[PATCH v2 0/5] x86/mm/pat: CPA fixes

Mike Rapoport posted 5 patches 1 month, 2 weeks ago
arch/x86/kernel/alternative.c | 39 ++++++++++++++++++++++++---
arch/x86/mm/pat/set_memory.c  | 61 +++++++++++++++++++++++++++++++------------
include/linux/mmap_lock.h     |  2 ++
3 files changed, 83 insertions(+), 19 deletions(-)
[PATCH v2 0/5] x86/mm/pat: CPA fixes
Posted by Mike Rapoport 1 month, 2 weeks ago
The first three patches are urgent, the third patch fixes BUG() reported
y several people and it depends on the first two.

There were no bug reports that the last two patches fix because bug
manifestations won't yell at users.

TL;DR version:

There are a couple of CPA fixes floating around:

Denis Lunev fixed races between split and collapse of the large mappings:

https://lore.kernel.org/all/20260715183453.2381141-1-den@openvz.org

Lorenzo Stoakes fixed UAF caused by races between CPA and ptdump:

https://lore.kernel.org/all/20260723-series-vmap-race-fix-v6-0-8cc77dcc0018@kernel.org

and an issue with stale page tables in IOMMU:

https://lore.kernel.org/all/20260721-fix-cpa-kernel-pagetables-v2-1-2b255deed710@kernel.org

Mike Rapoport fixed a check of RW attribute in lookup_address_in_pgd_attr()
used for the verification of RWX:

https://lore.kernel.org/all/20260715144519.934289-1-rppt@kernel.org

Pedro Falcato closed a race between text poking and collapse of large
pages:

https://lore.kernel.org/all/anCK3eWFMwZqq5ka@pedro-suse

Some of the fixes got merged into x86 tree, some of them got merged into mm
tree and some are still hanging in the air.

The changes here are collected from all these fixes into a single coherent
set on top of tip/x86/mm:
 
* fix for races between CPA and ptdump causing UAF
* update to the fix of the race between split and collapse of large
  mappings
* fix for races between CPA and vmalloc_to_page() in text poking
* fix for stale page tables in IOMMU
* fix for effective RW computation in lookup_address_in_pgd_attr()

---
v2 changes:
* rebased on the current tip/x86/mm that includes peterz's changes for
  DEBUG_PAGEALLOC
* added fix for CPA vs text poking race

v1: https://patch.msgid.link/20260728-cpa-fixes-v1-0-2ed2352300b3@kernel.org

---
Lorenzo Stoakes (ARM) (3):
      x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF
      x86/mm/pat: acquire init_mm read lock on attribute change to avoid UAF
      x86/mm/pat: allocate split page tables as kernel page tables

Mike Rapoport (Microsoft) (1):
      x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr()

Pedro Falcato (1):
      x86/alternative: exclude text poking against change_page_attr()

 arch/x86/kernel/alternative.c | 39 ++++++++++++++++++++++++---
 arch/x86/mm/pat/set_memory.c  | 61 +++++++++++++++++++++++++++++++------------
 include/linux/mmap_lock.h     |  2 ++
 3 files changed, 83 insertions(+), 19 deletions(-)
---
base-commit: 7da514d819a0afb148634aac92b3d190f34947c3
change-id: 20260727-cpa-fixes-d3c73c075672

