From nobody Thu Apr 9 12:08:13 2026 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 45AE035DA41 for ; Mon, 2 Mar 2026 10:54:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772448843; cv=none; b=MYv9jbOYAqzPysYrMRu6gI2WXjsG9HZRugxiVJRRkzdGE25DqUvxYx18vZIQatHz6b9S0XFvFYE48GTlPjzxPOO4p//EvYSpaMHkX7X1KssGPeuzZ4PBZSjIDyMbhPP8RWpVYdGETtE2JXHEOhnEsHzUwxhRkxzzWd5UqQePTVI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772448843; c=relaxed/simple; bh=G9K/hfUGPDsJKP/JccAN6u7KTjQnqlE1JHq0qDmAoF8=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=gzt8NCiqjixjZmEL+WEEsqU10rdAgrWSqA8Fdx6xgXsnsCYsf2+CmLL966wamYzDbuSnOf3mEs7DSqewmsu+ShRJp++lsFpzVBLm0zi289+aq6j/3ai7J7cACyZan4sjX7aMxyxR5I4EQcItdAQrKDYcXNIoj2ImJ/j1t5J+wrk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=YfIASNqY; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=foQueRih; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="YfIASNqY"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="foQueRih" Received: from pps.filterd (m0279869.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 62294k1Q1291356 for ; Mon, 2 Mar 2026 10:53:59 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=qcppdkim1; bh=p/JhN9/z48d DFlvHp8xGdUBIxR1Gv80fZSaR5kiHJV0=; b=YfIASNqYoGkQomrtKy/8g3fHjez ZaAj2H97xT6UjfB9cD3Fnp0GzMXuJ5Iv80IkNwePX+xWYaMUSQVhP/BLSxNVY1AR gtUVxS78x6jYsF8GLaa05Nkv6ED/9nVME8qA1C8lSICmfDKRaii8dQ6ObXd0JN6y gn9/hq+bd6Hbs1YUKhXHB7k137xtlfNmppim4u7wS4Inw8RcjQ+hrqx9N4fWE//G XScS2rVnBaiKWDHhDMhsM8uDUqezutrID84NUnJQvtXbN6TMhlcEAPq9j71m02Fz XU4Qjj8GhrCsepVPNdXC/J8aUmZiswYN8cDcSj9OUtEpDXaIpC/wWebedtA== Received: from mail-pl1-f199.google.com (mail-pl1-f199.google.com [209.85.214.199]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4cn7ku0ctc-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Mon, 02 Mar 2026 10:53:58 +0000 (GMT) Received: by mail-pl1-f199.google.com with SMTP id d9443c01a7336-2ae48a21d12so9209435ad.1 for ; Mon, 02 Mar 2026 02:53:58 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1772448838; x=1773053638; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=p/JhN9/z48dDFlvHp8xGdUBIxR1Gv80fZSaR5kiHJV0=; b=foQueRihCGEhf7/fB946YQAk8DbyUWKLY0xy6gupbfxzL7MmUDTOSgC6ItNi5ypagI Sw74JFWVChvQxvY87VR7Y1lazAABtL7l/4G4rvtgXRq2DXKKpr/nLFrtAamH07hCY0xO VnbFz8BRb+16a1w9l2JfdtlbRpO28FARvvT+ISWtlp++Gw5WhZjHOq3QH8mTEG0CycUo VPnarE6R6QofLo0/donno274oAcvZtGH6kRzUmsb++i3Dymnn1NB/WFdNSEOP1QVu1G/ 2SV2dPJMagJ7c+PsPNV0ElUbsEIHa8uyDBRvN1aZ8TSZgMxsppAhEHWbX4nmqXQn/T2e h7dg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772448838; x=1773053638; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=p/JhN9/z48dDFlvHp8xGdUBIxR1Gv80fZSaR5kiHJV0=; b=nnZ1UuVSY4NyLCKhL/qn7rhANDqikINinSQphW7TszBpQgObbwBHWJOvmU4lhtkYVw Zc2g/g0Etu63kBFVL4fDFdVAyH8H2fN+nLUIlXbAgAy/2likFVgcYLTKtw+p0AwePy/S onR2LsG0nrml86se9IGGDPAue8q+n7Q0xXidKCsEANiU8QdDWQwrfsEMehOdWjuHfv01 i2myWK+XqJWS8kMZhXAhrNtfFyPAAz0fbvZwNXl+rbt3W4ogQyWQB+x346AE8gn6JlsY O7RVvS2iRDhDVzxq01pHVuaHbcYRjPc9IIS/G5ksvF3yR+XBLSVnt8spk8x1pnWvZIpm J6KQ== X-Forwarded-Encrypted: i=1; AJvYcCV5/NXyCzK5ibvNbEnMr+z6nVTyMPq+1qfGPJG1403YsVlYntYc9XcLpF0G25xSOB0kXb/tfKDh4XWBHjA=@vger.kernel.org X-Gm-Message-State: AOJu0Yytz3WfGccKR83IMXrzmtSSlEs8CaaLBeD+ZXcpI6ppmiIScsAT