On 2026-07-07, "Mukesh Kumar Chaurasiya (IBM)" <[email protected]> wrote: > On PowerMac G5 (PPC970, CONFIG_PPC_970_NAP) the system panics shortly > after boot with symptoms including instruction fetch faults, kernel data > access faults, and stack corruption, predominantly on SMP and always > somewhere inside softirq processing. > > The PPC970 idle path works by setting _TLF_NAPPING in the current > thread's local flags before entering the MSR_POW nap loop. When any > async interrupt wakes the CPU, nap_adjust_return() is expected to detect > _TLF_NAPPING, clear it, and rewrite regs->NIP to power4_idle_nap_return > so that the interrupt returns cleanly to the caller of power4_idle_nap() > rather than back into the nap spin loop. > > DEFINE_INTERRUPT_HANDLER_ASYNC generates the following sequence: > > irq_enter_rcu(); > ____func(regs); /* timer_interrupt / do_IRQ body */ > irq_exit_rcu(); /* softirqs run here, irqs re-enabled */ > arch_interrupt_async_exit_prepare(regs); /* nap_adjust_return was here */ > irqentry_exit(regs, state); > > irq_exit_rcu() calls invoke_softirq() -> do_softirq_own_stack(), which > runs softirqs with hardware interrupts re-enabled. A nested async > interrupt can therefore arrive while _TLF_NAPPING is still set. That > nested interrupt reaches nap_adjust_return() in its own > arch_interrupt_async_exit_prepare() call, finds _TLF_NAPPING set, and > redirects *its own* regs->NIP to power4_idle_nap_return. Returning via > that blr with an unrelated LR on the softirq stack jumps to a garbage > address, causing the observed crashes. > > The comment that previously lived in arch_interrupt_async_exit_prepare() > even described this exact hazard ("must come before irq_exit()"), but > nap_adjust_return() was placed after irq_exit_rcu() in the macro, so > the protection was never effective. > > Fix this by calling nap_adjust_return() inside DEFINE_INTERRUPT_HANDLER_ASYNC > immediately before irq_exit_rcu(), ensuring _TLF_NAPPING is cleared and > regs->NIP is adjusted before any code that can re-enable interrupts or > invoke softirqs runs. Move the explanatory comment into > nap_adjust_return() itself and remove it from > arch_interrupt_async_exit_prepare(). > > Fixes: bee25f97ad24 ("powerpc: Enable GENERIC_ENTRY feature") > Closes: https://lore.kernel.org/all/[email protected]/ > Reported-by: Andreas Schwab <[email protected]> > Signed-off-by: Mukesh Kumar Chaurasiya (IBM) <[email protected]>
Tested-by: John Ogness <[email protected]> Would be nice to see this in 7.2-rc4
