nuttx/arch
Marco Casaroli f17c74c626 arch/arm64: Report a recovered user fault as a segmentation fault.
Two problems in the same path make a contained user fault look like a
kernel failure.

arm64_el1_undef() dumps the words around ELR.  For an exception taken
from EL0, ELR is a user address, and the words around it can be in a
page that is not mapped.  Then the memcpy faults inside the fatal
handler.  That nested exception trips the DEBUGASSERT in
arm64_fatal_handler(), and the fault that the user took is not reported.
The ESR that tells what happened is lost.  Skip the dump when the
exception came from EL0.  At EL1 the address is kernel code that was
just fetched, so keep the dump there.

arm64_fatal_handler() then reports the fault that it recovers from as
"PANIC: Unhandled user exception", followed by a full register dump.
But there is no panic: it sets TCB_FLAG_FORCED_CANCEL, changes ELR to
_exit(SIGSEGV), and the system continues without the offending task.
Print "Segmentation fault in <process> (PID n: <thread>)" instead, the
same message as risc-v, and keep the register dump for the
PANIC_WITH_REGS() path, which is fatal.

Tested on QEMU qemu-armv8a:knsh with examples/sandbox and ostest.  A
user read or write of kernel memory (0x40000000) now prints:

  arm64_exception_handler: ESR_ELn: 0x9200000e
  arm64_fatal_handler: Segmentation fault in sandbox (PID 10: sandbox)
  arm64_fatal_handler: Reason: DABT (lower EL) - Data Abort from a ...
  sandbox: the offender exited with status 2816

Before this change it printed "PANIC: Unhandled user exception" and a
register dump for the same recovered fault.  An undefined instruction
at EL0 now prints "Undefined instruction at <ELR>" without the dump,
then the same segmentation fault message.  The shell survives in all
cases, and ostest exits with status 0 before and after this change.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-08 15:51:14 -03:00
..
arm arch/arm/rtl8730e: add I2C master driver support 2026-10-08 15:49:34 -03:00
arm64 arch/arm64: Report a recovered user fault as a segmentation fault. 2026-10-08 15:51:14 -03:00
avr arch, boards, cmake: Build C++ ELF modules without __cxa_atexit. 2026-09-04 15:44:24 -03:00
ceva arch/atomic: remove up_testset in spinlock 2026-09-08 08:58:54 +08:00
dummy
hc tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
mips arch/mips/pic32mz: fix the GPIO_EDGE_RISING pin encoding. 2026-10-08 09:54:07 -03:00
misoc arch, boards, cmake: Build C++ ELF modules without __cxa_atexit. 2026-09-04 15:44:24 -03:00
or1k arch, boards, cmake: Build C++ ELF modules without __cxa_atexit. 2026-09-04 15:44:24 -03:00
renesas nuttx/libc: refine the atomic related Kconfig 2026-08-24 13:20:45 +08:00
risc-v arch/risc-v: Recover from a user fault without a kernel stack. 2026-10-08 15:50:39 -03:00
sim arch/sim/sim_cansock.c: drain all pending TX frames per txavail 2026-10-08 12:13:38 +08:00
sparc arch/atomic: remove up_testset in spinlock 2026-09-08 08:58:54 +08:00
tricore arch/atomic: remove up_testset in spinlock 2026-09-08 08:58:54 +08:00
x86 arch/x86: Add -P to CPP to suppress linemarkers. 2026-09-17 16:21:59 +08:00
x86_64 arch/x86_64: Implement up_addrenv_fork() and provide POSIX fork(). 2026-09-24 18:02:36 -03:00
xtensa espressif: stop leaking a Wi-Fi interrupt handle on every esp_wifi_start() 2026-09-30 13:25:42 -03:00
z16 tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
z80
CMakeLists.txt cmake: Use NUTTX(_DIR/_BIN_DIR) instead CMAKE(_SRC_DIR/_BIN_DIR) 2026-08-09 11:13:08 -03:00
Kconfig arch/arm64: Implement up_addrenv_fork() and provide POSIX fork(). 2026-10-08 09:35:07 -03:00