tolGedRziDsThFObt7dq+64ZLxEimz6j3ReGm6TbMtEbv7A7RzKmvV+DLpA62kh7nl9A48VoRt5 Up4YwzXU5h9HiGYLP0WS1vzcP/j2+f56gBA0eHIWCAQwpqmEAXDscXRKQxGqeluEEwuE= X-Gm-Gg: ATEYQzzRY+i8yiUcNGvpjjyGNAO6Ker5qlURTO+7fz+vMzBFt4ernCoLBwodG/TO2Ww CPJiKcwsnJZH6wzEn75UTS8PLjXxOLNa+RhaVXacVH7DYg4Nrqhbx/HlNboJrAVpVQfgx6RO1TO gD3C5RnjioR6hA04OGMi4zi8t/YVlv3x+UXLTTob8ZCAYGwsckCdCOp1JjGx78vXZ2RzeazuLi6 ennWO4IjtmgEv3EQ4WuVqWcJrb57VhHTF3MvZ3XZd2Tcgg6NdFkNnXFNZWhxp8lmVadtnVgj8mR LhukIHFa9T8hgSB/Lo7Xab6tOcLe276EmdeBl1LQkk12573nXCqM/lAxZmfJLvmOS4hezKqeZcw rhGP5bi/fersuScFO7Y2Jj7nd0cqDvqAXWKGl/CQU9y5vlKqqsPdf X-Received: by 2002:a05:6a20:3ca8:b0:364:33f7:7338 with SMTP id adf61e73a8af0-395c39de575mr9990028637.8.1772448837816; Mon, 02 Mar 2026 02:53:57 -0800 (PST) X-Received: by 2002:a05:6a20:3ca8:b0:364:33f7:7338 with SMTP id adf61e73a8af0-395c39de575mr9990008637.8.1772448837260; Mon, 02 Mar 2026 02:53:57 -0800 (PST) Received: from hu-kshaikkh-hyd.qualcomm.com ([202.46.23.25]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-c70fa632ddesm11847479a12.13.2026.03.02.02.53.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 02 Mar 2026 02:53:56 -0800 (PST) From: Khaja Hussain Shaik Khaji To: mark.rutland@arm.com Cc: ada.coupriediaz@arm.com, catalin.marinas@arm.com, dev.jain@arm.com, linux-arm-kernel@lists.infradead.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, mhiramat@kernel.org, will@kernel.org, yang@os.amperecomputing.com Subject: [PATCH v3 1/1] kernel: kprobes: fix cur_kprobe corruption during re-entrant kprobe_busy_begin() calls Date: Mon, 2 Mar 2026 16:23:47 +0530 Message-Id: <20260302105347.3602192-2-khaja.khaji@oss.qualcomm.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260302105347.3602192-1-khaja.khaji@oss.qualcomm.com> References: <20260302105347.3602192-1-khaja.khaji@oss.qualcomm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Authority-Analysis: v=2.4 cv=V4NwEOni c=1 sm=1 tr=0 ts=69a56c46 cx=c_pps a=JL+w9abYAAE89/QcEU+0QA==:117 a=ZePRamnt/+rB5gQjfz0u9A==:17 a=Yq5XynenixoA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_glEPmIy2e8OvE2BGh3C:22 a=EUspDBNiAAAA:8 a=7l7XfnHKCA38VmfCrlUA:9 a=324X-CrmTo6CU4MGRt3R:22 X-Proofpoint-GUID: 6arOIehqL4gtViZte-8whzSh_oHfNYpw X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwMzAyMDA4OCBTYWx0ZWRfX6kVEz5a9sSmV BSCWy8YvGlFb2NngrukanzADHpHXl7KfUcNZ3EInxy/10TS6nli4ZjDVsqWL1jDe6lzj3GFmclU /r2VzeEbnvHzTtMVgA6WNTpium4sutJQPt55DcJgSVLQbDoCoqgmMryqa0r5GNaZyo/O/ygsA3E 4qDuIIWMx5pZm/QMRf1ZTeIm/5ZUfTuQEtQexHkmeR2R+J3mM9DhyGBTfGDyliBpJjX7Ek+Go5B 3OLXrO/k/ST4y11lTsy4Az5V2+/6doZgzr9yY9aCBW0b9YCpG37ye6qXXQszmpVhqDhsdUE46gE eean063bjVQHkBpdIm5JYKVSJWf9mFb6c7sjSxgsNkSwqSnATzPxDzf1Rf/rW837fIzXUr836Kl 5XHE/UWailaPQCz06qTgTVUKs9He0rtpg5EV2bnPgd+5IGhZGnz00IuxCiRyDl5CvFdGlQGRQ/P XqTbvo35qcU1/HkSXlA== X-Proofpoint-ORIG-GUID: 6arOIehqL4gtViZte-8whzSh_oHfNYpw X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1121,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-03-02_03,2026-02-27_03,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 suspectscore=0 malwarescore=0 phishscore=0 lowpriorityscore=0 priorityscore=1501 adultscore=0 bulkscore=0 spamscore=0 impostorscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2602130000 definitions=main-2603020088 Content-Type: text/plain; charset="utf-8" Fix cur_kprobe corruption that occurs when kprobe_busy_begin() is called re-entrantly during an active kprobe handler. Previously, kprobe_busy_begin() unconditionally overwrites current_kprobe with &kprobe_busy, and kprobe_busy_end() writes NULL. This approach works correctly when no kprobe is active but fails during re-entrant calls. On arm64, arm64_enter_el1_dbg() re-enables IRQs before invoking kprobe handlers. This allows an IRQ during kretprobe entry_handler to trigger kprobe_flush_task() via softirq, which calls kprobe_busy_begin/end and corrupts cur_kprobe. Problem flow: kretprobe entry_handler -> IRQ -> softirq -> kprobe_flush_task -> kprobe_busy_begin/end -> cur_kprobe corruption. This corruption causes two issues: 1. NULL cur_kprobe in setup_singlestep leading to panic in single-step handler 2. kprobe_status overwritten with HIT_ACTIVE during execute-out-of-line window Implement a per-CPU re-entrancy tracking mechanism with: - A depth counter to track nested calls - Saved state for current_kprobe and kprobe_status - Save state on first entry, restore on final exit - Increment depth counter for nested calls only This approach maintains compatibility with existing callers as save/restore of NULL is a no-op. Signed-off-by: Khaja Hussain Shaik Khaji --- kernel/kprobes.c | 34 ++++++++++++++++++++++++++++++---- 1 file changed, 30 insertions(+), 4 deletions(-) diff --git a/kernel/kprobes.c b/kernel/kprobes.c index e2cd01cf5968..47a4ae50ee6c 100644 --- a/kernel/kprobes.c +++ b/kernel/kprobes.c @@ -70,6 +70,15 @@ static bool kprobes_all_disarmed; static DEFINE_MUTEX(kprobe_mutex); static DEFINE_PER_CPU(struct kprobe *, kprobe_instance); =20 +/* Per-CPU re-entrancy state for kprobe_busy_begin/end. + * kprobe_busy_begin() may be called while a kprobe handler + * is active - e.g. kprobe_flush_task() via softirq during + * kretprobe entry_handler on arm64 where IRQs are re-enabled. + */ +static DEFINE_PER_CPU(int, kprobe_busy_depth); +static DEFINE_PER_CPU(struct kprobe *, kprobe_busy_saved_current); +static DEFINE_PER_CPU(unsigned long, kprobe_busy_saved_status); + kprobe_opcode_t * __weak kprobe_lookup_name(const char *name, unsigned int __unused) { @@ -1307,14 +1316,31 @@ void kprobe_busy_begin(void) struct kprobe_ctlblk *kcb; =20 preempt_disable(); - __this_cpu_write(current_kprobe, &kprobe_busy); - kcb =3D get_kprobe_ctlblk(); - kcb->kprobe_status =3D KPROBE_HIT_ACTIVE; + if (__this_cpu_read(kprobe_busy_depth) =3D=3D 0) { + kcb =3D get_kprobe_ctlblk(); + __this_cpu_write(kprobe_busy_saved_current, + __this_cpu_read(current_kprobe)); + __this_cpu_write(kprobe_busy_saved_status, + kcb->kprobe_status); + __this_cpu_write(current_kprobe, &kprobe_busy); + kcb->kprobe_status =3D KPROBE_HIT_ACTIVE; + } + __this_cpu_inc(kprobe_busy_depth); } =20 void kprobe_busy_end(void) { - __this_cpu_write(current_kprobe, NULL); + struct kprobe_ctlblk *kcb; + + __this_cpu_dec(kprobe_busy_depth); + + if (__this_cpu_read(kprobe_busy_depth) =3D=3D 0) { + kcb =3D get_kprobe_ctlblk(); + __this_cpu_write(current_kprobe, + __this_cpu_read(kprobe_busy_saved_current)); + kcb->kprobe_status =3D + __this_cpu_read(kprobe_busy_saved_status); + } preempt_enable(); } =20 --=20 2.34.1