linux-mm.kvack.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 0/5] x86/mm/pat: CPA fixes
@ 2026-07-28 13:07 Mike Rapoport (Microsoft)
  2026-07-28 13:07 ` [PATCH 1/5] x86/mm/pat: introcude cpa_lock() and cpa_unlock() Mike Rapoport (Microsoft)
                   ` (5 more replies)
  0 siblings, 6 replies; 23+ messages in thread
From: Mike Rapoport (Microsoft) @ 2026-07-28 13:07 UTC (permalink / raw)
  To: Dave Hansen
  Cc: Andrew Morton, Andy Lutomirski, Borislav Petkov, David CARLIER,
	David Hildenbrand, Ingo Molnar, Jason Gunthorpe, Juergen Gross,
	Kevin Tian, Kiryl Shutsemau, Liam R. Howlett, Lorenzo Stoakes,
	Lu Baolu, Mike Rapoport, H. Peter Anvin, Peter Zijlstra,
	Shakeel Butt, Suren Baghdasaryan, Thomas Gleixner, Toshi Kani,
	Vishal Moola, Vlastimil Babka, Will Deacon, iommu, linux-kernel,
	linux-mm, stable, x86, syzbot

There are a couple of CPA fixes floating around:

Denis Lunev fixed races between split and collapse of the large mappings:

https://lore.kernel.org/all/20260715183453.2381141-1-den@openvz.org

Lorenzo Stoakes fixed UAF caused by races between CPA and ptdump:

https://lore.kernel.org/all/20260723-series-vmap-race-fix-v6-0-8cc77dcc0018@kernel.org

and an issue with stale page tables in IOMMU:

https://lore.kernel.org/all/20260721-fix-cpa-kernel-pagetables-v2-1-2b255deed710@kernel.org

Mike Rapoport fixed a check of RW attribute in lookup_address_in_pgd_attr()
used for the verification of RWX:

https://lore.kernel.org/all/20260715144519.934289-1-rppt@kernel.org

Some of the fixes got merged into x86 tree, some of them got merged into mm
tree and some are still hanging in the air.

Beside the fixes there was a supposed simplification of cpa_lock locking 
that looked like removal of an optimization for DEBUG_PAGEALLOC, but it
turned out that it was not an optimization but rather a correctness
guard because with DEBUG_PAGEALLOC the locks could be taken in an atomic
context and couldn't use plain spin_lock()/spin_unlock().

The changes here are collected from all these fixes into a sinlge coherent
set on top of tip/x86/mm:
 
* update to cpa_lock handling with DEBUG_PAGEALLOC
* fix for races between CPA and ptdumpi causing UAF
* fix for stale page tables in IOMMU
* update to the fix of the race between split and collapse of large
  mappings
* fix for effective RW computation in lookup_address_in_pgd_attr()

Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
---
Lorenzo Stoakes (ARM) (3):
      x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF
      x86/mm/pat: acquire init_mm read lock on attribute change to avoid UAF
      x86/mm/pat: allocate split page tables as kernel page tables

Mike Rapoport (Microsoft) (2):
      x86/mm/pat: introcude cpa_lock() and cpa_unlock()
      x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr()

 arch/x86/mm/pat/set_memory.c | 95 +++++++++++++++++++++++++++++++-------------
 include/linux/mmap_lock.h    |  2 +
 2 files changed, 70 insertions(+), 27 deletions(-)
---
base-commit: a5a162fe1ae130e3d2ceefef3f43afe3773c1d56
change-id: 20260727-cpa-fixes-d3c73c075672

--
Sincerely yours,
Mike.



^ permalink raw reply	[flat|nested] 23+ messages in thread

end of thread, other threads:[~2026-07-28 16:02 UTC | newest]

Thread overview: 23+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-28 13:07 [PATCH 0/5] x86/mm/pat: CPA fixes Mike Rapoport (Microsoft)
2026-07-28 13:07 ` [PATCH 1/5] x86/mm/pat: introcude cpa_lock() and cpa_unlock() Mike Rapoport (Microsoft)
2026-07-28 13:13   ` Lorenzo Stoakes (ARM)
2026-07-28 14:21   ` Peter Zijlstra
2026-07-28 14:30     ` Dave Hansen
2026-07-28 14:31       ` Peter Zijlstra
2026-07-28 14:46         ` Mike Rapoport
2026-07-28 14:50           ` Lorenzo Stoakes (ARM)
2026-07-28 14:55           ` Peter Zijlstra
2026-07-28 15:01             ` Peter Zijlstra
2026-07-28 15:20               ` Lorenzo Stoakes (ARM)
2026-07-28 15:33                 ` Peter Zijlstra
2026-07-28 15:54                   ` Mike Rapoport
2026-07-28 15:02             ` Lorenzo Stoakes (ARM)
2026-07-28 15:30             ` Peter Zijlstra
2026-07-28 15:16   ` Peter Zijlstra
2026-07-28 16:01     ` Mike Rapoport
2026-07-28 13:07 ` [PATCH 2/5] x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF Mike Rapoport
2026-07-28 13:07 ` [PATCH 3/5] x86/mm/pat: acquire init_mm read lock on attribute change " Mike Rapoport
2026-07-28 13:14   ` Lorenzo Stoakes (ARM)
2026-07-28 13:07 ` [PATCH 4/5] x86/mm/pat: allocate split page tables as kernel page tables Mike Rapoport
2026-07-28 13:07 ` [PATCH 5/5] x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr() Mike Rapoport (Microsoft)
2026-07-28 13:11 ` [PATCH 0/5] x86/mm/pat: CPA fixes Lorenzo Stoakes (ARM)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).