From: Mike Rapoport <rppt@kernel.org>
To: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
Cc: Mark Brown <broonie@kernel.org>,
Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@kernel.org>,
"H. Peter Anvin" <hpa@zytor.com>,
Peter Zijlstra <peterz@infradead.org>,
Andrew Morton <akpm@linux-foundation.org>,
Dave Hansen <dave.hansen@linux.intel.com>,
Linux Kernel Mailing List <linux-kernel@vger.kernel.org>,
Linux Next Mailing List <linux-next@vger.kernel.org>
Subject: Re: linux-next: manual merge of the tip tree with the mm-hotfixes-unstable tree
Date: Mon, 27 Jul 2026 16:03:38 +0300 [thread overview]
Message-ID: <amdXKvl8NMM9S6bB@kernel.org> (raw)
In-Reply-To: <amdA05gNFyzg4Uwc@lucifer>
On Mon, Jul 27, 2026 at 12:33:30PM +0100, Lorenzo Stoakes (ARM) wrote:
> On Mon, Jul 27, 2026 at 08:48:31AM +0300, Mike Rapoport wrote:
> > Hi Mark,
> >
> > On Sun, Jul 26, 2026 at 10:33:53PM +0100, Mark Brown wrote:
> > > Hi all,
> > >
> > > Today's linux-next merge of the tip tree got a conflict in:
> > >
> > > arch/x86/mm/pat/set_memory.c
> > >
> > > between commits:
> > >
> > > 7a7c16a2d2b4d ("x86/mm/pat: acquire init_mm read lock on attribute change to avoid UAF")
> > > 25a54f65ccbaf ("x86/mm/pat: allocate split page tables as kernel page tables")
> > >
> > > from the mm-hotfixes-unstable tree and commit:
> > >
> > > 5fce67641a3ed ("x86/mm/pat: Don't gate cpa_lock on debug_pagealloc_enabled()")
> > >
> > > from the tip tree.
> > >
> > > I fixed it up (see below) and can carry the fix as necessary. This
> > > is now fixed as far as linux-next is concerned, but any non trivial
> > > conflicts should be mentioned to your upstream maintainer when your tree
> > > is submitted for merging. You may also want to consider cooperating
> > > with the maintainer of the conflicting tree to minimise any particularly
> > > complex conflicts.
> > >
> > > diff --cc arch/x86/mm/pat/set_memory.c
> > > index 422ce7fba00c6,1f2a2ba9ce57d..0000000000000
> > > --- a/arch/x86/mm/pat/set_memory.c
> > > +++ b/arch/x86/mm/pat/set_memory.c
> > > @@@ -440,30 -441,12 +443,32 @@@ static void __cpa_collapse_large_pages(
> > >
> > > list_for_each_entry_safe(ptdesc, tmp, &pgtables, pt_list) {
> > > list_del(&ptdesc->pt_list);
> > > - pagetable_free(ptdesc);
> > > + /*
> > > + * Only early alloc'd direct map should not be flagged PG_table
> > > + * here and those shouldn't be collapsed. However be abundantly
> > > + * cautious and handle the !PG_table case too.
> > > + */
> > > + if (PageTable((ptdesc_page(ptdesc))))
> > > + pagetable_dtor_free(ptdesc);
> > > + else
> > > + pagetable_free(ptdesc);
> > > }
> > > +
> > > + spin_unlock(&cpa_lock);
> > > }
> > >
> > > +static void cpa_collapse_large_pages(struct cpa_data *cpa)
> > > +{
> > > + /*
> > > + * Take the mmap write lock on init_mm to:
> > > + * - Avoid a use-after-free if raced by ptdump (which takes its own
> > > + * write lock on init_mm).
> > > + * - Serialise concurrent CPA walkers.
> > > + */
> > > + scoped_guard(mmap_write_lock, &init_mm)
> > > + __cpa_collapse_large_pages(cpa);
> > > +}
> > > +
> > > static void cpa_flush(struct cpa_data *cpa, int cache)
> > > {
> > > unsigned int i;
> > > @@@ -1254,22 -1237,16 +1258,20 @@@ __split_large_page(struct cpa_data *cpa
> > > static int split_large_page(struct cpa_data *cpa, pte_t *kpte,
> > > unsigned long address)
> > > {
> > > - struct ptdesc *ptdesc;
> > > + pte_t *pte;
> > >
> > > - if (!debug_pagealloc_enabled())
> > > - spin_unlock(&cpa_lock);
> > > + spin_unlock(&cpa_lock);
> >
> > This should be
> >
> > if (!debug_pagealloc_enabled())
> > spin_unlock(&cpa_lock);
> >
> > > - ptdesc = pagetable_alloc(GFP_KERNEL, 0);
> > > + if (cpa->init_mm_read_locked)
> > > + mmap_read_unlock(&init_mm);
> > > + pte = pte_alloc_one_kernel(&init_mm);
> > > + if (cpa->init_mm_read_locked)
> > > + mmap_read_lock(&init_mm);
> > > - if (!debug_pagealloc_enabled())
> > > - spin_lock(&cpa_lock);
> > > + spin_lock(&cpa_lock);
> >
> > And this
> >
> > if (!debug_pagealloc_enabled())
> > spin_lock(&cpa_lock);
> >
> > > - if (!ptdesc)
> > > + if (!pte)
> > > return -ENOMEM;
> > >
> > > - if (__split_large_page(cpa, kpte, address, ptdesc))
> > > - pagetable_free(ptdesc);
> > > + if (__split_large_page(cpa, kpte, address, pte))
> > > + pte_free_kernel(&init_mm, pte);
> > >
> > > return 0;
> > > }
> >
> >
> >
> > --
> > Sincerely yours,
> > Mike.
>
> Hmm, what's the status of the x86/mm trees on this though? AFAICT Denis's
> patch is still as-is and the spin_lock() vs. spin_[un]lock_irq*() issue
> raised in [0] is unaddressed?
Maybe it's best to take x86 cpa fixes via x86 tree in the end.
I collected them on top of the current tip/x86/mm:
https://git.kernel.org/pub/scm/linux/kernel/git/rppt/linux.git/log/?h=cpa-fixes
Can you please take a look and check I didn't miss anything? I'd like to
test it a bit more before sending out.
If we route your x86 fixes via x86 tree rather than mm tree there will be a
trivial conflict in definition of the new guards for mmap_lock, but other
than that they should merge nicely with generic and arm64 part of your UAF
set.
> Thanks, Lorenzo
>
> [0]:https://lore.kernel.org/all/al-MrKyIafA8QR_8@lucifer/
--
Sincerely yours,
Mike.
next prev parent reply other threads:[~2026-07-27 13:03 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-26 21:33 linux-next: manual merge of the tip tree with the mm-hotfixes-unstable tree Mark Brown
2026-07-27 5:48 ` Mike Rapoport
2026-07-27 11:33 ` Lorenzo Stoakes (ARM)
2026-07-27 13:03 ` Mike Rapoport [this message]
2026-07-27 18:15 ` Lorenzo Stoakes (ARM)
2026-07-27 11:38 ` Mark Brown
2026-07-27 13:09 ` Mike Rapoport
-- strict thread matches above, loose matches on Subject: below --
2026-07-21 13:46 Mark Brown
2026-07-21 16:14 ` Lorenzo Stoakes (ARM)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=amdXKvl8NMM9S6bB@kernel.org \
--to=rppt@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=broonie@kernel.org \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-next@vger.kernel.org \
--cc=ljs@kernel.org \
--cc=mingo@kernel.org \
--cc=peterz@infradead.org \
--cc=tglx@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox