All of lore.kernel.org
 help / color / mirror / Atom feed
From: Pratyush Yadav <pratyush@kernel.org>
To: Yifei Chu <yifeichu24@gmail.com>
Cc: Pasha Tatashin <pasha.tatashin@soleen.com>,
	 Mike Rapoport <rppt@kernel.org>,
	 linux-kernel@vger.kernel.org,
	 Pratyush Yadav <pratyush@kernel.org>,
	 Andrew Morton <akpm@linux-foundation.org>,
	Alexander Graf <graf@amazon.com>,
	 linux-mm@kvack.org, kexec@lists.infradead.org
Subject: Re: [BUG] liveupdate: incoming/outgoing session ioctls accepted in wrong phase can panic
Date: Mon, 25 May 2026 17:26:51 +0200	[thread overview]
Message-ID: <2vxzjysr7bno.fsf@kernel.org> (raw)
In-Reply-To: <CAPJnbgLtEUQ4Kv1ENM4ku0S0JFS8T49MEHFa4MpoT3WRuuVfFA@mail.gmail.com> (Yifei Chu's message of "Sun, 24 May 2026 10:44:31 -0400")

On Sun, May 24 2026, Yifei Chu wrote:

> Hello,
>
> Short version: I found that liveupdate session ioctls can be accepted on the wrong kind of session. In my tests, that
> lets userspace drive memfd LUO into KHO restore paths for current-kernel preserved memory, which hits kho_restore_page()
> warnings and panics with panic_on_warn=1.

I already sent a fix for this:
https://lore.kernel.org/kexec/20260519122428.2378446-1-pratyush@kernel.org/

I need to do a refresh of this patch with some tests.

-- 
Regards,
Pratyush Yadav


  reply	other threads:[~2026-05-25 15:26 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-24 14:44 [BUG] liveupdate: incoming/outgoing session ioctls accepted in wrong phase can panic Yifei Chu
2026-05-25 15:26 ` Pratyush Yadav [this message]
  -- strict thread matches above, loose matches on Subject: below --
2026-05-24 17:31 Yifei Chu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2vxzjysr7bno.fsf@kernel.org \
    --to=pratyush@kernel.org \
    --cc=akpm@linux-foundation.org \
    --cc=graf@amazon.com \
    --cc=kexec@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=pasha.tatashin@soleen.com \
    --cc=rppt@kernel.org \
    --cc=yifeichu24@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.