From nobody Sat Jul 25 04:30:16 2026 Received: from mail-pg1-f182.google.com (mail-pg1-f182.google.com [209.85.215.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8192837BE8E for ; Sat, 18 Jul 2026 09:57:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.182 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784368625; cv=none; b=P1z5x8Daodh3n4y2HGGS5keLyTxvTNzBjalOnkjwR7IMJm6ejr1mvr+EgOJprdt9WvO+kSU5UYtcNXzhgaqgypu1t79NgaCRtiVy5v0ZvxHaASXMUtYxZLuyrwFeOX4Br5IQK4HN12KSTcRJW5RNzWq1bnVfa9iFGRMhz4iL8mk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784368625; c=relaxed/simple; bh=BkhvyAl41lLtYiFI8zJ9qADiaAA2a0URAAzIw0G5FzI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=s3MH30gheB/NQZ49MoHdtx2BMe3XPtoGEClARZfam7q5/sjcTm7Iabxvyf09KxFR+Luc0ZGr4yTz+xCVrorWtDYHZ5G7bV/q5OiCGryJi9/x58kIgwu7Orptp6hdx/l46CtHBfK53x9+vZe53gBQThifCCfCVQYYiLBLS3s75L4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=LbQjlLHa; arc=none smtp.client-ip=209.85.215.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="LbQjlLHa" Received: by mail-pg1-f182.google.com with SMTP id 41be03b00d2f7-c9e3c0b6480so453664a12.0 for ; Sat, 18 Jul 2026 02:57:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784368624; x=1784973424; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=NM59zTITSAnSgD8fALdagpl6xYMLVePtK5I+sk28JTE=; b=LbQjlLHa39blSNw0WgGm9rt3xMQXAN3qbxZsiUkSWXtMEheIOYEPFZFyDgMNo0QV9r JL7U+V2vJbJbuyGlVBxgzJMz0Op5SBOY+83lGJYLUz9MICNiZzQtzr6fzoNKE8iisqw5 /3+qedqqVV0q1Ovfmu+vccjuRCrXtSKuz7geq9J+hSfTUVxwqDzKo6EcTcNJjGQL4ouZ Zg0aiGH4jgyzVIVu88AOKhe4Cdlb8kEL2iZIyX2UR5JgbVghWfW3Rq8PUuQcbgmYj+yI ldDIFOasXH7IxRGi//izIZ2pLPklQPjZ3/PAYKN0o7vr7Jn8YpBwNNDLpc64obLNwxnW /V/Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784368624; x=1784973424; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=NM59zTITSAnSgD8fALdagpl6xYMLVePtK5I+sk28JTE=; b=RMurIbeUz6M2kFDRElKGjRtvvHOKj3XEmDBkBv0t4KMQ1RLb8Z3vbevmtUmPYOEvv4 N1r/P4/kmyb4m7DzI+jLqRQV3AkavCWhfAAYSypCFZZ8tIkJAfdBoBoNtiS9t/i5lm5v jG9n65bRihwMF4te/LOAbrn5Q/INpV/WF2VVblLhOZrFV1JuQ1x77MkZUU1P8UUcMDbH FZ1sEdxZhFEoC/Y41dUJOmrRTlg9nNd7zfSep+Eo0Mqz92kTTUP7hKhgbq07x69a2div jFiFS2Bm17Imxw9RKmApNRtlCT2lWozf42UKVutK3wgiyFStTijNfUyk41JBmrWaLhfp WdJg== X-Gm-Message-State: AOJu0YywQdRCmjo9kJk7ulBTbwOHd3Tysqx+NzLQurBX2jFGH1rc3LN3 3tpYJ+JZUHdUf5HPLD2ydsP2PkgMbsgBTP2qYB9ESEP9PbABDKwbbSe1 X-Gm-Gg: AfdE7ckpHFJXGwPYkWh5larVBwockyGCWgmS0jiouDpcb3KihSrGd4uPxxe6L9UdSWz y4K2AX+4TGe6C2Trq2hf0RehRnBBkSiluOG9mL/VnA02nxxH5JsieloYKjm4PW7wj9zoL0uvJ9i OJ5Lopr5WjLfynZEz3yj7jBCFBG5rE9uOmqgT1w2PhqVNqA0kSRcH0gnREbdrSWE1FqOXwm7Qu+ JYx5cIyDkdyX7Vc8f4f50wJ18IY/q9bACbHSGxxG67veA+y8E3hvgdQoI6/fwo3bzfo1N+1fHE4 dpItIS9i/6W2UrED1zSJrX6GHfFVbDjwzAUS9XuRvA7b/W3NVN68mrYM/ezyV6oF4uZvPkJ+pDB 3ghHTFy1AxnqRnSSUMLhGoXNGdEpMIBhBMFiNrE8qV5EnVCURZwJIb3q6h7op90E4pf+oxfjzOP p90RPvHrt4UCbGw+JGWaTs7Akq7rbKHOhgKG+XcyuOofKz X-Received: by 2002:a05:6a00:7287:b0:847:88aa:4f4f with SMTP id d2e1a72fcca58-84c29510c82mr3438599b3a.7.1784368623754; Sat, 18 Jul 2026 02:57:03 -0700 (PDT) Received: from debian.lan ([240e:391:eb4:a240::1]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84c2af317c8sm2417248b3a.30.2026.07.18.02.56.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 18 Jul 2026 02:57:03 -0700 (PDT) From: Xueyuan Chen To: linux-mm@kvack.org, Andrew Morton , David Hildenbrand , Lorenzo Stoakes Cc: linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, Catalin Marinas , Will Deacon , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H . Peter Anvin" , Andy Lutomirski , Peter Zijlstra , Lance Yang , Usama Arif , Jann Horn , Yang Shi , Mike Rapoport , Zi Yan , Baolin Wang , "Liam R . Howlett" , Nico Pache , Ryan Roberts , Dev Jain , Barry Song , Xueyuan Chen Subject: [RFC PATCH v4 1/3] mm: make persistent huge zero folio read-only Date: Sat, 18 Jul 2026 17:56:45 +0800 Message-ID: <20260718095647.182592-2-xueyuan.chen21@gmail.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260718095647.182592-1-xueyuan.chen21@gmail.com> References: <20260718095647.182592-1-xueyuan.chen21@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The persistent huge zero folio is shared globally and should stay zero after initialization. As Jann Horn pointed out[1], kernel bugs have ended up writing to pages that were meant to be read-only, including in security-sensitive cases. Making the persistent huge zero folio read-only in the direct map turns such writes into faults instead of silent zero-page corruption. Add set_direct_map_ro_noflush() so mm code can make a direct-map range read-only. Use an address-based signature to match ongoing direct-map helper work[2], where existing page-based helpers may move the same way. The helper is direct-map specific and leaves TLB invalidation to its caller. Architectures without direct-map permission support keep existing behavior through the generic stub. The folio is allocated and zeroed through the writable direct map before thp_shrinker_init() changes its permissions. thp_shrinker_init() is called from hugepage_init(), which is registered as a subsys_initcall and runs after SMP initialization. Stale writable kernel TLB entries may therefore exist. Flush the direct-map range immediately after the page-table update so they cannot bypass the read-only mapping. Treat the direct-map permission change as best-effort. Architectures that do not implement the helper keep the existing behavior via the generic stub. Inspired by Jann Horn's read-only zero page work[1] and follow-up discussion[3] with Yang Shi. [1] https://lore.kernel.org/linux-mm/20260508-ro-zeropage-v1-1-9808abc20b49= @google.com/ [2] https://lore.kernel.org/linux-mm/0e5b23a6-4895-454a-9dfa-6dc21adc2991@k= ernel.org/ [3] https://lore.kernel.org/linux-mm/CAHbLzkrXXe7r3n3jXgDKtwZhRqj=3DjDx9E6d= LOULohnhBguvi9A@mail.gmail.com/ Suggested-by: David Hildenbrand Suggested-by: Usama Arif Co-developed-by: Lance Yang Signed-off-by: Lance Yang Signed-off-by: Xueyuan Chen --- include/linux/set_memory.h | 29 +++++++++++++++++++++++++++++ mm/huge_memory.c | 16 +++++++++++++++- 2 files changed, 44 insertions(+), 1 deletion(-) diff --git a/include/linux/set_memory.h b/include/linux/set_memory.h index 3030d9245f5a..e83ced6a3827 100644 --- a/include/linux/set_memory.h +++ b/include/linux/set_memory.h @@ -40,6 +40,24 @@ static inline int set_direct_map_valid_noflush(struct pa= ge *page, return 0; } =20 +/** + * set_direct_map_ro_noflush - make a direct-map range read-only + * @addr: start address in the direct map + * @nr_pages: number of pages starting at @addr + * + * Make the direct-map range starting at @addr read-only without invalidat= ing + * TLBs. Callers must either ensure that no stale writable translations can + * be used, or treat the permission change as a best-effort hardening step. + * + * Return: 0 on success or when direct-map permission changes are unsuppor= ted, + * or a negative errno on failure. + */ +static inline int set_direct_map_ro_noflush(const void *addr, + unsigned long nr_pages) +{ + return 0; +} + static inline bool kernel_page_present(struct page *page) { return true; @@ -56,6 +74,17 @@ static inline bool can_set_direct_map(void) } #define can_set_direct_map can_set_direct_map #endif + +#ifndef set_direct_map_ro_noflush +/* See the comment above the generic fallback for the _noflush contract. */ +static inline int set_direct_map_ro_noflush(const void *addr, + unsigned long nr_pages) +{ + return 0; +} + +#define set_direct_map_ro_noflush set_direct_map_ro_noflush +#endif #endif /* CONFIG_ARCH_HAS_SET_DIRECT_MAP */ =20 #ifdef CONFIG_X86_64 diff --git a/mm/huge_memory.c b/mm/huge_memory.c index 970e077019b7..4425ae5560cb 100644 --- a/mm/huge_memory.c +++ b/mm/huge_memory.c @@ -40,8 +40,10 @@ #include #include #include +#include =20 #include +#include #include "internal.h" #include "swap.h" =20 @@ -932,6 +934,8 @@ static int __init thp_shrinker_init(void) shrinker_register(deferred_split_shrinker); =20 if (IS_ENABLED(CONFIG_PERSISTENT_HUGE_ZERO_FOLIO)) { + unsigned long addr; + /* * Bump the reference of the huge_zero_folio and do not * initialize the shrinker. @@ -940,8 +944,18 @@ static int __init thp_shrinker_init(void) * that get_huge_zero_folio() will most likely not fail as * thp_shrinker_init() is invoked early on during boot. */ - if (!get_huge_zero_folio()) + if (!get_huge_zero_folio()) { pr_warn("Allocating persistent huge zero folio failed\n"); + return 0; + } + + addr =3D (unsigned long)folio_address(huge_zero_folio); + /* + * The folio was zeroed through the writable direct map. Flush + * after the page-table update to invalidate stale translations. + */ + set_direct_map_ro_noflush((void *)addr, HPAGE_PMD_NR); + flush_tlb_kernel_range(addr, addr + HPAGE_PMD_SIZE); return 0; } =20 --=20 2.47.3 From nobody Sat Jul 25 04:30:16 2026 Received: from mail-pl1-f169.google.com (mail-pl1-f169.google.com [209.85.214.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7158D384258 for ; Sat, 18 Jul 2026 09:57:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.169 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784368632; cv=none; b=UnZYwa0BFPPKqLct+4licHl/JayeY1ZUoLyXuQ8sP1YSpp103XsfkvoH1DfsYZ05oA1bZGhm5LDuuJbkeTxqoLUny8BLzoxXV8mJ+gjR9DcFAwIxMNw5IWFVIvw3q0yBFFEReritqEd0p2tUMgM5Jnsnkfn1Nd3oWOSmuAJJNwY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784368632; c=relaxed/simple; bh=21ZuBpHqoPYqHnweWse0rj1WqEhRVoPtbLK1UXr3wTE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GmIrivzqaWs66kmZWrnP21sQgscaMV5apc9l9IgXh5FQBTqcYvH+HwWbIqGj+5mYUGyDLuA+Bdrh/+jwJuf+p8dmqUe+/f6j4830LGQUpIUKLbowYmTgWFbRyRqDEdRqaibiItLesMrJKFcLnLgNEEvcfCi0MC3ZdGaygJ/a4Zs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=sR2/ksYp; arc=none smtp.client-ip=209.85.214.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="sR2/ksYp" Received: by mail-pl1-f169.google.com with SMTP id d9443c01a7336-2cf49dc28ccso1071085ad.0 for ; Sat, 18 Jul 2026 02:57:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784368631; x=1784973431; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ObdtBSjlBwpgFGsbg/wrosB7LM91UtGEZki+/E5+WZ0=; b=sR2/ksYp0mctBnl0rqenXNhPn36hUpbC2oERDV0W5SMsutoGVRiT4H/DhTTcxM6aOV U6/i+DjimSed+Q5HOYcpiZ0zorL9VWMcAobiZjIxl9GByJIw5pzCiXGhtAvTaEDlA/WQ zmciWBck7IN6q027KEpYIkzwIdnzPBQD8gjtvZVLvDg+JSkpuymTuCOm/cePm+Z5XBmx IH9SzZmZeV8wIdWniQ+yOAKjBwmHj3Qw4POavwzNOoTbPYsGfDl9TmhtYM61313g3z0a DkJ9mgH8+oGtNVK3IMSe4NZDND1PlzUX7wfKl+PoIsq0UetpsiJK1f9WGFSP+JZl/Gzc 1kDw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784368631; x=1784973431; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ObdtBSjlBwpgFGsbg/wrosB7LM91UtGEZki+/E5+WZ0=; b=cdciCBON9joJVIGoioIMikWSmape/vi/mHhRzHup5UrOvy0a8BRQkbRPUb55B4j/iq y4xPEImBvE0JpXpcl9wloo0hdMHF9jC8MDArFcXIbxfFjqVWTgblZ7UKSNGl6F//gJdy nRDpSwJLkmz3qm29iIv+sJU/9TBy59E9HubCZOPDxkYN81rvXUTFDjV69B48rU4kTa+0 fNa0V5z2xe36l865BvySLxHgM+FsPigbcJyOAdQiHkXJ0r/8+IfJ3DZc1epvbOMDyAJQ VIcrIMsENlFZbv3oTVlOySf0mcOCD+/tDst9lgWVU+hsVxvfXVPQrr79z8KYZzxlXbSg 1Org== X-Gm-Message-State: AOJu0YwcEKk5rsQosNXZb5hGCg+BYXeJiH2sCpXv62BQ1SFbvF2adidy NPFouybNUQ2VjLyBPR2YNLBBskwHr8XkBWNU15FPYxNB6o2q5993SNwX X-Gm-Gg: AfdE7cmoYp4DtQGvhrXMqeH0OAEwIRrSWAogU/oo9AswOrFfGL22mT3uHKwIrbLJEmc yvVx5eMEKT9ST6wikSCBLltM5b16ZbvU9SlcYYCmJfAjf8iMGYBfYIjdgnmU82GGC0l3GdgXngQ IiKRYI6pTSLOUbv6X4xDz8D1LM3Cj1zmxNALxEZIVtfgi92EVVLGaxKedXkXRojvMNIiZaYgsG8 SU710waLZFB+2kkBkODPITCM3z75P+A8ncOWfLDFAMadFzDBMrwt8A9/zw/SX+jTGhDI6aBiA6c c10XBIxb4kgoWIOoqgQf8grGPe8Vt0eiwMEwG2D4nqFzuV4wZ3OfbbFtagYsx4zWFX/Yewk/7pC ml27YivYkJHYH78Ts5+3fHnQdFdzU6Z523dQJNh0anb5RxMtSRSHYMx/TWDhne+6M7lHpCQsepV TqZmHV4RjYuAIp1Ons9x8Lkim5ffN8IKtRlIg/4UOSc5iM X-Received: by 2002:a05:6a20:9397:b0:3b4:7aae:1eed with SMTP id adf61e73a8af0-3c3ad91f768mr4682057637.4.1784368630603; Sat, 18 Jul 2026 02:57:10 -0700 (PDT) Received: from debian.lan ([240e:391:eb4:a240::1]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84c2af317c8sm2417248b3a.30.2026.07.18.02.57.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 18 Jul 2026 02:57:10 -0700 (PDT) From: Xueyuan Chen To: linux-mm@kvack.org, Andrew Morton , David Hildenbrand , Lorenzo Stoakes Cc: linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, Catalin Marinas , Will Deacon , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H . Peter Anvin" , Andy Lutomirski , Peter Zijlstra , Lance Yang , Usama Arif , Jann Horn , Yang Shi , Mike Rapoport , Zi Yan , Baolin Wang , "Liam R . Howlett" , Nico Pache , Ryan Roberts , Dev Jain , Barry Song , Xueyuan Chen Subject: [RFC PATCH v4 2/3] arm64/mm: add set_direct_map_ro_noflush() Date: Sat, 18 Jul 2026 17:56:46 +0800 Message-ID: <20260718095647.182592-3-xueyuan.chen21@gmail.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260718095647.182592-1-xueyuan.chen21@gmail.com> References: <20260718095647.182592-1-xueyuan.chen21@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Implement set_direct_map_ro_noflush() for arm64 with update_range_prot() on the linear map, setting PTE_RDONLY and clearing PTE_WRITE. Keep the existing can_set_direct_map() guard and leave TLB invalidation to the caller. Co-developed-by: Lance Yang Signed-off-by: Lance Yang Signed-off-by: Xueyuan Chen --- arch/arm64/include/asm/set_memory.h | 2 ++ arch/arm64/mm/pageattr.c | 10 ++++++++++ 2 files changed, 12 insertions(+) diff --git a/arch/arm64/include/asm/set_memory.h b/arch/arm64/include/asm/s= et_memory.h index 90f61b17275e..7083260303c3 100644 --- a/arch/arm64/include/asm/set_memory.h +++ b/arch/arm64/include/asm/set_memory.h @@ -14,6 +14,8 @@ int set_memory_valid(unsigned long addr, int numpages, in= t enable); int set_direct_map_invalid_noflush(struct page *page); int set_direct_map_default_noflush(struct page *page); int set_direct_map_valid_noflush(struct page *page, unsigned nr, bool vali= d); +int set_direct_map_ro_noflush(const void *addr, unsigned long nr_pages); +#define set_direct_map_ro_noflush set_direct_map_ro_noflush bool kernel_page_present(struct page *page); =20 int set_memory_encrypted(unsigned long addr, int numpages); diff --git a/arch/arm64/mm/pageattr.c b/arch/arm64/mm/pageattr.c index ce035e1b4eaf..c51236b61651 100644 --- a/arch/arm64/mm/pageattr.c +++ b/arch/arm64/mm/pageattr.c @@ -365,6 +365,16 @@ int set_direct_map_valid_noflush(struct page *page, un= signed nr, bool valid) return set_memory_valid(addr, nr, valid); } =20 +int set_direct_map_ro_noflush(const void *addr, unsigned long nr_pages) +{ + if (!can_set_direct_map()) + return 0; + + return update_range_prot((unsigned long)addr, PAGE_SIZE * nr_pages, + __pgprot(PTE_RDONLY), + __pgprot(PTE_WRITE)); +} + #ifdef CONFIG_DEBUG_PAGEALLOC /* * This is - apart from the return value - doing the same --=20 2.47.3 From nobody Sat Jul 25 04:30:16 2026 Received: from mail-pf1-f180.google.com (mail-pf1-f180.google.com [209.85.210.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9921A3845CF for ; Sat, 18 Jul 2026 09:57:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784368638; cv=none; b=MsSoztsBFJloPLRTPnSEBt6dPA136JgmW/X1ce/W/92QKnt+u0lhmGAh9OfBtaI+DOJELJyQ+b4MkqOFcjGC+D3jNaZpbyX2QOd480TehNSt/cdE7TmLmX07Q7rZsbNIjnAFSH8dMXy62uXS125QGHzFyjfYejirahyQ8ZxbRus= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784368638; c=relaxed/simple; bh=Udw3VmtBDGMh03w4Ye2QpMgmiRbGy9bBJEkA5F6Eo1I=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=H5WDe79YUkAnX2zHSAqIiaHAtWjBNA65B3F+Qms9JcqIdmd3JZ+mPvk/yWwaqfYi/7YNv7s2b2YeV0BPgJ+93h1iCz7kxUWQeaUGVG2WdNl4a9KMOwS3TJLa9Sym6nOO1c09HqgbHDPwa2HCOYmiCN3lzykWdg95zOYCCbP/Wzc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ZfSKS+J9; arc=none smtp.client-ip=209.85.210.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ZfSKS+J9" Received: by mail-pf1-f180.google.com with SMTP id d2e1a72fcca58-8423f52cd57so1185391b3a.2 for ; Sat, 18 Jul 2026 02:57:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784368637; x=1784973437; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5hdCu1wf2k5fVGlVM7jRlnxeinlriHXvmsiXxLfmcKs=; b=ZfSKS+J9oB9zuVwsLU6Gw9/NlXlilPKfD+1id8+55QXhtOazp3q+cF4qlRMrO3Uq4Z FQ7Np52jcsyWMYBhFvtrHYOUtVSWUQn8nBEl/AVFeuK4jwtbYAREdwtHhPbdpECbnlgQ ItONHQqQraEzdYXB4/XTS2/9iON0YnMNdYs3l90e3x9mp0NGpeL7PIQQpk/8CUDAWhZv zlrJvkAkE4OYUy5bcx9s2Ar4PJnvYKwWatXjmlofj88Gy2mwvwijcF2vEhtLlX4Pr4dX lam805C9bubVnbUbc2S6Tn6VMdFvgHCvZMVlfPMWobITIMiursbxZXH3qRFrCeTFtpQ7 MJKw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784368637; x=1784973437; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=5hdCu1wf2k5fVGlVM7jRlnxeinlriHXvmsiXxLfmcKs=; b=mhnbsVuuZnsTX132d11gGQ3n2JUxA09moTy9VRY/3ILQNdBNUerG06zQR5yJ82dnPE 83d9xNGE52m2oH8u2tBVY3w5B+Cf/LAnCFf1rwQTHlPMx2YseJBr0MWAoBgMaYhytoSz luL6EcV+dHy2LBmx+n4C0t6pWvi17e42YrUx2dYvIE5uhj7OkxMU2sMnoIuKPmS42Q0f qELNfh9aGhIinYUEqHBjgPCgN4QIbWd7tzT64EL2Tm6NnCOg9PtFpUFaXGF43TwuaYXt 18ZnxQ+F8Pig40BaVx5TBWm5rtdOV6KGRUV60BLo90EDfG1luBjK8E7cPbqIZ7x5FqLo /7pA== X-Gm-Message-State: AOJu0YwBIpLPlhiUX+gpyWmKO7i0Upj/c1/JtnaDp8gFcbzEdwCx9Xuf 0sJ13Hrd0T/X8oAW7My+oQBz2gbJ2CW4TGLJLqt0205E2HdN/hYNqIAs X-Gm-Gg: AfdE7clePZTWW67FsdIdL/30G5Tz64JSV1U1a2gvpG1KYfmyy/1bwYjC39Eb7D1q9v4 ehS17k+cVTnMGzg1mH8g7S5isnXm5BdWWDWM3GRyzOao7EZPMnSCPvYU5uIA2psiIPUEDHHlrMd rMzy0dgyh7N1f9/sbBpOj/BBUVIRKOJga8gLxGYP+Qcca2WZ3mWeej1BpaNI3mp2IgVntEb6nfa 82FK1V5jodq7gJdggQVaoPMLJxK7Zr+xGsVqiuhpvujM3UkRhbK86ybzV8Su+2HPKEqB+oy+PHQ XGRxjc4jn6Nw5WgJ2H9Kpd6oRxheLoVwqJAIrOzZBJG7h5YE7STu+TMItW4mEKWpHYUri/BW8NK qXQw7P7cqW5fmsjUuZUFEdm8dq+DPTnG27/VqgkObgWXy+yHFR13CZmHERJ/PP2E4kSADRebDom ilHB+T9GaJc3aZFxN3eWXj28infVJvYu6jZDrss5B4wJlw X-Received: by 2002:a05:6a00:9499:b0:842:5a18:9af0 with SMTP id d2e1a72fcca58-84c2917f212mr4248164b3a.0.1784368636739; Sat, 18 Jul 2026 02:57:16 -0700 (PDT) Received: from debian.lan ([240e:391:eb4:a240::1]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84c2af317c8sm2417248b3a.30.2026.07.18.02.57.