Sitelet https://github.com/ish-app/ish/pull/2816
Skip to content

Raise SIGBUS for an unaligned lock cmpxchg8b - #2816

Open
emkey1 wants to merge 1 commit into
ish-app:masterfrom
emkey1:unaligned_cmpxchg8b_sigbus
Open

emkey1 wants to merge 1 commit into
ish-app:masterfrom
emkey1:unaligned_cmpxchg8b_sigbus

Conversation

@emkey1

@emkey1 emkey1 commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

On aarch64, lock cmpxchg8b on an address that isn't 8-byte aligned branches to segfault_write. That exit reports tlb->segfault_addr, but nothing on this path sets it, so the fault carries whatever address is left over:

  • If that address is mapped, the page-fault handler has nothing to do and the instruction retries forever, at 100% CPU.
  • If it isn't, the guest gets a SIGSEGV for an unrelated address.

Python 3.14, which Alpine 3.24 ships, hits this at startup and does either one, depending on what was left there.

As discussed in #2813, this raises SIGBUS instead, with BUS_ADRALN and the operand's address. The x86_64 host's gadget uses the host's own lock cmpxchg8b and is unchanged.

Tested on an arm64 Mac with the Alpine 3.24 x86 rootfs:

  • An unaligned __atomic_fetch_add on a uint64_t gets SIGBUS, with si_code 1 and si_addr at the operand.
  • The aligned case is unaffected.
  • python3 now exits with "Bus error" instead of hanging or segfaulting.

🤖 Generated with Claude Code

The aarch64 gadget sent it to segfault_write, which reports
tlb->segfault_addr, but nothing on that path set it. The fault carried a
stale address: if mapped, the instruction retried forever; if not, the
guest got a SIGSEGV for an unrelated address. Raise SIGBUS (BUS_ADRALN)
at the operand instead.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants