From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
To: "Mike Rapoport (Microsoft)" <rppt@kernel.org>
Cc: Dave Hansen <dave.hansen@linux.intel.com>,
Andrew Morton <akpm@linux-foundation.org>,
Andy Lutomirski <luto@kernel.org>,
Borislav Petkov <bp@alien8.de>,
David CARLIER <devnexen@gmail.com>,
David Hildenbrand <david@kernel.org>,
Ingo Molnar <mingo@redhat.com>, Jason Gunthorpe <jgg@ziepe.ca>,
Juergen Gross <jgross@suse.com>,
Kevin Tian <kevin.tian@intel.com>,
Kiryl Shutsemau <kas@kernel.org>,
"Liam R. Howlett" <liam@infradead.org>,
Lu Baolu <baolu.lu@linux.intel.com>,
"H. Peter Anvin" <hpa@zytor.com>,
Peter Zijlstra <peterz@infradead.org>,
Shakeel Butt <shakeel.butt@linux.dev>,
Suren Baghdasaryan <surenb@google.com>,
Thomas Gleixner <tglx@kernel.org>,
Toshi Kani <toshi.kani@hpe.com>,
Vishal Moola <vishal.moola@gmail.com>,
Vlastimil Babka <vbabka@kernel.org>,
Will Deacon <will@kernel.org>,
iommu@lists.linux.dev, linux-kernel@vger.kernel.org,
linux-mm@kvack.org, stable@vger.kernel.org, x86@kernel.org,
syzbot@syzkaller.appspotmail.com
Subject: Re: [PATCH 0/5] x86/mm/pat: CPA fixes
Date: Tue, 28 Jul 2026 14:11:15 +0100 [thread overview]
Message-ID: <amiqDkAxFx60biG1@lucifer> (raw)
In-Reply-To: <20260728-cpa-fixes-v1-0-2ed2352300b3@kernel.org>
Ack on all my patches thanks!
Andrew - let's take the x86 patches from my series through the x86 tree, and the
core mm patches through the mm tree.
There's no ordering requirement in the x86 patches.
On Tue, Jul 28, 2026 at 04:07:43PM +0300, Mike Rapoport (Microsoft) wrote:
> There are a couple of CPA fixes floating around:
>
> Denis Lunev fixed races between split and collapse of the large mappings:
>
> https://lore.kernel.org/all/20260715183453.2381141-1-den@openvz.org
>
> Lorenzo Stoakes fixed UAF caused by races between CPA and ptdump:
>
> https://lore.kernel.org/all/20260723-series-vmap-race-fix-v6-0-8cc77dcc0018@kernel.org
>
> and an issue with stale page tables in IOMMU:
>
> https://lore.kernel.org/all/20260721-fix-cpa-kernel-pagetables-v2-1-2b255deed710@kernel.org
>
> Mike Rapoport fixed a check of RW attribute in lookup_address_in_pgd_attr()
> used for the verification of RWX:
>
> https://lore.kernel.org/all/20260715144519.934289-1-rppt@kernel.org
>
> Some of the fixes got merged into x86 tree, some of them got merged into mm
> tree and some are still hanging in the air.
:)))
>
> Beside the fixes there was a supposed simplification of cpa_lock locking
> that looked like removal of an optimization for DEBUG_PAGEALLOC, but it
> turned out that it was not an optimization but rather a correctness
> guard because with DEBUG_PAGEALLOC the locks could be taken in an atomic
> context and couldn't use plain spin_lock()/spin_unlock().
>
> The changes here are collected from all these fixes into a sinlge coherent
> set on top of tip/x86/mm:
>
> * update to cpa_lock handling with DEBUG_PAGEALLOC
> * fix for races between CPA and ptdumpi causing UAF
> * fix for stale page tables in IOMMU
> * update to the fix of the race between split and collapse of large
> mappings
> * fix for effective RW computation in lookup_address_in_pgd_attr()
Thanks for this!
>
> Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
> ---
> Lorenzo Stoakes (ARM) (3):
> x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF
> x86/mm/pat: acquire init_mm read lock on attribute change to avoid UAF
> x86/mm/pat: allocate split page tables as kernel page tables
>
> Mike Rapoport (Microsoft) (2):
> x86/mm/pat: introcude cpa_lock() and cpa_unlock()
> x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr()
>
> arch/x86/mm/pat/set_memory.c | 95 +++++++++++++++++++++++++++++++-------------
> include/linux/mmap_lock.h | 2 +
> 2 files changed, 70 insertions(+), 27 deletions(-)
> ---
> base-commit: a5a162fe1ae130e3d2ceefef3f43afe3773c1d56
> change-id: 20260727-cpa-fixes-d3c73c075672
>
> --
> Sincerely yours,
> Mike.
>
Cheers, Lorenzo
prev parent reply other threads:[~2026-07-28 13:11 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-28 13:07 [PATCH 0/5] x86/mm/pat: CPA fixes Mike Rapoport (Microsoft)
2026-07-28 13:07 ` [PATCH 1/5] x86/mm/pat: introcude cpa_lock() and cpa_unlock() Mike Rapoport (Microsoft)
2026-07-28 13:13 ` Lorenzo Stoakes (ARM)
2026-07-28 14:21 ` Peter Zijlstra
2026-07-28 14:30 ` Dave Hansen
2026-07-28 14:31 ` Peter Zijlstra
2026-07-28 14:46 ` Mike Rapoport
2026-07-28 14:50 ` Lorenzo Stoakes (ARM)
2026-07-28 14:55 ` Peter Zijlstra
2026-07-28 15:01 ` Peter Zijlstra
2026-07-28 15:20 ` Lorenzo Stoakes (ARM)
2026-07-28 15:33 ` Peter Zijlstra
2026-07-28 15:54 ` Mike Rapoport
2026-07-28 15:02 ` Lorenzo Stoakes (ARM)
2026-07-28 15:30 ` Peter Zijlstra
2026-07-28 15:16 ` Peter Zijlstra
2026-07-28 16:01 ` Mike Rapoport
2026-07-28 13:07 ` [PATCH 2/5] x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF Mike Rapoport
2026-07-28 13:07 ` [PATCH 3/5] x86/mm/pat: acquire init_mm read lock on attribute change " Mike Rapoport
2026-07-28 13:14 ` Lorenzo Stoakes (ARM)
2026-07-28 13:07 ` [PATCH 4/5] x86/mm/pat: allocate split page tables as kernel page tables Mike Rapoport
2026-07-28 13:07 ` [PATCH 5/5] x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr() Mike Rapoport (Microsoft)
2026-07-28 13:11 ` Lorenzo Stoakes (ARM) [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=amiqDkAxFx60biG1@lucifer \
--to=ljs@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=baolu.lu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=david@kernel.org \
--cc=devnexen@gmail.com \
--cc=hpa@zytor.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@ziepe.ca \
--cc=jgross@suse.com \
--cc=kas@kernel.org \
--cc=kevin.tian@intel.com \
--cc=liam@infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=luto@kernel.org \
--cc=mingo@redhat.com \
--cc=peterz@infradead.org \
--cc=rppt@kernel.org \
--cc=shakeel.butt@linux.dev \
--cc=stable@vger.kernel.org \
--cc=surenb@google.com \
--cc=syzbot@syzkaller.appspotmail.com \
--cc=tglx@kernel.org \
--cc=toshi.kani@hpe.com \
--cc=vbabka@kernel.org \
--cc=vishal.moola@gmail.com \
--cc=will@kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox