From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 371E249739C; Thu, 17 Sep 2026 16:00:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660806; cv=none; b=oz5HEvFqlcC+eH4HX49r17cxcX9W6j9+kt/CAs3hutxNSMVtK8rmXnQWScGxIyD4U0NvAJrA9JFwPVuuY1WPjWgkIruOFPoFUU63hf2aMdnAJyra/WcQ1yij9/u9qRBj4wH1GwNxUoYev+fN/wZ01tymPtDttu3HSLe4dpwM0+A= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660806; c=relaxed/simple; bh=uIq6K6J0pbmPLuQaGDCGlws7zTe7IQw7q3JuxT1PAhc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CbaR3cNAgt/JZh2+eEEb78qjxe9rX3DGMJcN3SYxBzSlJ3H+u/dxME9bQeGFZ2yXmtn1Aen+508xdTwss4psbjFiuLLMzvn8f0xYYXvRB4keiU92lGG11zOEfXQyHN3u6cZGcx9pfBOIYCxiZwFbQZRahet5Ew8ony8SywQoVtA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=QSSRr/Vn; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="QSSRr/Vn" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8D1B51F000FF; Thu, 17 Sep 2026 16:00:04 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789660805; bh=GuxWezB1ZrPLLQOe+XC9XuiugqU+XSnmTFY6G7rC0AY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=QSSRr/VnUyqWsa12xwPdOn9dFA0S2UjxsVW4ZxiZV/kBXsUYrJvSlsXIw/GC+N2eF STWyTqAsnnAXK7V0bjzt2UbqnBWoSiP/LIoZEfHv3qZFb0g/P2t2+9qRo9R3tolBU5 WW/Fu0ZV9SctTYMSyze22gf8z8VkMU6LkFHH6DUM= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Dave Hansen , "Mike Rapoport (Microsoft)" , Dave Hansen , Sasha Levin Subject: [PATCH 7.2 715/733] x86/mm/pat: Dont gate cpa_lock on debug_pagealloc_enabled() Date: Thu, 17 Sep 2026 16:17:03 +0100 Message-ID: <20260917151410.733588877@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260917151350.597953846@linuxfoundation.org> References: <20260917151350.597953846@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: "Mike Rapoport (Microsoft)" [ Upstream commit 5fce67641a3ed9a0782eaa228ddece526461a367 ] The splitting and merging of kernel page table mappings between small and large is protected by cpa_lock. The merging is relatively new but the splitting is ancient. The splitting has a locking optimization: since DEBUG_PAGEALLOC forces all mappings to 4k, there are no large pages to split. So the code that *might* cause a split can just skip the locking (and a few other things). This is entertaining, but it adds complexity and makes for weird locking rules. Plus it's all for a debugging feature which makes the kernel super slow in the first place. Optimizing something which is already super slow and not used in production is not the best way to spend our complexity budget. Stop gating cpa_lock on debug_pagealloc_enabled() to simplify the code and the locking rules. [ dhansen: flesh out changelog ] Suggested-by: Dave Hansen Signed-off-by: Mike Rapoport (Microsoft) Signed-off-by: Dave Hansen Link: https://patch.msgid.link/20260715144519.934289-1-rppt@kernel.org Link: https://lore.kernel.org/all/aab44f08-89f8-47fe-bee4-0ab6b25968c6@intel.com/ Stable-dep-of: d5d8b8662e6e ("x86/mm/pat: Acquire init_mm read lock on attribute changes to avoid UAF") Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- arch/x86/mm/pat/set_memory.c | 19 +++++++------------ 1 file changed, 7 insertions(+), 12 deletions(-) --- a/arch/x86/mm/pat/set_memory.c +++ b/arch/x86/mm/pat/set_memory.c @@ -63,10 +63,9 @@ enum cpa_warn { static const int cpa_warn_level = CPA_PROTECT; /* - * Serialize cpa() (for !DEBUG_PAGEALLOC which uses large identity mappings) - * using cpa_lock. So that we don't allow any other cpu, with stale large tlb - * entries change the page attribute in parallel to some other cpu - * splitting a large page entry along with changing the attribute. + * Serialize cpa() using cpa_lock so that we don't allow any other cpu, with + * stale large tlb entries, to change the page attribute in parallel to some + * other cpu splitting a large page entry along with changing the attribute. */ static DEFINE_SPINLOCK(cpa_lock); @@ -1254,11 +1253,9 @@ static int split_large_page(struct cpa_d { struct ptdesc *ptdesc; - if (!debug_pagealloc_enabled()) - spin_unlock(&cpa_lock); + spin_unlock(&cpa_lock); ptdesc = pagetable_alloc(GFP_KERNEL, 0); - if (!debug_pagealloc_enabled()) - spin_lock(&cpa_lock); + spin_lock(&cpa_lock); if (!ptdesc) return -ENOMEM; @@ -2042,11 +2039,9 @@ static int __change_page_attr_set_clr(st if (cpa->flags & (CPA_ARRAY | CPA_PAGES_ARRAY)) cpa->numpages = 1; - if (!debug_pagealloc_enabled()) - spin_lock(&cpa_lock); + spin_lock(&cpa_lock); ret = __change_page_attr(cpa, primary); - if (!debug_pagealloc_enabled()) - spin_unlock(&cpa_lock); + spin_unlock(&cpa_lock); if (ret) goto out;