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 18 Jul 2026 02:57:16 -0700 (PDT) From: Xueyuan Chen To: linux-mm@kvack.org, Andrew Morton , David Hildenbrand , Lorenzo Stoakes Cc: linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, Catalin Marinas , Will Deacon , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H . Peter Anvin" , Andy Lutomirski , Peter Zijlstra , Lance Yang , Usama Arif , Jann Horn , Yang Shi , Mike Rapoport , Zi Yan , Baolin Wang , "Liam R . Howlett" , Nico Pache , Ryan Roberts , Dev Jain , Barry Song , Xueyuan Chen Subject: [RFC PATCH v4 3/3] x86/mm: add set_direct_map_ro_noflush() Date: Sat, 18 Jul 2026 17:56:47 +0800 Message-ID: <20260718095647.182592-4-xueyuan.chen21@gmail.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260718095647.182592-1-xueyuan.chen21@gmail.com> References: <20260718095647.182592-1-xueyuan.chen21@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Implement set_direct_map_ro_noflush() for x86 using CPA directly on the passed direct-map address. Clear _PAGE_RW and _PAGE_DIRTY, keep alias checks disabled like the existing direct-map _noflush helpers, and leave TLB invalidation to the caller. Co-developed-by: Lance Yang Signed-off-by: Lance Yang Signed-off-by: Xueyuan Chen --- arch/x86/include/asm/set_memory.h | 2 ++ arch/x86/mm/pat/set_memory.c | 15 +++++++++++++++ 2 files changed, 17 insertions(+) diff --git a/arch/x86/include/asm/set_memory.h b/arch/x86/include/asm/set_m= emory.h index 4362c26aa992..bd3817e06052 100644 --- a/arch/x86/include/asm/set_memory.h +++ b/arch/x86/include/asm/set_memory.h @@ -89,6 +89,8 @@ int set_pages_rw(struct page *page, int numpages); int set_direct_map_invalid_noflush(struct page *page); int set_direct_map_default_noflush(struct page *page); int set_direct_map_valid_noflush(struct page *page, unsigned nr, bool vali= d); +int set_direct_map_ro_noflush(const void *addr, unsigned long nr_pages); +#define set_direct_map_ro_noflush set_direct_map_ro_noflush bool kernel_page_present(struct page *page); =20 extern int kernel_set_to_readonly; diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c index d023a40a1e03..5987f4c84f6f 100644 --- a/arch/x86/mm/pat/set_memory.c +++ b/arch/x86/mm/pat/set_memory.c @@ -2662,6 +2662,21 @@ int set_direct_map_valid_noflush(struct page *page, = unsigned nr, bool valid) return __set_pages_np(page, nr); } =20 +int set_direct_map_ro_noflush(const void *addr, unsigned long nr_pages) +{ + unsigned long tempaddr =3D (unsigned long)addr; + struct cpa_data cpa =3D { + .vaddr =3D &tempaddr, + .pgd =3D NULL, + .numpages =3D nr_pages, + .mask_set =3D __pgprot(0), + .mask_clr =3D __pgprot(_PAGE_RW | _PAGE_DIRTY), + .flags =3D CPA_NO_CHECK_ALIAS, + }; + + return __change_page_attr_set_clr(&cpa, 1); +} + #ifdef CONFIG_DEBUG_PAGEALLOC void __kernel_map_pages(struct page *page, int numpages, int enable) { --=20 2.47.3