From: sashiko-bot@kernel.org
To: "Suzuki K Poulose" <suzuki.poulose@arm.com>
Cc: kvmarm@lists.linux.dev, kvm@vger.kernel.org,
"Oliver Upton" <oupton@kernel.org>,
"Marc Zyngier" <maz@kernel.org>
Subject: Re: [PATCH v20 7/9] arm64: Block hibernate and kexec while RMM is active
Date: Tue, 29 Sep 2026 22:26:39 +0000 [thread overview]
Message-ID: <20260929222639.997731F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929221623.1342076-8-suzuki.poulose@arm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] arm64: hibernation resume blind copy triggers GPF when RMM is active
--
commit cd33ba7dfabdc9882b5491e3f0d6693b247f8326
Author: Suzuki K Poulose <suzuki.poulose@arm.com>
arm64: Block hibernate and kexec while RMM is active
RMM can be deactivated only after all delegated granules have been
reclaimed. If a new kernel is entered while any granules remain in the
Realm PAS, accesses to that memory can raise a Granule Protection Fault
and be fatal to the new kernel.
> diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c
> index 424291c547f02..253f544a59731 100644
> --- a/arch/arm64/kernel/hibernate.c
> +++ b/arch/arm64/kernel/hibernate.c
[ ... ]
> @@ -341,6 +342,11 @@ int swsusp_arch_suspend(void)
> return -EBUSY;
> }
>
> + if (is_rmm_active()) {
> + pr_err("Can't hibernate: RMM is active.\n");
> + return -EBUSY;
> + }
> +
[Severity: High]
While this successfully prevents saving a hibernation image, is there a missing
check in the resume path, specifically arch_hibernation_header_restore() in
arch/arm64/kernel/hibernate.c?
If a hibernation image is present on disk (e.g., from a prior boot with RMM
disabled, but with a matching uts_version), subsys_initcall(arm64_init_rmi)
activates RMM and delegates memory to the Realm PAS early in boot.
Later, late_initcall_sync(software_resume_initcall) restores the image.
Because arch_hibernation_header_restore() lacks an is_rmm_active() check,
the image is accepted. The low-level resume path swsusp_arch_resume() then
blindly overwrites physical memory with the saved image.
Without an upstream guard during resume, won't this overwrite newly delegated
Realm PAS memory, triggering a fatal Granule Protection Fault?
> flags = local_daif_save();
>
> if (__cpu_suspend_enter(&state)) {
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929221623.1342076-1-suzuki.poulose@arm.com?part=7
next prev parent reply other threads:[~2026-09-29 22:26 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 22:16 [PATCH v20 0/9] firmware: arm_rmm: Add RMM v2.0 base RMI support Suzuki K Poulose
2026-09-29 22:16 ` [PATCH v20 1/9] firmware: arm_rmm: Add SMC definitions for calling the RMM Suzuki K Poulose
2026-09-30 9:51 ` Catalin Marinas
2026-09-29 22:16 ` [PATCH v20 2/9] firmware: arm_rmm: Check for RMI support at init Suzuki K Poulose
2026-09-29 22:28 ` sashiko-bot
2026-09-30 8:18 ` Suzuki K Poulose
2026-09-30 11:02 ` Catalin Marinas
2026-10-01 6:03 ` Suzuki K Poulose
2026-10-01 8:17 ` Suzuki K Poulose
2026-09-29 22:16 ` [PATCH v20 3/9] firmware: arm_rmm: Configure the RMM with the host's page size Suzuki K Poulose
2026-09-30 11:10 ` Catalin Marinas
2026-09-29 22:16 ` [PATCH v20 4/9] firmware: arm_rmm: Add support for SRO Suzuki K Poulose
2026-09-29 22:30 ` sashiko-bot
2026-09-30 8:45 ` Suzuki K Poulose
2026-09-30 8:46 ` Suzuki K Poulose
2026-09-30 13:15 ` Catalin Marinas
2026-09-30 13:48 ` Suzuki K Poulose
2026-09-29 22:16 ` [PATCH v20 5/9] firmware: arm_rmm: Activate the RMM Suzuki K Poulose
2026-09-30 13:20 ` Catalin Marinas
2026-09-29 22:16 ` [PATCH v20 6/9] firmware: arm_rmm: Ensure the RMM has GPT entries for memory Suzuki K Poulose
2026-09-30 13:39 ` Catalin Marinas
2026-09-30 14:44 ` Sudeep Holla
2026-09-30 15:55 ` Suzuki K Poulose
2026-10-01 8:31 ` Sudeep Holla
2026-09-29 22:16 ` [PATCH v20 7/9] arm64: Block hibernate and kexec while RMM is active Suzuki K Poulose
2026-09-29 22:26 ` sashiko-bot [this message]
2026-09-30 9:12 ` Suzuki K Poulose
2026-09-30 15:15 ` Catalin Marinas
2026-09-30 16:06 ` Jonathan Cameron
2026-09-29 22:16 ` [PATCH v20 8/9] firmware: arm_rmm: Add wrappers for Realm related RMI commands Suzuki K Poulose
2026-09-29 22:29 ` sashiko-bot
2026-09-30 11:12 ` Suzuki K Poulose
2026-09-30 15:51 ` Catalin Marinas
2026-09-29 22:16 ` [PATCH v20 9/9] firmware: arm_rmm: hotplug: Skip memory added to ZONE_MOVABLE Suzuki K Poulose
2026-09-30 12:22 ` David Hildenbrand (Arm)
2026-09-30 12:47 ` Suzuki K Poulose
2026-09-30 15:53 ` Catalin Marinas
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929222639.997731F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=suzuki.poulose@arm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.