From: Jiri Slaby <jirislaby@kernel.org>
To: Mike Rapoport <rppt@kernel.org>,
Dave Hansen <dave.hansen@linux.intel.com>
Cc: Andrew Morton <akpm@linux-foundation.org>,
Andy Lutomirski <luto@kernel.org>, Borislav Petkov <bp@alien8.de>,
David CARLIER <devnexen@gmail.com>,
David Hildenbrand <david@kernel.org>,
Ingo Molnar <mingo@redhat.com>, Jason Gunthorpe <jgg@ziepe.ca>,
Juergen Gross <jgross@suse.com>,
Kevin Tian <kevin.tian@intel.com>,
Kiryl Shutsemau <kas@kernel.org>,
"Liam R. Howlett" <liam@infradead.org>,
Lorenzo Stoakes <ljs@kernel.org>,
Lu Baolu <baolu.lu@linux.intel.com>,
Nikunj A Dadhania <nikunj@amd.com>,
Pedro Falcato <pfalcato@suse.de>,
"H. Peter Anvin" <hpa@zytor.com>,
Peter Zijlstra <peterz@infradead.org>,
Shakeel Butt <shakeel.butt@linux.dev>,
Steffen Dirkwinkel <lists@steffen.cc>,
Suren Baghdasaryan <surenb@google.com>,
Thomas Gleixner <tglx@kernel.org>,
Toshi Kani <toshi.kani@hpe.com>,
Vishal Moola <vishal.moola@gmail.com>,
Vlastimil Babka <vbabka@kernel.org>,
Will Deacon <will@kernel.org>,
iommu@lists.linux.dev, linux-kernel@vger.kernel.org,
linux-mm@kvack.org, stable@vger.kernel.org,
syzbot@syzkaller.appspotmail.com, x86@kernel.org
Subject: Re: [PATCH v2 3/5] x86/alternative: exclude text poking against change_page_attr()
Date: Tue, 25 Aug 2026 11:37:50 +0200 [thread overview]
Message-ID: <0a00c5c4-5dca-4957-b4cf-2a52efb2deb1@kernel.org> (raw)
In-Reply-To: <20260813-cpa-fixes-v2-3-39b4ff90f91d@kernel.org>
On 13. 08. 26, 11:01, Mike Rapoport wrote:
> From: Pedro Falcato <pfalcato@suse.de>
>
> From time to time, the following BUG can be observed[0]:
>
>> kernel BUG at arch/x86/kernel/alternative.c:2576!
>> Oops: invalid opcode: 0000 [#1] SMP NOPTI
>> CPU: 0 UID: 0 PID: 355 Comm: (udev-worker) Not tainted 7.1.3-1-default #1 PREEMPT(full) openSUSE Tumbleweed 8c1795b03ec64f997e57a8ad38b1161e3b98da64
>> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS unknown 02/02/2022
>> RIP: 0010:__text_poke+0x2aa/0x450
>> Call Trace:
>> <TASK>
>> smp_text_poke_batch_finish+0x2a7/0x320
>> __static_call_transform+0xb7/0x220
>> arch_static_call_transform+0x5b/0xb0
>> __static_call_init+0xe9/0x270
>> static_call_module_notify+0x11f/0x150
>> notifier_call_chain+0x61/0xe0
>> blocking_notifier_call_chain_robust+0x63/0xc0
>> load_module+0x1c92/0x20c0
>> init_module_from_file+0xd8/0x140
>> idempotent_init_module+0x100/0x2f0
>> __x64_sys_finit_module+0x71/0xe0
>> do_syscall_64+0xe1/0x610
>> entry_SYSCALL_64_after_hwframe+0x76/0x7e
>
> which matches the following BUG_ON in alternative.c:
> /*
> * If something went wrong, crash and burn since recovery paths are not
> * implemented.
> */
> BUG_ON(!pages[0] || (cross_page_boundary && !pages[1]));
>
> This can happen if vmalloc_to_page() fails, for any reason. Such can happen
> if text poking races with CPA, which can possibly result in the collapsing
> of page tables (or breaking of PMD hugepages). It is not a problem for most
> users of vmalloc_to_page() (they solely own the vmalloc'd range) but, when
> CONFIG_ARCH_HAS_EXECMEM_ROX=y, various modules own a single execmem vmalloc
> range, and can call set_memory_*() in parallel on it. This can happen to
> race against __text_poke and cause havoc in vmalloc_to_page().
>
> Fix it by excluding against CPA using the init_mm mmap read lock.
>
> Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support")
> Reported-by: Jiri Slaby <jirislaby@kernel.org>
FWIW
Tested-by: Jiri Slaby <jirislaby@kernel.org>
We have not seen any BUGs since applied to the SUSE's kernel.
https://bugzilla.suse.com/show_bug.cgi?id=1271202#c26
thanks,
--
js
suse labs
next prev parent reply other threads:[~2026-08-25 9:38 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-13 9:01 [PATCH v2 0/5] x86/mm/pat: CPA fixes Mike Rapoport
2026-08-13 9:01 ` [PATCH v2 1/5] x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF Mike Rapoport
2026-08-13 9:01 ` [PATCH v2 2/5] x86/mm/pat: acquire init_mm read lock on attribute change " Mike Rapoport
2026-08-13 9:01 ` [PATCH v2 3/5] x86/alternative: exclude text poking against change_page_attr() Mike Rapoport
2026-08-25 9:37 ` Jiri Slaby [this message]
2026-08-13 9:01 ` [PATCH v2 4/5] x86/mm/pat: allocate split page tables as kernel page tables Mike Rapoport
2026-08-13 9:01 ` [PATCH v2 5/5] x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr() Mike Rapoport (Microsoft)
2026-08-13 9:45 ` Lorenzo Stoakes (ARM)
2026-08-13 15:05 ` [PATCH v2 0/5] x86/mm/pat: CPA fixes Nikunj A. Dadhania
2026-08-13 15:07 ` Lorenzo Stoakes (ARM)
2026-08-13 15:23 ` Pedro Falcato
2026-08-13 17:13 ` Andrew Morton
2026-08-25 7:12 ` Atish Patra
2026-08-25 7:31 ` Lorenzo Stoakes (ARM)
2026-08-25 20:05 ` Atish Patra
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=0a00c5c4-5dca-4957-b4cf-2a52efb2deb1@kernel.org \
--to=jirislaby@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=baolu.lu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=david@kernel.org \
--cc=devnexen@gmail.com \
--cc=hpa@zytor.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@ziepe.ca \
--cc=jgross@suse.com \
--cc=kas@kernel.org \
--cc=kevin.tian@intel.com \
--cc=liam@infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=lists@steffen.cc \
--cc=ljs@kernel.org \
--cc=luto@kernel.org \
--cc=mingo@redhat.com \
--cc=nikunj@amd.com \
--cc=peterz@infradead.org \
--cc=pfalcato@suse.de \
--cc=rppt@kernel.org \
--cc=shakeel.butt@linux.dev \
--cc=stable@vger.kernel.org \
--cc=surenb@google.com \
--cc=syzbot@syzkaller.appspotmail.com \
--cc=tglx@kernel.org \
--cc=toshi.kani@hpe.com \
--cc=vbabka@kernel.org \
--cc=vishal.moola@gmail.com \
--cc=will@kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.