Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] arm64/mm: Check the requested PFN range during memoroy removal
@ 2026-07-20  2:06 Richard Cheng
  2026-07-20  3:56 ` Anshuman Khandual
  2026-07-20 20:23 ` Jonathan Cameron
  0 siblings, 2 replies; 3+ messages in thread
From: Richard Cheng @ 2026-07-20  2:06 UTC (permalink / raw)
  To: catalin.marinas, will
  Cc: ryan.roberts, ardb, kevin.brodsky, anshuman.khandual, yang,
	chaitanyas.prakash, linux-arm-kernel, linux-kernel, linux-cxl,
	newtonl, kristinc, mochs, kaihengf, kobak, Richard Cheng

prevent_memory_remove_notifier() advances pfn while checking whether the
range contains early memory. After the loop, pfn points to end_pfn, but
it is passed to can_unmap_without_split(). This checks the range
immediately after the requested memory instead of the range being
offlined.

Consequently, valid requests can be rejected with shifted address range,
while an unsafe request can be accepted when the following range is
unmapped. This was observed with CXL DAX memory, where the final memory
block was incorrectly allowed offline.

Pass arg->start_pfn so the leaf-split check examines the requested
range.

Fixes: 95a58852b0e5 ("arm64/mm: Reject memory removal that splits a kernel leaf mapping")
Signed-off-by: Richard Cheng <icheng@nvidia.com>
---
The bug occurred on a machine with CXL Type-3 device.
Branch: cxl-next

Before 95a58852b0e5:

"""
$ sudo echo offline > memory557056/state
write error: Operation not permitted
$ sudo dmesg
---[snip]---
[440008000000 440010000000] splits a leaf entry in linear map

$ sudo echo offline > memory558079/state
$ cat memory558079/state
offline
"""

After:
"""
$ sudo echo offline > memory557056/state
write error: Operation not permitted
[440000000000 440008000000] splits a leaf entry in linear map

$ sudo echo offline > memory558079/state
write error: Operation not permitted
[441ff8000000 442000000000] splits a leaf entry in linear map

My fix corrects the checked range and prevents the false acceptance.

Best regards,
Richard Cheng.
---
 arch/arm64/mm/mmu.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/arm64/mm/mmu.c b/arch/arm64/mm/mmu.c
index a25d8beacc83..18a8b0d3714e 100644
--- a/arch/arm64/mm/mmu.c
+++ b/arch/arm64/mm/mmu.c
@@ -2194,7 +2194,7 @@ static int prevent_memory_remove_notifier(struct notifier_block *nb,
 		}
 	}
 
-	if (!can_unmap_without_split(pfn, arg->nr_pages))
+	if (!can_unmap_without_split(arg->start_pfn, arg->nr_pages))
 		return NOTIFY_BAD;
 
 	return NOTIFY_OK;

base-commit: 5ca04f3ba91f1773bbd5da6d9c654ccc1ba7831d
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-07-20 21:17 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-20  2:06 [PATCH] arm64/mm: Check the requested PFN range during memoroy removal Richard Cheng
2026-07-20  3:56 ` Anshuman Khandual
2026-07-20 20:23 ` Jonathan Cameron

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox