From: Yeoreum Yun <yeoreum.yun@arm.com>
To: sashiko-reviews@lists.linux.dev
Cc: Yeoreum Yun <yeoreum.yun@arm.com>, kvm@vger.kernel.org
Subject: Re: [PATCH RFC v2 07/20] mm/pgtable: define (pgd|p4d|pud)_offset_lockless() for folded page tables
Date: Wed, 22 Jul 2026 20:25:08 +0100 [thread overview]
Message-ID: <amEZFECJbtQfoXOo@e129823.arm.com> (raw)
In-Reply-To: <20260722155849.85FF41F00A3A@smtp.kernel.org>
On Wed, Jul 22, 2026 at 03:58:49PM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
>
> Pre-existing issues:
> - [Critical] Use-After-Free in GUP-fast on dynamically folded architectures (RISC-V SV39) due to flawed generic lockless page table offset macros.
> --
>
> --- Patch [7]: [PATCH RFC v2 07/20] mm/pgtable: define (pgd|p4d|pud)_offset_lockless() for folded page tables ---
> commit 235a6b06e94a41ff4c56118e36e869516151cea9
> Author: David Hildenbrand (Arm) <david@kernel.org>
>
> mm/pgtable: define (pgd|p4d|pud)_offset_lockless() for folded page tables
>
> The patch provides p4d_offset_lockless(), pmd_offset_lockless(), and
> pud_offset_lockless() for static folded page tables to ignore the passed
> value and return the pointer. This avoids returning a pointer to the stack
> value like the default handlers do.
>
> > diff --git a/include/asm-generic/pgtable-nopud.h b/include/asm-generic/pgtable-nopud.h
> > index 6c9bca78047c4..5a2b0a81ae197 100644
> > --- a/include/asm-generic/pgtable-nopud.h
> > +++ b/include/asm-generic/pgtable-nopud.h
> [ ... ]
> > @@ -47,6 +47,13 @@ static inline pud_t *pud_offset(p4d_t *p4d, unsigned long address)
> > }
> > #define pud_offset pud_offset
> >
> > +static inline pud_t *pud_offset_lockless(p4d_t *p4dp, p4d_t p4d,
> > + unsigned long address)
> > +{
> > + return (pud_t *)p4dp;
> > +}
> > +#define pud_offset_lockless pud_offset_lockless
>
> [Severity: Critical]
> This is a pre-existing issue, but does this fix leave dynamically folded
> architectures like RISC-V SV39 vulnerable to a use-after-free?
>
> The generic fallback macro in include/linux/pgtable.h still passes the address
> of a local stack variable:
>
> #define pud_offset_lockless(p4dp, p4d, address) pud_offset(&(p4d), address)
>
> On RISC-V SV39, PUD is folded dynamically in arch/riscv/mm/pgtable.c:
>
> pud_t *pud_offset(p4d_t *p4d, unsigned long address)
> {
> if (pgtable_l4_enabled)
> return p4d_pgtable(p4dp_get(p4d)) + pud_index(address);
>
> return (pud_t *)p4d;
> }
>
> Since pgtable_l4_enabled is false on SV39, pud_offset() returns the pointer it
> was passed, which is the stack pointer from the generic pud_offset_lockless()
> macro.
>
> When gup_fast_pud_leaf() in mm/gup.c executes its concurrent modification
> check, it reads the stale stack variable instead of the actual page table:
>
> if (unlikely(pud_val(orig) != pud_val(pudp_get(pudp)))) {
> gup_put_folio(folio, refs, flags);
> return 0;
> }
>
> Because it reads the isolated stack variable, the check trivially passes,
> allowing GUP-fast to pin and return a concurrently freed 1GB huge page.
>
> Could a similar lockless override be applied for dynamically folded
> architectures to prevent this?
concurrent modification check doesn't lose the meaning since pudp is read
again and compare with orig and isolated stack variable doesn't connect
to trivially passes. So, this is ignorable.
--
Sincerely,
Yeoreum Yun
next prev parent reply other threads:[~2026-07-22 19:25 UTC|newest]
Thread overview: 50+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 15:30 [PATCH RFC v2 00/20] mm: optimize unnecessary loads due to ptep_get() and friends out Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 01/20] ARM: mm: make nommu pgd_t a scalar Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 02/20] ARM: mm: make 2-level " Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 03/20] ARM: mm: remove custom pgdp_get() Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 04/20] LoongArch: mm: define pud_leaf() only when PUD exists Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 05/20] MIPS: " Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 06/20] mm/pgtable: define (pgd|p4d|pud)_leaf() for folded page tables Yeoreum Yun
2026-07-22 15:51 ` sashiko-bot
2026-07-22 15:30 ` [PATCH RFC v2 07/20] mm/pgtable: define (pgd|p4d|pud)_offset_lockless() " Yeoreum Yun
2026-07-22 15:58 ` sashiko-bot
2026-07-22 19:25 ` Yeoreum Yun [this message]
2026-07-22 15:30 ` [PATCH RFC v2 08/20] mm: vmscan: remove stack copy address of pud pass in wallk_pud_range() Yeoreum Yun
2026-07-22 15:56 ` sashiko-bot
2026-07-22 19:31 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 09/20] loongarch: kvm: remove stack copy address of pXd in pXd_offset() Yeoreum Yun
2026-07-22 15:53 ` sashiko-bot
2026-07-22 19:51 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 10/20] riscv: " Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 11/20] riscv: mm: use proper set_pXd() for generic compile-time folded patable in vmalloc_fault() Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 12/20] x86: mm: define pudp_set_access_flags() when CONFIG_HAVE_ARCH_TRANSPARENT_HUGEPAGE_PUD is enabled only Yeoreum Yun
2026-07-22 16:02 ` Dave Hansen
2026-07-22 17:27 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 13/20] x86: mm: carve out the generic compile-time folded pgtable case in effective_prot() Yeoreum Yun
2026-07-22 16:07 ` sashiko-bot
2026-07-22 16:23 ` Yeoreum Yun
2026-07-22 16:11 ` Dave Hansen
2026-07-22 16:28 ` Yeoreum Yun
2026-07-22 17:37 ` Yeoreum Yun
2026-07-22 20:20 ` Dave Hansen
2026-07-22 21:00 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 14/20] x86: mm: skip pud setup when using generic compile-time folded pagetable Yeoreum Yun
2026-07-22 16:18 ` sashiko-bot
2026-07-22 19:08 ` Yeoreum Yun
2026-07-22 16:33 ` Dave Hansen
2026-07-22 17:18 ` Yeoreum Yun
2026-07-22 20:02 ` Dave Hansen
2026-07-22 20:18 ` Yeoreum Yun
2026-07-22 20:22 ` Dave Hansen
2026-07-22 20:28 ` H. Peter Anvin
2026-07-22 20:40 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 15/20] mm/pgtable: optimize pmdp_get() and friends for folded pagetable levels Yeoreum Yun
2026-07-22 16:15 ` sashiko-bot
2026-07-22 19:44 ` Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 16/20] mm/pgtable: catch abuse of folded dummy pgd_t/p4d_t/pud_t Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 17/20] mm/pgtable: disallow calling (pgd|p4d|pud)_page, pgd_page_vaddr() and (p4d|pud)_pgtable with dummy Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 18/20] mm/pgtable: disallow calling folded set_pgd/set_p4d/set_pud " Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 19/20] openrisc/pgtable: drop __pmd_offset() Yeoreum Yun
2026-07-22 15:30 ` [PATCH RFC v2 20/20] arm64: pgtable: convert pte_present() from macro to static inline Yeoreum Yun
2026-07-22 16:40 ` [PATCH RFC v2 00/20] mm: optimize unnecessary loads due to ptep_get() and friends out Dave Hansen
2026-07-22 17:30 ` Yeoreum Yun
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=amEZFECJbtQfoXOo@e129823.arm.com \
--to=yeoreum.yun@arm.com \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox