From: Karl Mehltretter <kmehltretter@gmail.com>
To: stable@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Catalin Marinas <catalin.marinas@arm.com>,
Will Deacon <will@kernel.org>,
Ryan Roberts <ryan.roberts@arm.com>,
Ard Biesheuvel <ardb@kernel.org>,
Mark Rutland <mark.rutland@arm.com>,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org,
Karl Mehltretter <kmehltretter@gmail.com>
Subject: [PATCH 6.6.y] arm64: mm: clear extra idmap level before use
Date: Mon, 31 Aug 2026 07:42:47 +0200 [thread overview]
Message-ID: <20260831054247.33352-1-kmehltretter@gmail.com> (raw)
The 6.6.y adaptation of commit 0e9df1c905d8 ("arm64: mm: Don't remap
pgtables for allocate vs populate") removes the clearing performed by
early_pgtable_alloc(). Its replacement clears allocations made by the
generic page-table walkers, but 6.6's create_idmap() still allocates an
extra root level directly when a sub-48-bit VA kernel is loaded
sufficiently high in physical memory.
memblock_phys_alloc_range() does not zero the returned memory. The direct
caller therefore publishes an uncleared root page and passes it to
__create_pgd_mapping(). A stale nonzero entry can trip the bad-descriptor
BUG_ON or be followed as a page-table descriptor, preventing the kernel
from booting.
Clear the direct allocation through its linear alias before publishing it.
init_clear_pgtable() also supplies the barrier required before the table
descriptor becomes visible.
Mainline is not affected because commit e6128a8e523c ("arm64: mm: Use
48-bit virtual addressing for the permanent ID map") removed the dynamic
extra level before page-table initialization moved out of the allocator.
Fixes: 54322d95309d ("arm64: mm: Don't remap pgtables for allocate vs populate")
---
A deterministic QEMU A/B used 16 KiB pages, a 36-bit VA, a 48-bit PA, an
Image loaded at 0x1000200000, and test-only instrumentation that filled the
extra root with 0x02. The affected kernel hit the expected bad-descriptor
BUG_ON. With this patch, the same poisoned allocation survived
create_idmap() before the test stopped deliberately.
The injected contents make the allocator's permitted nonzero return
deterministic; they do not estimate real-world incidence.
Tested on:
6.6.y a4a971135a2ff64382ae4235b3ae60503bb1036a (Linux 6.6.155)
arch/arm64/mm/mmu.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/mm/mmu.c b/arch/arm64/mm/mmu.c
index e075792d722575d38488e8352df8947c6aaddd2b..4e9e997e08daf543e5c09799563f991a9f8a7cc0 100644
--- a/arch/arm64/mm/mmu.c
+++ b/arch/arm64/mm/mmu.c
@@ -777,9 +777,10 @@ static void __init create_idmap(void)
/* check if we need an additional level of translation */
if (VA_BITS < 48 && idmap_t0sz < (64 - VA_BITS_MIN)) {
pgd_phys = early_pgtable_alloc(PAGE_SHIFT);
+ pgd = __va(pgd_phys);
+ init_clear_pgtable(pgd);
set_pgd(&idmap_pg_dir[start >> VA_BITS],
__pgd(pgd_phys | P4D_TYPE_TABLE));
- pgd = __va(pgd_phys);
}
__create_pgd_mapping(pgd, start, start, size, PAGE_KERNEL_ROX,
early_pgtable_alloc, 0);
--
2.39.5 (Apple Git-154)
next reply other threads:[~2026-08-31 5:43 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 5:42 Karl Mehltretter [this message]
2026-08-31 5:54 ` [PATCH 6.6.y] arm64: mm: clear extra idmap level before use Greg Kroah-Hartman
2026-08-31 6:15 ` Ard Biesheuvel
2026-08-31 11:00 ` Karl Mehltretter
2026-08-31 11:47 ` Greg Kroah-Hartman
2026-08-31 15:29 ` [PATCH 6.6.y v2] Revert "arm64: mm: Don't remap pgtables for allocate vs populate" Karl Mehltretter
2026-09-01 1:21 ` Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831054247.33352-1-kmehltretter@gmail.com \
--to=kmehltretter@gmail.com \
--cc=ardb@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=gregkh@linuxfoundation.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mark.rutland@arm.com \
--cc=ryan.roberts@arm.com \
--cc=stable@vger.kernel.org \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.