All of lore.kernel.org
 help / color / mirror / Atom feed
From: Suzuki K Poulose <suzuki.poulose@arm.com>
To: sashiko-reviews@lists.linux.dev
Cc: kvmarm@lists.linux.dev, kvm@vger.kernel.org,
	Oliver Upton <oupton@kernel.org>, Marc Zyngier <maz@kernel.org>
Subject: Re: [PATCH v20 7/9] arm64: Block hibernate and kexec while RMM is active
Date: Wed, 30 Sep 2026 10:12:36 +0100	[thread overview]
Message-ID: <8e02fe1d-2011-47f0-97a6-c34d730dee6c@arm.com> (raw)
In-Reply-To: <20260929222639.997731F000FF@smtp.kernel.org>

On 29/09/2026 23:26, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] arm64: hibernation resume blind copy triggers GPF when RMM is active
> --
> 
> commit cd33ba7dfabdc9882b5491e3f0d6693b247f8326
> Author: Suzuki K Poulose <suzuki.poulose@arm.com>
> 
> arm64: Block hibernate and kexec while RMM is active
> 
> RMM can be deactivated only after all delegated granules have been
> reclaimed. If a new kernel is entered while any granules remain in the
> Realm PAS, accesses to that memory can raise a Granule Protection Fault
> and be fatal to the new kernel.
> 
>> diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c
>> index 424291c547f02..253f544a59731 100644
>> --- a/arch/arm64/kernel/hibernate.c
>> +++ b/arch/arm64/kernel/hibernate.c
> 
> [ ... ]
> 
>> @@ -341,6 +342,11 @@ int swsusp_arch_suspend(void)
>>   		return -EBUSY;
>>   	}
>>   
>> +	if (is_rmm_active()) {
>> +		pr_err("Can't hibernate: RMM is active.\n");
>> +		return -EBUSY;
>> +	}
>> +
> 
> [Severity: High]
> While this successfully prevents saving a hibernation image, is there a missing
> check in the resume path, specifically arch_hibernation_header_restore() in
> arch/arm64/kernel/hibernate.c?
> 
> If a hibernation image is present on disk (e.g., from a prior boot with RMM
> disabled, but with a matching uts_version), subsys_initcall(arm64_init_rmi)
> activates RMM and delegates memory to the Realm PAS early in boot.
> 
> Later, late_initcall_sync(software_resume_initcall) restores the image.
> Because arch_hibernation_header_restore() lacks an is_rmm_active() check,
> the image is accepted. The low-level resume path swsusp_arch_resume() then
> blindly overwrites physical memory with the saved image.
> 
> Without an upstream guard during resume, won't this overwrite newly delegated
> Realm PAS memory, triggering a fatal Granule Protection Fault?

That is a valid point, I have added a check there to bail out if the rmm
is active.

Suzuki

> 
>>   	flags = local_daif_save();
>>   
>>   	if (__cpu_suspend_enter(&state)) {
> 


  reply	other threads:[~2026-09-30  9:12 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29 22:16 [PATCH v20 0/9] firmware: arm_rmm: Add RMM v2.0 base RMI support Suzuki K Poulose
2026-09-29 22:16 ` [PATCH v20 1/9] firmware: arm_rmm: Add SMC definitions for calling the RMM Suzuki K Poulose
2026-09-30  9:51   ` Catalin Marinas
2026-09-29 22:16 ` [PATCH v20 2/9] firmware: arm_rmm: Check for RMI support at init Suzuki K Poulose
2026-09-29 22:28   ` sashiko-bot
2026-09-30  8:18     ` Suzuki K Poulose
2026-09-30 11:02       ` Catalin Marinas
2026-10-01  6:03         ` Suzuki K Poulose
2026-10-01  8:17           ` Suzuki K Poulose
2026-09-29 22:16 ` [PATCH v20 3/9] firmware: arm_rmm: Configure the RMM with the host's page size Suzuki K Poulose
2026-09-30 11:10   ` Catalin Marinas
2026-09-29 22:16 ` [PATCH v20 4/9] firmware: arm_rmm: Add support for SRO Suzuki K Poulose
2026-09-29 22:30   ` sashiko-bot
2026-09-30  8:45     ` Suzuki K Poulose
2026-09-30  8:46       ` Suzuki K Poulose
2026-09-30 13:15   ` Catalin Marinas
2026-09-30 13:48     ` Suzuki K Poulose
2026-09-29 22:16 ` [PATCH v20 5/9] firmware: arm_rmm: Activate the RMM Suzuki K Poulose
2026-09-30 13:20   ` Catalin Marinas
2026-09-29 22:16 ` [PATCH v20 6/9] firmware: arm_rmm: Ensure the RMM has GPT entries for memory Suzuki K Poulose
2026-09-30 13:39   ` Catalin Marinas
2026-09-30 14:44   ` Sudeep Holla
2026-09-30 15:55     ` Suzuki K Poulose
2026-10-01  8:31       ` Sudeep Holla
2026-09-29 22:16 ` [PATCH v20 7/9] arm64: Block hibernate and kexec while RMM is active Suzuki K Poulose
2026-09-29 22:26   ` sashiko-bot
2026-09-30  9:12     ` Suzuki K Poulose [this message]
2026-09-30 15:15       ` Catalin Marinas
2026-09-30 16:06   ` Jonathan Cameron
2026-09-29 22:16 ` [PATCH v20 8/9] firmware: arm_rmm: Add wrappers for Realm related RMI commands Suzuki K Poulose
2026-09-29 22:29   ` sashiko-bot
2026-09-30 11:12     ` Suzuki K Poulose
2026-09-30 15:51   ` Catalin Marinas
2026-09-29 22:16 ` [PATCH v20 9/9] firmware: arm_rmm: hotplug: Skip memory added to ZONE_MOVABLE Suzuki K Poulose
2026-09-30 12:22   ` David Hildenbrand (Arm)
2026-09-30 12:47     ` Suzuki K Poulose
2026-09-30 15:53   ` Catalin Marinas

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8e02fe1d-2011-47f0-97a6-c34d730dee6c@arm.com \
    --to=suzuki.poulose@arm.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.