--
Sincerely yours,
Mike.
Re: [PATCH v2 0/5] x86/mm/pat: CPA fixes
Posted by Atish Patra 1 month ago
On 8/13/26 2:01 AM, Mike Rapoport wrote:
> The first three patches are urgent, the third patch fixes BUG() reported
> y several people and it depends on the first two.
>
> There were no bug reports that the last two patches fix because bug
> manifestations won't yell at users.
>
> TL;DR version:
>
> There are a couple of CPA fixes floating around:
>
> Denis Lunev fixed races between split and collapse of the large mappings:
>
> https://lore.kernel.org/all/20260715183453.2381141-1-den@openvz.org
>
> Lorenzo Stoakes fixed UAF caused by races between CPA and ptdump:
>
> https://lore.kernel.org/all/20260723-series-vmap-race-fix-v6-0-8cc77dcc0018@kernel.org
>
> and an issue with stale page tables in IOMMU:
>
> https://lore.kernel.org/all/20260721-fix-cpa-kernel-pagetables-v2-1-2b255deed710@kernel.org
>
> Mike Rapoport fixed a check of RW attribute in lookup_address_in_pgd_attr()
> used for the verification of RWX:
>
> https://lore.kernel.org/all/20260715144519.934289-1-rppt@kernel.org
>
> Pedro Falcato closed a race between text poking and collapse of large
> pages:
>
> https://lore.kernel.org/all/anCK3eWFMwZqq5ka@pedro-suse
>
> Some of the fixes got merged into x86 tree, some of them got merged into mm
> tree and some are still hanging in the air.
>
> The changes here are collected from all these fixes into a single coherent
> set on top of tip/x86/mm:
>   
> * fix for races between CPA and ptdump causing UAF
> * update to the fix of the race between split and collapse of large
>    mappings
> * fix for races between CPA and vmalloc_to_page() in text poking
> * fix for stale page tables in IOMMU
> * fix for effective RW computation in lookup_address_in_pgd_attr()
>
> ---
> v2 changes:
> * rebased on the current tip/x86/mm that includes peterz's changes for
>    DEBUG_PAGEALLOC
> * added fix for CPA vs text poking race
>
> v1: https://patch.msgid.link/20260728-cpa-fixes-v1-0-2ed2352300b3@kernel.org
>
> ---
> Lorenzo Stoakes (ARM) (3):
>        x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF
>        x86/mm/pat: acquire init_mm read lock on attribute change to avoid UAF
>        x86/mm/pat: allocate split page tables as kernel page tables
>
> Mike Rapoport (Microsoft) (1):
>        x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr()
>
> Pedro Falcato (1):
>        x86/alternative: exclude text poking against change_page_attr()
>
>   arch/x86/kernel/alternative.c | 39 ++++++++++++++++++++++++---
>   arch/x86/mm/pat/set_memory.c  | 61 +++++++++++++++++++++++++++++++------------
>   include/linux/mmap_lock.h     |  2 ++
>   3 files changed, 83 insertions(+), 19 deletions(-)
> ---
> base-commit: 7da514d819a0afb148634aac92b3d190f34947c3
> change-id: 20260727-cpa-fixes-d3c73c075672

Reproduced and verified this series (patches 1-3) on 4vcpu guest running two different kernels
1. mainline (commit: 77ae27fd98f3)
2. Ubuntu Resolute 7.0.0-26 (production kernel hitting the issue in a VM)

The Reproducer consisted of
1. A debug patch a cmdline-gated stall between the two *pmd reads in vmalloc_to_page()
2. One taskset-pinned insmod/rmmod worker per module over stock cfg80211/dummy/veth modules

With the above reproducer, both BUG within seconds in unpatched kernel.
1. Resolute in 0.71s at alternative.c:2564 (BUG_ON(!pages[0] ...), RAX=0)
2. mainline at alternative.c:2473 (BUG_ON(memcmp(addr, src, len))).

With patches 1-3: zero splats across 10 runs each (600s/11,378 module load/unload cycles on mainline and 1200s/55,980 module load/unload cycles on Resolute).


Tested-by: Atish Patra<atishp@meta.com>

> --
> Sincerely yours,
> Mike.
>
Re: [PATCH v2 0/5] x86/mm/pat: CPA fixes
Posted by Lorenzo Stoakes (ARM) 1 month ago
On Tue, Aug 25, 2026 at 12:12:32AM -0700, Atish Patra wrote:
> Reproduced and verified this series (patches 1-3) on 4vcpu guest running two different kernels
> 1. mainline (commit: 77ae27fd98f3)
> 2. Ubuntu Resolute 7.0.0-26 (production kernel hitting the issue in a VM)
>
> The Reproducer consisted of
> 1. A debug patch a cmdline-gated stall between the two *pmd reads in vmalloc_to_page()
> 2. One taskset-pinned insmod/rmmod worker per module over stock cfg80211/dummy/veth modules
>
> With the above reproducer, both BUG within seconds in unpatched kernel.
> 1. Resolute in 0.71s at alternative.c:2564 (BUG_ON(!pages[0] ...), RAX=0)
> 2. mainline at alternative.c:2473 (BUG_ON(memcmp(addr, src, len))).
>
> With patches 1-3: zero splats across 10 runs each (600s/11,378 module load/unload cycles on mainline and 1200s/55,980 module load/unload cycles on Resolute).

