All of lore.kernel.org
 help / color / mirror / Atom feed
From: Shrikanth Hegde <sshegde@linux.ibm.com>
To: Venkat Rao Bagalkote <venkat88@linux.ibm.com>,
	linuxppc-dev@lists.ozlabs.org
Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com,
	chleroy@kernel.org, mkchauras@linux.ibm.com, mkchauras@gmail.com,
	ruanjinjie@huawei.com, ritesh.list@gmail.com,
	riteshh@linux.ibm.com, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v3] powerpc/interrupt: Use early_radix_enabled() in NMI real-mode guard
Date: Wed, 9 Sep 2026 23:19:56 +0530	[thread overview]
Message-ID: <8d45cfd1-55d0-4e8f-aac1-fae5c9c4d91c@linux.ibm.com> (raw)
In-Reply-To: <20260909123240.58786-1-venkat88@linux.ibm.com>



On 9/9/26 6:02 PM, Venkat Rao Bagalkote wrote:
> radix_enabled() uses a jump label which is only valid after
> setup_feature_keys() is called. Before that point, on a pSeries
> hash guest, early_check_vec5() clears MMU_FTR_TYPE_RADIX in
> cur_cpu_spec->mmu_features, but the jump label has not yet been patched,
> so radix_enabled() incorrectly returns true.
> 
> The dangerous usage window where it goes wrong in early_setup():
> 
>      early_setup:
>          configure_exceptions();
>          <exceptions can happen now, and handler enter/exit can be invoked>
>          <those could use radix_enabled(), which returns stale true>
>          setup_feature_keys();
>          <jump labels set up; post this it is safe to use radix_enabled()>
> 
> If an NMI occurs in this window, !radix_enabled() evaluates to false in
> DEFINE_INTERRUPT_HANDLER_NMI. The handler fails to skip NMI entry in real
> mode and attempts to access memory outside the Real Mode Area (RMA),
> hanging the boot.
> 
> Since common interrupt wrappers do not have the context of early or late,
> using early_radix_enabled() is the safer option. It does a plain bitmask
> check against cur_cpu_spec->mmu_features and is correct at all times.
> 
> Console logs from a pSeries HASH guest showing values across boot stages:
> 
> [    0.000000] DEBUG: after early_init_devtree: early_radix_enabled=0 radix_enabled=1 (mismatch means NMI real-mode check is unsafe!)
> [    0.000000] DEBUG: after configure_exceptions (DANGEROUS WINDOW): early_radix_enabled=0 radix_enabled=1
> [    0.000000] DEBUG: after setup_feature_keys (jump labels initialized): early_radix_enabled=0 radix_enabled=0 (should now match!)
> [    0.057124] DEBUG: post secondary CPU bringup: early_radix_enabled=0 radix_enabled=0 (should match!)
> 
> Console logs from a RADIX guest showing values across boot stages:
> 
> [    0.000000] DEBUG: after early_init_devtree: early_radix_enabled=1 radix_enabled=1 (mismatch means NMI real-mode check is unsafe!)
> [    0.000000] DEBUG: after configure_exceptions (DANGEROUS WINDOW): early_radix_enabled=1 radix_enabled=1
> [    0.000000] DEBUG: after setup_feature_keys (jump labels initialized): early_radix_enabled=1 radix_enabled=1 (should now match!)
> [    0.057016] DEBUG: post secondary CPU bringup: early_radix_enabled=1 radix_enabled=1 (should match!)
> 
> Add the missing #include <asm/mmu.h> in alphabetical order since
> early_radix_enabled() is declared there.
> 

Reviewed-by: Shrikanth Hegde <sshegde@linux.ibm.com>

> Fixes: 8d0e21012743 ("powerpc/mce: Avoid nmi_enter/exit in real mode on pseries hash")
> Signed-off-by: Venkat Rao Bagalkote <venkat88@linux.ibm.com>
> Reviewed-by: Mukesh Kumar Chaurasiya <mkchauras@gmail.com>

Nit: I prefer to see Signed-off-by at the end.
But i guess b4 or patchwork tools take care of ordering. So i think
we are fine.

> ---
> v3:
>   - Clarified early_setup execution flow and race window in changelog.
>   - Explained why early_radix_enabled() is required for context-agnostic wrappers.
>   - Added console logs for both HASH and RADIX guests in changelog.
> v2:
>   - Added Fixes: tag referencing commit 8d0e21012743.
>   - Included <asm/mmu.h> in alphabetical order.
>   - Added Reviewed-by tag from Mukesh.
> 
>   arch/powerpc/include/asm/interrupt.h | 5 +++--
>   1 file changed, 3 insertions(+), 2 deletions(-)
> 
> diff --git a/arch/powerpc/include/asm/interrupt.h b/arch/powerpc/include/asm/interrupt.h
> index 1b45a49e9bed..355f6bbf9894 100644
> --- a/arch/powerpc/include/asm/interrupt.h
> +++ b/arch/powerpc/include/asm/interrupt.h
> @@ -70,6 +70,7 @@
>   #include <linux/irq-entry-common.h>
>   
>   #include <asm/kprobes.h>
> +#include <asm/mmu.h>
>   #include <asm/runlatch.h>
>   
>   #ifdef CONFIG_PPC_IRQ_SOFT_MASK_DEBUG
> @@ -290,7 +291,7 @@ interrupt_handler long func(struct pt_regs *regs)			\
>   		state = irqentry_nmi_enter(regs);			\
>   	} else if (IS_ENABLED(CONFIG_PPC_BOOK3S_64) &&			\
>   		   firmware_has_feature(FW_FEATURE_LPAR) &&		\
> -		   !radix_enabled()) {					\
> +		   !early_radix_enabled()) {				\
>   		/* no nmi_entry for a pseries hash guest		\
>   		 * taking a real mode exception */			\
>   	} else if (IS_ENABLED(CONFIG_KASAN)) {				\
> @@ -307,7 +308,7 @@ interrupt_handler long func(struct pt_regs *regs)			\
>   		irqentry_nmi_exit(regs, state);				\
>   	} else if (IS_ENABLED(CONFIG_PPC_BOOK3S_64) &&			\
>   		   firmware_has_feature(FW_FEATURE_LPAR) &&		\
> -		   !radix_enabled()) {					\
> +		   !early_radix_enabled()) {				\
>   		/* no nmi_exit for a pseries hash guest			\
>   		 * taking a real mode exception */			\
>   	} else if (IS_ENABLED(CONFIG_KASAN)) {				\



      reply	other threads:[~2026-09-09 17:50 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09 12:32 [PATCH v3] powerpc/interrupt: Use early_radix_enabled() in NMI real-mode guard Venkat Rao Bagalkote
2026-09-09 17:49 ` Shrikanth Hegde [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8d45cfd1-55d0-4e8f-aac1-fae5c9c4d91c@linux.ibm.com \
    --to=sshegde@linux.ibm.com \
    --cc=chleroy@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=maddy@linux.ibm.com \
    --cc=mkchauras@gmail.com \
    --cc=mkchauras@linux.ibm.com \
    --cc=mpe@ellerman.id.au \
    --cc=npiggin@gmail.com \
    --cc=ritesh.list@gmail.com \
    --cc=riteshh@linux.ibm.com \
    --cc=ruanjinjie@huawei.com \
    --cc=venkat88@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.