Skip to content

Commit 7dcd9dd

Browse files
kristina-martsenkoctmarinas
authored andcommitted
arm64: hw_breakpoint: fix watchpoint matching for tagged pointers
When we take a watchpoint exception, the address that triggered the watchpoint is found in FAR_EL1. We compare it to the address of each configured watchpoint to see which one was hit. The configured watchpoint addresses are untagged, while the address in FAR_EL1 will have an address tag if the data access was done using a tagged address. The tag needs to be removed to compare the address to the watchpoints. Currently we don't remove it, and as a result can report the wrong watchpoint as being hit (specifically, always either the highest TTBR0 watchpoint or lowest TTBR1 watchpoint). This patch removes the tag. Fixes: d50240a ("arm64: mm: permit use of tagged pointers at EL0") Cc: <[email protected]> # 3.12.x- Acked-by: Mark Rutland <[email protected]> Acked-by: Will Deacon <[email protected]> Signed-off-by: Kristina Martsenko <[email protected]> Signed-off-by: Catalin Marinas <[email protected]>
1 parent 81cddd6 commit 7dcd9dd

File tree

2 files changed

+6
-3
lines changed

2 files changed

+6
-3
lines changed

arch/arm64/include/asm/uaccess.h

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -106,9 +106,9 @@ static inline void set_fs(mm_segment_t fs)
106106
})
107107

108108
/*
109-
* When dealing with data aborts or instruction traps we may end up with
110-
* a tagged userland pointer. Clear the tag to get a sane pointer to pass
111-
* on to access_ok(), for instance.
109+
* When dealing with data aborts, watchpoints, or instruction traps we may end
110+
* up with a tagged userland pointer. Clear the tag to get a sane pointer to
111+
* pass on to access_ok(), for instance.
112112
*/
113113
#define untagged_addr(addr) sign_extend64(addr, 55)
114114

arch/arm64/kernel/hw_breakpoint.c

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,7 @@
3636
#include <asm/traps.h>
3737
#include <asm/cputype.h>
3838
#include <asm/system_misc.h>
39+
#include <asm/uaccess.h>
3940

4041
/* Breakpoint currently in use for each BRP. */
4142
static DEFINE_PER_CPU(struct perf_event *, bp_on_reg[ARM_MAX_BRP]);
@@ -721,6 +722,8 @@ static u64 get_distance_from_watchpoint(unsigned long addr, u64 val,
721722
u64 wp_low, wp_high;
722723
u32 lens, lene;
723724

725+
addr = untagged_addr(addr);
726+
724727
lens = __ffs(ctrl->len);
725728
lene = __fls(ctrl->len);
726729

0 commit comments

Comments
 (0)