From: Peter Zijlstra <peterz@infradead.org>
To: "Mike Rapoport (Microsoft)" <rppt@kernel.org>
Cc: Dave Hansen <dave.hansen@linux.intel.com>,
Andrew Morton <akpm@linux-foundation.org>,
Andy Lutomirski <luto@kernel.org>, Borislav Petkov <bp@alien8.de>,
David CARLIER <devnexen@gmail.com>,
David Hildenbrand <david@kernel.org>,
Ingo Molnar <mingo@redhat.com>, Jason Gunthorpe <jgg@ziepe.ca>,
Juergen Gross <jgross@suse.com>,
Kevin Tian <kevin.tian@intel.com>,
Kiryl Shutsemau <kas@kernel.org>,
"Liam R. Howlett" <liam@infradead.org>,
Lorenzo Stoakes <ljs@kernel.org>,
Lu Baolu <baolu.lu@linux.intel.com>,
"H. Peter Anvin" <hpa@zytor.com>,
Shakeel Butt <shakeel.butt@linux.dev>,
Suren Baghdasaryan <surenb@google.com>,
Thomas Gleixner <tglx@kernel.org>,
Toshi Kani <toshi.kani@hpe.com>,
Vishal Moola <vishal.moola@gmail.com>,
Vlastimil Babka <vbabka@kernel.org>,
Will Deacon <will@kernel.org>,
iommu@lists.linux.dev, linux-kernel@vger.kernel.org,
linux-mm@kvack.org, stable@vger.kernel.org, x86@kernel.org
Subject: Re: [PATCH 1/5] x86/mm/pat: introcude cpa_lock() and cpa_unlock()
Date: Tue, 28 Jul 2026 16:21:08 +0200 [thread overview]
Message-ID: <20260728142108.GW751831@noisy.programming.kicks-ass.net> (raw)
In-Reply-To: <20260728-cpa-fixes-v1-1-2ed2352300b3@kernel.org>
On Tue, Jul 28, 2026 at 04:07:44PM +0300, Mike Rapoport (Microsoft) wrote:
> The splitting and merging of kernel page table mappings between small and
> large is protected by cpa_lock.
>
> Commit 5fce67641a3e ("x86/mm/pat: Don't gate cpa_lock on
> debug_pagealloc_enabled()") disabled gatig of cpa_lock on
> debug_pagealloc_enabled() to simplify the code presuming that skipping
> the lock when debug_pagealloc_enabled() was an optimization.
>
> However Lorenzo Stoakes notes that:
>
> __kernel_map_pages() can be called from irq context:
>
> < GFP_ATOMIC context >
> kfree() or whatever
> -> ...
> -> __free_pages_prepare()
> -> debug_pagealloc_unmap_pages()
> -> __kernel_map_pages()
> -> __change_page_attr_set_clr()
> -> cpa_lock spins [irqs off]
>
> So you're spin locking in irq context here, which is probably not a
> good idea.
>
> It would be possible to unconditionally use spin_lock_irqsave() and
> spin_unlock_irqrestore() but that would complicate locking rules even
> more.
>
> Restore gating of cpa_lock of debug_pagealloc_enabled(), but instead of
> putting the open-coded condition
>
> if (debug_pagealloc_enabled())
>
> before every lock and unlock operation, wrap the condition and the
> locking operation into cpa_lock() and cpa_unlock() helpers.
>
> Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
> ---
> arch/x86/mm/pat/set_memory.c | 33 +++++++++++++++++++++++++--------
> 1 file changed, 25 insertions(+), 8 deletions(-)
>
> diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c
> index b1e780a465b5..4c8922695fd3 100644
> --- a/arch/x86/mm/pat/set_memory.c
> +++ b/arch/x86/mm/pat/set_memory.c
> @@ -65,8 +65,25 @@ static const int cpa_warn_level = CPA_PROTECT;
> * Serialize cpa() using cpa_lock so that we don't allow any other cpu, with
> * stale large tlb entries, to change the page attribute in parallel to some
> * other cpu splitting a large page entry along with changing the attribute.
> + *
> + * When debug_pagealloc_enabled(), page attributes could be changed in atomic
> + * context that would warrant disabling IRQs. But since debug_pagealloc always
> + * uses 4k pages in the direct map there are no races for splits and collapses
> + * and locking can be just skipped altogether.
> */
> -static DEFINE_SPINLOCK(cpa_lock);
> +static DEFINE_SPINLOCK(_cpa_lock);
> +
> +static inline void cpa_lock(void)
> +{
> + if (!debug_pagealloc_enabled())
> + spin_lock(&_cpa_lock);
> +}
> +
> +static inline void cpa_unlock(void)
> +{
> + if (!debug_pagealloc_enabled())
> + spin_unlock(&_cpa_lock);
> +}
There was already a patch merged that removed the shole debug_pagealloc
exception. Is that not better?
next prev parent reply other threads:[~2026-07-28 14:21 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-28 13:07 [PATCH 0/5] x86/mm/pat: CPA fixes Mike Rapoport (Microsoft)
2026-07-28 13:07 ` [PATCH 1/5] x86/mm/pat: introcude cpa_lock() and cpa_unlock() Mike Rapoport (Microsoft)
2026-07-28 13:13 ` Lorenzo Stoakes (ARM)
2026-07-28 14:21 ` Peter Zijlstra [this message]
2026-07-28 14:30 ` Dave Hansen
2026-07-28 14:31 ` Peter Zijlstra
2026-07-28 14:46 ` Mike Rapoport
2026-07-28 14:50 ` Lorenzo Stoakes (ARM)
2026-07-28 14:55 ` Peter Zijlstra
2026-07-28 15:01 ` Peter Zijlstra
2026-07-28 15:20 ` Lorenzo Stoakes (ARM)
2026-07-28 15:33 ` Peter Zijlstra
2026-07-28 15:54 ` Mike Rapoport
2026-07-28 15:02 ` Lorenzo Stoakes (ARM)
2026-07-28 15:30 ` Peter Zijlstra
2026-07-28 15:16 ` Peter Zijlstra
2026-07-28 16:01 ` Mike Rapoport
2026-07-28 13:07 ` [PATCH 2/5] x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF Mike Rapoport
2026-07-28 13:07 ` [PATCH 3/5] x86/mm/pat: acquire init_mm read lock on attribute change " Mike Rapoport
2026-07-28 13:14 ` Lorenzo Stoakes (ARM)
2026-07-28 13:07 ` [PATCH 4/5] x86/mm/pat: allocate split page tables as kernel page tables Mike Rapoport
2026-07-28 13:07 ` [PATCH 5/5] x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr() Mike Rapoport (Microsoft)
2026-07-28 13:11 ` [PATCH 0/5] x86/mm/pat: CPA fixes Lorenzo Stoakes (ARM)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260728142108.GW751831@noisy.programming.kicks-ass.net \
--to=peterz@infradead.org \
--cc=akpm@linux-foundation.org \
--cc=baolu.lu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=david@kernel.org \
--cc=devnexen@gmail.com \
--cc=hpa@zytor.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@ziepe.ca \
--cc=jgross@suse.com \
--cc=kas@kernel.org \
--cc=kevin.tian@intel.com \
--cc=liam@infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=ljs@kernel.org \
--cc=luto@kernel.org \
--cc=mingo@redhat.com \
--cc=rppt@kernel.org \
--cc=shakeel.butt@linux.dev \
--cc=stable@vger.kernel.org \
--cc=surenb@google.com \
--cc=tglx@kernel.org \
--cc=toshi.kani@hpe.com \
--cc=vbabka@kernel.org \
--cc=vishal.moola@gmail.com \
--cc=will@kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.