All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Yeoreum Yun" <yeoreum.yun@arm.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH RFC v2 13/20] x86: mm: carve out the generic compile-time folded pgtable case in effective_prot()
Date: Wed, 22 Jul 2026 16:07:53 +0000	[thread overview]
Message-ID: <20260722160753.C48291F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260722-dummy_ptxp3-v2-13-d9e4bad31e0a@arm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] `effective_prot()` incorrectly stores dummy values from folded page table entries instead of ignoring them, breaking protection inheritance and silently disabling W+X security checks.
--

--- Patch [13]: [PATCH RFC v2 13/20] x86: mm: carve out the generic compile-time folded pgtable case in effective_prot() ---
commit 11eb6cce58717a2c22f41583089bb3b0105af585
Author: David Hildenbrand (Arm) <david@kernel.org>

x86: mm: carve out the generic compile-time folded pgtable case in effective_prot()

This commit introduces ptdump_pt_level_first() to identify the first
real page-table level for compile-time folded page tables. It modifies
effective_prot() to skip updating higher_prot for folded or top-level
entries, aiming to ignore dummy values from folded page table levels.

> diff --git a/arch/x86/mm/dump_pagetables.c b/arch/x86/mm/dump_pagetables.c
> index 2afa7a23340e9..4e545988953a0 100644
> --- a/arch/x86/mm/dump_pagetables.c
> +++ b/arch/x86/mm/dump_pagetables.c
[ ... ]
> @@ -254,7 +255,7 @@ static void effective_prot(struct ptdump_state *pt_st, int level, u64 val)
>  	pgprotval_t prot = val & PTE_FLAGS_MASK;
>  	pgprotval_t effective;
>  
> -	if (level > 0) {
> +	if (level > st->first_level) {
>  		pgprotval_t higher_prot = st->prot_levels[level - 1];
>  
>  		effective = (higher_prot & prot & (_PAGE_USER | _PAGE_RW)) |

[Severity: High]
When dealing with a folded level (where level <= st->first_level), the code
falls through to the else branch (effective = prot). Since folded levels use
a dummy value, prot lacks _PAGE_RW.

When the walker reaches the first real intermediate level, higher_prot reads
this dummy value from st->prot_levels[level - 1]. Since it lacks _PAGE_RW,
won't the bitwise AND clear the _PAGE_RW bit for all subsequent levels?

Could this cause ptdump_check_wx() to evaluate all pages as read-only and
silently pass, hiding W+X security vulnerabilities?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260722-dummy_ptxp3-v2-0-d9e4bad31e0a@arm.com?part=13

  reply	other threads:[~2026-07-22 16:07 UTC|newest]

