From: sashiko-bot@kernel.org
To: "Yeoreum Yun" <yeoreum.yun@arm.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH RFC v2 07/20] mm/pgtable: define (pgd|p4d|pud)_offset_lockless() for folded page tables
Date: Wed, 22 Jul 2026 15:58:49 +0000 [thread overview]
Message-ID: <20260722155849.85FF41F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260722-dummy_ptxp3-v2-7-d9e4bad31e0a@arm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [Critical] Use-After-Free in GUP-fast on dynamically folded architectures (RISC-V SV39) due to flawed generic lockless page table offset macros.
--
--- Patch [7]: [PATCH RFC v2 07/20] mm/pgtable: define (pgd|p4d|pud)_offset_lockless() for folded page tables ---
commit 235a6b06e94a41ff4c56118e36e869516151cea9
Author: David Hildenbrand (Arm) <david@kernel.org>
mm/pgtable: define (pgd|p4d|pud)_offset_lockless() for folded page tables
The patch provides p4d_offset_lockless(), pmd_offset_lockless(), and
pud_offset_lockless() for static folded page tables to ignore the passed
value and return the pointer. This avoids returning a pointer to the stack
value like the default handlers do.
> diff --git a/include/asm-generic/pgtable-nopud.h b/include/asm-generic/pgtable-nopud.h
> index 6c9bca78047c4..5a2b0a81ae197 100644
> --- a/include/asm-generic/pgtable-nopud.h
> +++ b/include/asm-generic/pgtable-nopud.h
[ ... ]
> @@ -47,6 +47,13 @@ static inline pud_t *pud_offset(p4d_t *p4d, unsigned long address)
> }
> #define pud_offset pud_offset
>
> +static inline pud_t *pud_offset_lockless(p4d_t *p4dp, p4d_t p4d,
> + unsigned long address)
> +{
> + return (pud_t *)p4dp;
> +}
> +#define pud_offset_lockless pud_offset_lockless
[Severity: Critical]
This is a pre-existing issue, but does this fix leave dynamically folded
architectures like RISC-V SV39 vulnerable to a use-after-free?
The generic fallback macro in include/linux/pgtable.h still passes the address
of a local stack variable:
#define pud_offset_lockless(p4dp, p4d, address) pud_offset(&(p4d), address)
On RISC-V SV39, PUD is folded dynamically in arch/riscv/mm/pgtable.c:
pud_t *pud_offset(p4d_t *p4d, unsigned long address)
{
if (pgtable_l4_enabled)
return p4d_pgtable(p4dp_get(p4d)) + pud_index(address);
return (pud_t *)p4d;
}
Since pgtable_l4_enabled is false on SV39, pud_offset() returns the pointer it
was passed, which is the stack pointer from the generic pud_offset_lockless()
macro.
When gup_fast_pud_leaf() in mm/gup.c executes its concurrent modification
check, it reads the stale stack variable instead of the actual page table:
if (unlikely(pud_val(orig) != pud_val(pudp_get(pudp)))) {
gup_put_folio(folio, refs, flags);
return 0;
}
Because it reads the isolated stack variable, the check trivially passes,
allowing GUP-fast to pin and return a concurrently freed 1GB huge page.
Could a similar lockless override be applied for dynamically folded
architectures to prevent this?
