nuttx/arch
Marco Casaroli baeedc5009 arch/arm64: Synchronize the TTBR0 write before the TLB invalidation.
mmu_write_ttbr0() writes TTBR0_EL1 and then invalidates the TLB.  A write
to TTBR0_EL1 takes effect only at the next context synchronization event,
so until the ISB at the end of the invalidation, a table walk can still
use the old table.  The instruction fetches of the invalidation sequence
itself do such walks.  An entry that they cache after the TLBI completes
stays valid: walk cache entries are not tagged with the table base, and
the kernel and every process use ASID 0.

A kernel build then translates a user address of the new process through
a level 0 entry of the old table, and gets a level 1 translation fault.
Under QEMU with HVF on Apple silicon this happens on every boot of
qemu-armv8a:knsh: up_addrenv_va_to_pa() fails for the first user buffer,
and virtio gets a descriptor with address 0.  TCG has no walk caches, so
it does not show the problem.

Add an ISB after the write, as the Arm ARM sequence for a TTBR change
without an ASID change requires: write, ISB, TLBI, DSB, ISB.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-08 15:55:02 -03:00
..
arm arch/arm/rp23xx: Clear the DMA callback before invoking it. 2026-10-08 15:53:54 -03:00
arm64 arch/arm64: Synchronize the TTBR0 write before the TLB invalidation. 2026-10-08 15:55:02 -03:00
avr arch, boards, cmake: Build C++ ELF modules without __cxa_atexit. 2026-09-04 15:44:24 -03:00
ceva arch/atomic: remove up_testset in spinlock 2026-09-08 08:58:54 +08:00
dummy
hc tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
mips arch/mips/pic32mz: fix the GPIO_EDGE_RISING pin encoding. 2026-10-08 09:54:07 -03:00
misoc arch, boards, cmake: Build C++ ELF modules without __cxa_atexit. 2026-09-04 15:44:24 -03:00
or1k arch, boards, cmake: Build C++ ELF modules without __cxa_atexit. 2026-09-04 15:44:24 -03:00
renesas nuttx/libc: refine the atomic related Kconfig 2026-08-24 13:20:45 +08:00
risc-v arch/risc-v: Recover from a user fault without a kernel stack. 2026-10-08 15:50:39 -03:00
sim arch/sim/sim_cansock.c: drain all pending TX frames per txavail 2026-10-08 12:13:38 +08:00
sparc arch/atomic: remove up_testset in spinlock 2026-09-08 08:58:54 +08:00
tricore arch/atomic: remove up_testset in spinlock 2026-09-08 08:58:54 +08:00
x86 arch/x86: Add -P to CPP to suppress linemarkers. 2026-09-17 16:21:59 +08:00
x86_64 arch/x86_64: Kill only the offending task on a user-space fault. 2026-10-08 15:51:41 -03:00
xtensa espressif: stop leaking a Wi-Fi interrupt handle on every esp_wifi_start() 2026-09-30 13:25:42 -03:00
z16 tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
z80
CMakeLists.txt cmake: Use NUTTX(_DIR/_BIN_DIR) instead CMAKE(_SRC_DIR/_BIN_DIR) 2026-08-09 11:13:08 -03:00
Kconfig arch/arm64: Implement up_addrenv_fork() and provide POSIX fork(). 2026-10-08 09:35:07 -03:00