On 22/09/2026 11:59 am, Vladimir Murzin wrote: > Currently MTE selftests assume that they can skip (expected) MTE > faults by advancing the PC by 4 in mte_default_handler(), but this is > not generally safe, as the faults are triggered from arbitrary library > functions (e.g. memset() and memcpy()). For instance, memset() could > be implemented as simple as: > > mov x3, x0 // copy pointer > add x4, x0, x2 // calculate end > loop: > strb w1, [x3], #1 // faulting access > cmp x3, x4 > b.ne loop > ret > > which leads to an infinite loop since X3 could not be updated. > > Or, it could be having advanced implementation (FEAT_MOPS): > > mov x3, x0 // copy pointer > setp [x3]!, x2!, x1 // prologue > setm [x3]!, x2!, x1 // main > sete [x3]!, x2!, x1 // epilogue > ret > > with faulting access at prologue advancing PC to main could lead to > infinite loop due to main could be triggering unaligned access fault > which kernel fixing up by advancing PC back to prologue. > > Address this by introducing memory access helpers with predictable > behavior, allowing faults to be safely handled, and switch the MTE > selftests over to them.
Tested on Pixel 8: Tested-by: Muhammad Usama Anjum <[email protected]> Reviewed-by: Muhammad Usama Anjum <[email protected]> > > Vladimir Murzin (2): > kselftest/arm64/mte: Introduce MTE safe memory accessors > kselftest/arm64/mte: Use MTE safe memory accessors > > .../selftests/arm64/mte/check_buffer_fill.c | 10 ++--- > .../selftests/arm64/mte/check_child_memory.c | 6 +-- > .../arm64/mte/check_hugetlb_options.c | 4 +- > .../selftests/arm64/mte/check_mmap_options.c | 10 ++--- > .../arm64/mte/check_tags_inclusion.c | 4 +- > .../selftests/arm64/mte/mte_common_util.h | 4 ++ > .../testing/selftests/arm64/mte/mte_helper.S | 44 +++++++++++++++++++ > 7 files changed, 65 insertions(+), 17 deletions(-) > -- Thanks, Usama