> +
> #define pud_val(x) (p4d_val((x).p4d))
> #define __pud(x) ((pud_t) { __p4d(x) })
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260722-dummy_ptxp3-v2-0-d9e4bad31e0a@arm.com?part=7
next prev parent reply other threads:[~2026-07-22 15:58 UTC|newest]
Thread overview: 124+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 15:30 [PATCH RFC v2 00/20] mm: optimize unnecessary loads due to ptep_get() and friends out Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 01/20] ARM: mm: make nommu pgd_t a scalar Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 02/20] ARM: mm: make 2-level " Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 03/20] ARM: mm: remove custom pgdp_get() Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 04/20] LoongArch: mm: define pud_leaf() only when PUD exists Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 05/20] MIPS: " Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 06/20] mm/pgtable: define (pgd|p4d|pud)_leaf() for folded page tables Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:51 ` sashiko-bot
2026-07-22 15:30 ` [PATCH RFC v2 07/20] mm/pgtable: define (pgd|p4d|pud)_offset_lockless() " Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:58 ` sashiko-bot [this message]
2026-07-22 19:25 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 08/20] mm: vmscan: remove stack copy address of pud pass in wallk_pud_range() Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:56 ` sashiko-bot
2026-07-22 19:31 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 09/20] loongarch: kvm: remove stack copy address of pXd in pXd_offset() Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:53 ` sashiko-bot
2026-07-22 19:51 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 10/20] riscv: " Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 11/20] riscv: mm: use proper set_pXd() for generic compile-time folded patable in vmalloc_fault() Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 12/20] x86: mm: define pudp_set_access_flags() when CONFIG_HAVE_ARCH_TRANSPARENT_HUGEPAGE_PUD is enabled only Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 16:02 ` Dave Hansen
2026-07-22 16:02 ` Dave Hansen
2026-07-22 16:02 ` Dave Hansen
2026-07-22 17:27 ` Yeoreum Yun
2026-07-22 17:27 ` Yeoreum Yun
2026-07-22 17:27 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 13/20] x86: mm: carve out the generic compile-time folded pgtable case in effective_prot() Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 16:07 ` sashiko-bot
2026-07-22 16:23 ` Yeoreum Yun
2026-07-22 16:11 ` Dave Hansen
2026-07-22 16:11 ` Dave Hansen
2026-07-22 16:11 ` Dave Hansen
2026-07-22 16:28 ` Yeoreum Yun
2026-07-22 16:28 ` Yeoreum Yun
2026-07-22 16:28 ` Yeoreum Yun
2026-07-22 17:37 ` Yeoreum Yun
2026-07-22 17:37 ` Yeoreum Yun
2026-07-22 17:37 ` Yeoreum Yun
2026-07-22 20:20 ` Dave Hansen
2026-07-22 20:20 ` Dave Hansen
2026-07-22 20:20 ` Dave Hansen
2026-07-22 21:00 ` Yeoreum Yun
2026-07-22 21:00 ` Yeoreum Yun
2026-07-22 21:00 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 14/20] x86: mm: skip pud setup when using generic compile-time folded pagetable Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 16:18 ` sashiko-bot
2026-07-22 19:08 ` Yeoreum Yun
2026-07-22 16:33 ` Dave Hansen
2026-07-22 16:33 ` Dave Hansen
2026-07-22 16:33 ` Dave Hansen
2026-07-22 17:18 ` Yeoreum Yun
2026-07-22 17:18 ` Yeoreum Yun
2026-07-22 17:18 ` Yeoreum Yun
2026-07-22 20:02 ` Dave Hansen
2026-07-22 20:02 ` Dave Hansen
2026-07-22 20:02 ` Dave Hansen
2026-07-22 20:18 ` Yeoreum Yun
2026-07-22 20:18 ` Yeoreum Yun
2026-07-22 20:18 ` Yeoreum Yun
2026-07-22 20:22 ` Dave Hansen
2026-07-22 20:22 ` Dave Hansen
2026-07-22 20:22 ` Dave Hansen
2026-07-22 20:28 ` H. Peter Anvin
2026-07-22 20:28 ` H. Peter Anvin
2026-07-22 20:28 ` H. Peter Anvin
2026-07-22 20:40 ` Yeoreum Yun
2026-07-22 20:40 ` Yeoreum Yun
2026-07-22 20:40 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 15/20] mm/pgtable: optimize pmdp_get() and friends for folded pagetable levels Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 16:15 ` sashiko-bot
2026-07-22 19:44 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 16/20] mm/pgtable: catch abuse of folded dummy pgd_t/p4d_t/pud_t Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 17/20] mm/pgtable: disallow calling (pgd|p4d|pud)_page, pgd_page_vaddr() and (p4d|pud)_pgtable with dummy Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 18/20] mm/pgtable: disallow calling folded set_pgd/set_p4d/set_pud " Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 19/20] openrisc/pgtable: drop __pmd_offset() Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 20/20] arm64: pgtable: convert pte_present() from macro to static inline Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 16:40 ` [PATCH RFC v2 00/20] mm: optimize unnecessary loads due to ptep_get() and friends out Dave Hansen
2026-07-22 16:40 ` Dave Hansen
2026-07-22 16:40 ` Dave Hansen
2026-07-22 17:30 ` Yeoreum Yun
2026-07-22 17:30 ` Yeoreum Yun
2026-07-22 17:30 ` Yeoreum Yun
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260722155849.85FF41F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=yeoreum.yun@arm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.