Thread overview: 124+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-22 15:30 [PATCH RFC v2 00/20] mm: optimize unnecessary loads due to ptep_get() and friends out Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 01/20] ARM: mm: make nommu pgd_t a scalar Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 02/20] ARM: mm: make 2-level " Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 03/20] ARM: mm: remove custom pgdp_get() Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 04/20] LoongArch: mm: define pud_leaf() only when PUD exists Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 05/20] MIPS: " Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 06/20] mm/pgtable: define (pgd|p4d|pud)_leaf() for folded page tables Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:51   ` sashiko-bot
2026-07-22 15:30 ` [PATCH RFC v2 07/20] mm/pgtable: define (pgd|p4d|pud)_offset_lockless() " Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:58   ` sashiko-bot
2026-07-22 19:25     ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 08/20] mm: vmscan: remove stack copy address of pud pass in wallk_pud_range() Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:56   ` sashiko-bot
2026-07-22 19:31     ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 09/20] loongarch: kvm: remove stack copy address of pXd in pXd_offset() Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:53   ` sashiko-bot
2026-07-22 19:51     ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 10/20] riscv: " Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 11/20] riscv: mm: use proper set_pXd() for generic compile-time folded patable in vmalloc_fault() Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 12/20] x86: mm: define pudp_set_access_flags() when CONFIG_HAVE_ARCH_TRANSPARENT_HUGEPAGE_PUD is enabled only Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 16:02   ` Dave Hansen
2026-07-22 16:02     ` Dave Hansen
2026-07-22 16:02     ` Dave Hansen
2026-07-22 17:27     ` Yeoreum Yun
2026-07-22 17:27       ` Yeoreum Yun
2026-07-22 17:27       ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 13/20] x86: mm: carve out the generic compile-time folded pgtable case in effective_prot() Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 16:07   ` sashiko-bot [this message]
2026-07-22 16:23     ` Yeoreum Yun
2026-07-22 16:11   ` Dave Hansen
2026-07-22 16:11     ` Dave Hansen
2026-07-22 16:11     ` Dave Hansen
2026-07-22 16:28     ` Yeoreum Yun
2026-07-22 16:28       ` Yeoreum Yun
2026-07-22 16:28       ` Yeoreum Yun
2026-07-22 17:37     ` Yeoreum Yun
2026-07-22 17:37       ` Yeoreum Yun
2026-07-22 17:37       ` Yeoreum Yun
2026-07-22 20:20       ` Dave Hansen
2026-07-22 20:20         ` Dave Hansen
2026-07-22 20:20         ` Dave Hansen
2026-07-22 21:00         ` Yeoreum Yun
2026-07-22 21:00           ` Yeoreum Yun
2026-07-22 21:00           ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 14/20] x86: mm: skip pud setup when using generic compile-time folded pagetable Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 16:18   ` sashiko-bot
2026-07-22 19:08     ` Yeoreum Yun
2026-07-22 16:33   ` Dave Hansen
2026-07-22 16:33     ` Dave Hansen
2026-07-22 16:33     ` Dave Hansen
2026-07-22 17:18     ` Yeoreum Yun
2026-07-22 17:18       ` Yeoreum Yun
2026-07-22 17:18       ` Yeoreum Yun
2026-07-22 20:02       ` Dave Hansen
2026-07-22 20:02         ` Dave Hansen
2026-07-22 20:02         ` Dave Hansen
2026-07-22 20:18         ` Yeoreum Yun
2026-07-22 20:18           ` Yeoreum Yun
2026-07-22 20:18           ` Yeoreum Yun
2026-07-22 20:22           ` Dave Hansen
2026-07-22 20:22             ` Dave Hansen
2026-07-22 20:22             ` Dave Hansen
2026-07-22 20:28             ` H. Peter Anvin
2026-07-22 20:28               ` H. Peter Anvin
2026-07-22 20:28               ` H. Peter Anvin
2026-07-22 20:40               ` Yeoreum Yun
2026-07-22 20:40                 ` Yeoreum Yun
2026-07-22 20:40                 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 15/20] mm/pgtable: optimize pmdp_get() and friends for folded pagetable levels Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 16:15   ` sashiko-bot
2026-07-22 19:44     ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 16/20] mm/pgtable: catch abuse of folded dummy pgd_t/p4d_t/pud_t Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 17/20] mm/pgtable: disallow calling (pgd|p4d|pud)_page, pgd_page_vaddr() and (p4d|pud)_pgtable with dummy Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 18/20] mm/pgtable: disallow calling folded set_pgd/set_p4d/set_pud " Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 19/20] openrisc/pgtable: drop __pmd_offset() Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 20/20] arm64: pgtable: convert pte_present() from macro to static inline Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 15:30   ` Yeoreum Yun
2026-07-22 16:40 ` [PATCH RFC v2 00/20] mm: optimize unnecessary loads due to ptep_get() and friends out Dave Hansen
2026-07-22 16:40   ` Dave Hansen
2026-07-22 16:40   ` Dave Hansen
2026-07-22 17:30   ` Yeoreum Yun
2026-07-22 17:30     ` Yeoreum Yun
2026-07-22 17:30     ` Yeoreum Yun

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260722160753.C48291F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=yeoreum.yun@arm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.