Kexec Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: "Kalra, Ashish" <ashish.kalra@amd.com>
To: Mike Rapoport <rppt@kernel.org>
Cc: Borislav Petkov <bp@alien8.de>,
	tglx@linutronix.de, mingo@redhat.com,
	dave.hansen@linux.intel.com, x86@kernel.org, rafael@kernel.org,
	hpa@zytor.com, peterz@infradead.org, adrian.hunter@intel.com,
	sathyanarayanan.kuppuswamy@linux.intel.com,
	jun.nakajima@intel.com, rick.p.edgecombe@intel.com,
	thomas.lendacky@amd.com, michael.roth@amd.com, seanjc@google.com,
	kai.huang@intel.com, bhe@redhat.com,
	kirill.shutemov@linux.intel.com, bdas@redhat.com,
	vkuznets@redhat.com, dionnaglaze@google.com, anisinha@redhat.com,
	jroedel@suse.de, ardb@kernel.org, kexec@lists.infradead.org,
	linux-coco@lists.linux.dev, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v7 1/3] efi/x86: Fix EFI memory map corruption with kexec
Date: Mon, 3 Jun 2024 09:01:49 -0500	[thread overview]
Message-ID: <1ef36309-8d7f-447b-a54a-3cdafeccca64@amd.com> (raw)
In-Reply-To: <Zl3HfiQ6oHdTdOdA@kernel.org>

On 6/3/2024 8:39 AM, Mike Rapoport wrote:

> On Mon, Jun 03, 2024 at 08:06:56AM -0500, Kalra, Ashish wrote:
>> On 6/3/2024 3:56 AM, Borislav Petkov wrote
>>
>>>> EFI memory map and due to early allocation it uses memblock allocation.
>>>>
>>>> Later during boot, efi_enter_virtual_mode() calls kexec_enter_virtual_mode()
>>>> in case of a kexec-ed kernel boot.
>>>>
>>>> This function kexec_enter_virtual_mode() installs the new EFI memory map by
>>>> calling efi_memmap_init_late() which remaps the efi_memmap physically allocated
>>>> in efi_arch_mem_reserve(), but this remapping is still using memblock allocation.
>>>>
>>>> Subsequently, when memblock is freed later in boot flow, this remapped
>>>> efi_memmap will have random corruption (similar to a use-after-free scenario).
>>>>
>>>> The corrupted EFI memory map is then passed to the next kexec-ed kernel
>>>> which causes a panic when trying to use the corrupted EFI memory map.
>>> This sounds fishy: memblock allocated memory is not freed later in the
>>> boot - it remains reserved. Only free memory is freed from memblock to
>>> the buddy allocator.
>>>
>>> Or is the problem that memblock-allocated memory cannot be memremapped
>>> because *raisins*?
>> This is what seems to be happening:
>>
>> efi_arch_mem_reserve() calls efi_memmap_alloc() to allocate memory for
>> EFI memory map and due to early allocation it uses memblock allocation.
>>
>> And later efi_enter_virtual_mode() calls kexec_enter_virtual_mode()
>> in case of a kexec-ed kernel boot.
>>
>> This function kexec_enter_virtual_mode() installs the new EFI memory map by
>> calling efi_memmap_init_late() which does memremap() on memblock-allocated memory.
> Does the issue happen only with SNP?

This is observed under SNP as efi_arch_mem_reserve() is only being 
called with SNP enabled and then efi_arch_mem_reserve() allocates EFI 
memory map using memblock.

If we skip efi_arch_mem_reserve() (which should probably be anyway 
skipped for kexec case), then for kexec boot, EFI memmap is memremapped 
in the same virtual address as the first kernel and not the allocated 
memblock address.

Thanks, Ashish

>
> I didn't really dig, but my theory would be that it has something to do
> with arch_memremap_can_ram_remap() in arch/x86/mm/ioremap.c
>   
>> Thanks, Ashish

_______________________________________________
kexec mailing list
kexec@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/kexec

  reply	other threads:[~2024-06-03 14:02 UTC|newest]

Thread overview: 92+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20240528095522.509667-1-kirill.shutemov@linux.intel.com>
2024-05-28 10:01 ` [PATCHv11 00/19] x86/tdx: Add kexec support Rafael J. Wysocki
     [not found] ` <20240528095522.509667-2-kirill.shutemov@linux.intel.com>
2024-05-28 13:47   ` [PATCHv11 01/19] x86/acpi: Extract ACPI MADT wakeup code into a separate file Borislav Petkov
     [not found] ` <20240528095522.509667-11-kirill.shutemov@linux.intel.com>
2024-05-29 10:42   ` [PATCHv11 10/19] x86/mm: Add callbacks to prepare encrypted memory for kexec Borislav Petkov
     [not found]     ` <20240602123903.2121883-1-kirill.shutemov@linux.intel.com>
2024-06-02 12:42       ` [PATCHv11.1 " Kirill A. Shutemov
2024-06-04 16:16   ` [PATCHv11 " Dave Hansen
     [not found] ` <20240528095522.509667-6-kirill.shutemov@linux.intel.com>
2024-05-29 10:47   ` [PATCHv11 05/19] x86/relocate_kernel: Use named labels for less confusion Nikolay Borisov
2024-05-29 11:17     ` Kirill A. Shutemov
2024-05-29 11:28       ` Borislav Petkov
2024-05-29 12:33         ` Andrew Cooper
2024-05-29 15:15           ` Borislav Petkov
2024-06-04  0:24       ` H. Peter Anvin
2024-06-04  9:15         ` Borislav Petkov
2024-06-04 15:21           ` Kirill A. Shutemov
2024-06-04 17:57             ` Borislav Petkov
2024-06-11 18:26             ` H. Peter Anvin
2024-06-12  9:22               ` Kirill A. Shutemov
2024-06-12 23:06                 ` Andrew Cooper
2024-06-12 23:25                   ` H. Peter Anvin
2024-06-03 14:43     ` H. Peter Anvin
2024-06-12 12:10       ` Nikolay Borisov
2024-06-03 22:43     ` H. Peter Anvin
     [not found] ` <20240528095522.509667-7-kirill.shutemov@linux.intel.com>
2024-05-28 11:12   ` [PATCHv11 06/19] x86/kexec: Keep CR4.MCE set during kexec for TDX guest Huang, Kai
2024-05-29 11:39   ` Nikolay Borisov
2024-05-30 23:36 ` [PATCH v7 0/3] x86/snp: Add kexec support Ashish Kalra
2024-05-30 23:36   ` [PATCH v7 1/3] efi/x86: Fix EFI memory map corruption with kexec Ashish Kalra
2024-05-31  9:12     ` Alexander Kuleshov
2024-06-03  8:56     ` Borislav Petkov
2024-06-03 13:06       ` Kalra, Ashish
2024-06-03 13:39         ` Mike Rapoport
2024-06-03 14:01           ` Kalra, Ashish [this message]
2024-06-03 14:46             ` Borislav Petkov
2024-06-03 15:31               ` Mike Rapoport
2024-06-03 16:48                 ` Kalra, Ashish
2024-06-03 16:57                   ` Borislav Petkov
2024-06-03 17:08                     ` Kalra, Ashish
2024-06-03 17:12                       ` Borislav Petkov
2024-06-04 22:12                         ` Kalra, Ashish
2024-06-04 22:35                         ` Kalra, Ashish
2024-06-05  1:48                           ` Dave Young
2024-06-05  1:52                             ` Dave Young
2024-06-05  1:58                               ` Dave Young
2024-06-05  2:08                                 ` Kalra, Ashish
2024-06-05  2:28                                   ` Dave Young
2024-06-05 11:09                                     ` Borislav Petkov
2024-06-06  1:52                                       ` Dave Young
2024-06-05  2:14                             ` Kalra, Ashish
2024-06-03 17:05                   ` Kalra, Ashish
2024-06-03 17:10                     ` Borislav Petkov
2024-06-04  1:23                 ` Dave Young
2024-06-04  9:43                   ` Borislav Petkov
2024-06-04 11:09                     ` Dave Young
2024-06-04 18:02                       ` Borislav Petkov
2024-06-05  2:53                         ` Dave Young
2024-06-05  7:42                           ` Borislav Petkov
2024-06-05  8:17                             ` Ard Biesheuvel
2024-06-05 11:15                               ` Borislav Petkov
2024-06-03 15:29             ` Mike Rapoport
2024-06-03 16:56               ` Kalra, Ashish
2024-06-03 17:41                 ` Mike Rapoport
2024-05-30 23:37   ` [PATCH v7 2/3] x86/boot/compressed: Skip Video Memory access in Decompressor for SEV-ES/SNP Ashish Kalra
2024-06-05 20:14     ` Borislav Petkov
2024-05-30 23:37   ` [PATCH v7 3/3] x86/snp: Convert shared memory back to private on kexec Ashish Kalra
     [not found] ` <20240528095522.509667-12-kirill.shutemov@linux.intel.com>
2024-05-31 15:14   ` [PATCHv11 11/19] x86/tdx: " Borislav Petkov
2024-05-31 17:34     ` Kalra, Ashish
2024-05-31 18:06       ` Borislav Petkov
2024-06-02 14:20     ` Kirill A. Shutemov
     [not found]     ` <20240602142303.3263551-1-kirill.shutemov@linux.intel.com>
2024-06-03  8:37       ` [PATCHv11.1 " Borislav Petkov
2024-06-04 15:32         ` Kirill A. Shutemov
2024-06-04 15:47           ` Dave Hansen
2024-06-04 16:14             ` Kirill A. Shutemov
2024-06-04 18:05               ` Borislav Petkov
2024-06-05 12:21                 ` Kirill A. Shutemov
2024-06-05 16:24                   ` Borislav Petkov
2024-06-06 12:39                     ` Kirill A. Shutemov
2024-06-04 16:27   ` [PATCHv11 " Dave Hansen
2024-06-05 12:43     ` Kirill A. Shutemov
2024-06-05 16:05       ` Dave Hansen
     [not found] ` <20240528095522.509667-19-kirill.shutemov@linux.intel.com>
2024-06-03  8:39   ` [PATCHv11 18/19] x86/acpi: Add support for CPU offlining for ACPI MADT wakeup method Borislav Petkov
2024-06-07 15:14     ` Kirill A. Shutemov
2024-06-10 13:40       ` Borislav Petkov
2024-06-10 14:01         ` Kirill A. Shutemov
2024-06-11 15:47           ` Kirill A. Shutemov
2024-06-11 19:46             ` Borislav Petkov
2024-06-12  9:24               ` Kirill A. Shutemov
2024-06-12  9:29                 ` Borislav Petkov
2024-06-13 13:41                   ` Kirill A. Shutemov
2024-06-13 14:56                     ` Borislav Petkov
2024-06-14 14:06                       ` Tom Lendacky
2024-06-18 12:20                         ` Kirill A. Shutemov
2024-06-21 13:38                     ` Borislav Petkov
     [not found] ` <20240528095522.509667-10-kirill.shutemov@linux.intel.com>
2024-06-04 16:08   ` [PATCHv11 09/19] x86/tdx: Account shared memory Dave Hansen
2024-06-04 16:24     ` Kirill A. Shutemov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1ef36309-8d7f-447b-a54a-3cdafeccca64@amd.com \
    --to=ashish.kalra@amd.com \
    --cc=adrian.hunter@intel.com \
    --cc=anisinha@redhat.com \
    --cc=ardb@kernel.org \
    --cc=bdas@redhat.com \
    --cc=bhe@redhat.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=dionnaglaze@google.com \
    --cc=hpa@zytor.com \
    --cc=jroedel@suse.de \
    --cc=jun.nakajima@intel.com \
    --cc=kai.huang@intel.com \
    --cc=kexec@lists.infradead.org \
    --cc=kirill.shutemov@linux.intel.com \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=michael.roth@amd.com \
    --cc=mingo@redhat.com \
    --cc=peterz@infradead.org \
    --cc=rafael@kernel.org \
    --cc=rick.p.edgecombe@intel.com \
    --cc=rppt@kernel.org \
    --cc=sathyanarayanan.kuppuswamy@linux.intel.com \
    --cc=seanjc@google.com \
    --cc=tglx@linutronix.de \
    --cc=thomas.lendacky@amd.com \
    --cc=vkuznets@redhat.com \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox