NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

kern/60819: arm32_kernel_vm_init unconditionally reads pfr1 if CPU_ARM11 or CPU_ARMV7 is enabled alongside CPU_ARM9



>Number:         60819
>Category:       kern
>Synopsis:       arm32_kernel_vm_init unconditionally reads pfr1 if CPU_ARM11 or CPU_ARMV7 is enabled alongside CPU_ARM9
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    kern-bug-people
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Mon Sep 28 18:00:01 +0000 2026
>Originator:     Joe Groff
>Release:        11.0-STABLE
>Organization:
>Environment:
>Description:
The evbarm INTEGRATOR_CP kernel configuration is set up out of the box to support CPU_ARM9, CPU_ARM10, and CPU_ARM11. However, this causes this block of code in arm32_kernel_vm_init to take the ARM11 path and attempt to read the pfr1 control register, which will trap on ARM9 because it doesn't exist there:

```
#ifdef ARM_HAS_VBAR
	const bool map_vectors_p = false;
#elif defined(CPU_ARMV7) || defined(CPU_ARM11)
	const bool map_vectors_p = vectors == ARM_VECTORS_HIGH
	    || (armreg_pfr1_read() & ARM_PFR1_SEC_MASK) == 0;
#else
	const bool map_vectors_p = true;
#endif
```

If CPU_ARM9, ARM9E, or ARM10 is enabled alongside ARM11 or ARMV7, then there should be a conditional check before reading `pfr1`.
>How-To-Repeat:
- Build the kernel with `./build.sh -m evbarm -a earmv5 kernel=INTEGRATOR_CP`.

- Boot the kernel in qemu with something like `qemu-system-arm -machine integratorcp -cpu arm926 -nographic -kernel ../path/to/INTEGRATOR_CP/netbsd`.

The boot will stop quickly after the initial `booting evbarm ...` message.
>Fix:




Home | Main Index | Thread Index | Old Index