2 ABI */ > > Not sure the comment is correct. You get CONFIG_PPC64_ELF_ABI_V2 without > CONFIG_PPC_KERNEL_PCREL. > > Kconfig help presents CONFIG_PPC_KERNEL_PCREL as an ABI extension. > So considering your comment and Segher's observation https://lore.kernel.org/all/al33jmn9PmMJwYlz@gate/ would be better to reword it as: /* r2 may be clobbered by the callee when using PCREL mode in the ELFv2 ABI. */ > > +#ifdef CONFIG_PPC_KERNEL_PCREL > > + "r2", > > +#endif > > + "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10", > > "r11", "r12" > > To minimise number of small lines I'd prefer something like: > > "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6", "cr7", "r0", > #ifdef CONFIG_PPC_KERNEL_PCREL > "r2", > #endif > "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10", "r11", "r12" > > Noted > > ); > > } > > @@ -276,7 +281,12 @@ static __always_inline void call_do_irq(struct pt_regs *regs, void *sp) > > [callee] "i" (__do_irq) > > : // Clobbers > > "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6", > > - "cr7", "r0", "r4", "r5", "r6", "r7", "r8", "r9", "r10", > > + "cr7", "r0", > > + /* r2 may be clobbered by the callee when using the ELFv2 ABI */ > > +#ifdef CONFIG_PPC_KERNEL_PCREL > > + "r2", > > +#endif > > + "r4", "r5", "r6", "r7", "r8", "r9", "r10", > > Same > Noted > > "r11", "r12" > > ); > > } > > Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org> > > Thanks, Saket ^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-07-29 16:47 UTC | newest] Thread overview: 3+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-07-27 10:58 [PATCH v2] powerpc/irq: Fix missing r2 clobber in PCREL inline assembly Saket Kumar Bhaskar 2026-07-27 12:09 ` Christophe Leroy (CS GROUP) 2026-07-29 16:47 ` Saket Kumar Bhaskar
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox