From 88fae8bdd70bfa0983b02fb3272c947df0bdc621 Mon Sep 17 00:00:00 2001 From: "awilliam@xenbuild.aw" Date: Fri, 23 Jun 2006 15:24:06 -0600 Subject: [PATCH] [IA64] fix RSE issues rlated to handle_lazy_cover(). It must be after trying vTLB in ia64_do_page_fault(). This patch fixes the following scenario. linux-2.6-xen-sparse/arch/ia64/xen/xenentry.S Here psr.i and psr.ic is off rse_clear_invalid: ... (pRecurse) br.call.dptk.few b0=rse_clear_invalid ;; mov loc8=0 mov loc9=0 1. Right before mov loc8=0, vcpu is switched to another cpu. 2. While the vcpu is waiting for cpu, the tlb entry which backs the rse stack is purged. 3. The vcpu gets cpu again, tlb miss fault occurs with isr.ir = 1. 4. xen ia64_do_page_fault() calls handle_lazy_cover() which sets cr.ifs = 0. 5. xen returns cpu execution to the guest. 6. mov loc8 = 0 is executed with cfm = 0. Illigal operation fault is raised 7. priv_handle_op() is called. but it fails to emulate because mov loc8 = 0 isn't privileged op. 8. ia64_handle_privop() calls panic_domain(). Signed-off-by: Xu, Anthony Signed-off-by: Isaku Yamahata --- xen/arch/ia64/xen/faults.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/xen/arch/ia64/xen/faults.c b/xen/arch/ia64/xen/faults.c index 5c2981dbab..ac16d3a32e 100644 --- a/xen/arch/ia64/xen/faults.c +++ b/xen/arch/ia64/xen/faults.c @@ -218,7 +218,6 @@ void ia64_do_page_fault (unsigned long address, unsigned long isr, struct pt_reg int is_ptc_l_needed = 0; u64 logps; - if ((isr & IA64_ISR_IR) && handle_lazy_cover(current, regs)) return; if ((isr & IA64_ISR_SP) || ((isr & IA64_ISR_NA) && (isr & IA64_ISR_CODE_MASK) == IA64_ISR_CODE_LFETCH)) { @@ -269,6 +268,10 @@ void ia64_do_page_fault (unsigned long address, unsigned long isr, struct pt_reg } return; } + + if ((isr & IA64_ISR_IR) && handle_lazy_cover(current, regs)) + return; + if (!PSCB(current,interrupt_collection_enabled)) { check_bad_nested_interruption(isr,regs,fault); //printf("Delivering NESTED DATA TLB fault\n"); -- 2.30.2