Amazing, thanks!

>
>
> Tested-by: Atish Patra<atishp@meta.com>

I guess should be applied to patches 1-3 only strictly? Or perhaps 3/5?

>
> > --
> > Sincerely yours,
> > Mike.
> >

--
Cheers, Lorenzo
Re: [PATCH v2 0/5] x86/mm/pat: CPA fixes
Posted by Atish Patra 1 month ago
On 8/25/26 12:31 AM, Lorenzo Stoakes (ARM) wrote:
> On Tue, Aug 25, 2026 at 12:12:32AM -0700, Atish Patra wrote:
>> Reproduced and verified this series (patches 1-3) on 4vcpu guest running two different kernels
>> 1. mainline (commit: 77ae27fd98f3)
>> 2. Ubuntu Resolute 7.0.0-26 (production kernel hitting the issue in a VM)
>>
>> The Reproducer consisted of
>> 1. A debug patch a cmdline-gated stall between the two *pmd reads in vmalloc_to_page()
>> 2. One taskset-pinned insmod/rmmod worker per module over stock cfg80211/dummy/veth modules
>>
>> With the above reproducer, both BUG within seconds in unpatched kernel.
>> 1. Resolute in 0.71s at alternative.c:2564 (BUG_ON(!pages[0] ...), RAX=0)
>> 2. mainline at alternative.c:2473 (BUG_ON(memcmp(addr, src, len))).
>>
>> With patches 1-3: zero splats across 10 runs each (600s/11,378 module load/unload cycles on mainline and 1200s/55,980 module load/unload cycles on Resolute).
> Amazing, thanks!
>
>>
>> Tested-by: Atish Patra<atishp@meta.com>
> I guess should be applied to patches 1-3 only strictly? Or perhaps 3/5?

Yes. 1-3 sounds good.


>>> --
>>> Sincerely yours,
>>> Mike.
>>>
> --
> Cheers, Lorenzo
Re: [PATCH v2 0/5] x86/mm/pat: CPA fixes
Posted by Andrew Morton 1 month, 2 weeks ago
On Thu, 13 Aug 2026 12:01:23 +0300 Mike Rapoport <rppt@kernel.org> wrote:

> Some of the fixes got merged into x86 tree, some of them got merged into mm
> tree and some are still hanging in the air.

I'm assuming/hoping that this whole series will be handled by the x86
team.


I have retained three random pat patches in mm.git since July 23:

x86-mm-pat-acquire-init_mm-write-lock-on-collapse-to-avoid-uaf.patch
x86-mm-pat-acquire-init_mm-read-lock-on-attribute-change-to-avoid-uaf.patch
x86-mm-pat-allocate-split-page-tables-as-kernel-page-tables.patch

just to get them some testing exposure.  But they're old.  I've heard
no reports since adding them.

There's nothing more to be learned by keeping these in mm.git so I'll
remove them now.
Re: [PATCH v2 0/5] x86/mm/pat: CPA fixes
Posted by Nikunj A. Dadhania 1 month, 2 weeks ago
On 8/13/2026 2:31 PM, Mike Rapoport wrote:

> The first three patches are urgent, the third patch fixes BUG() reported
> y several people and it depends on the first two.
> 
> There were no bug reports that the last two patches fix because bug
> manifestations won't yell at users.
> 
> TL;DR version:
> 
> There are a couple of CPA fixes floating around:
> 
> Denis Lunev fixed races between split and collapse of the large mappings:
> 
> https://lore.kernel.org/all/20260715183453.2381141-1-den@openvz.org
> 
> Lorenzo Stoakes fixed UAF caused by races between CPA and ptdump:
> 
> https://lore.kernel.org/all/20260723-series-vmap-race-fix-v6-0-8cc77dcc0018@kernel.org
> 
> and an issue with stale page tables in IOMMU:
> 
> https://lore.kernel.org/all/20260721-fix-cpa-kernel-pagetables-v2-1-2b255deed710@kernel.org
> 
> Mike Rapoport fixed a check of RW attribute in lookup_address_in_pgd_attr()
> used for the verification of RWX:
> 
> https://lore.kernel.org/all/20260715144519.934289-1-rppt@kernel.org
> 
> Pedro Falcato closed a race between text poking and collapse of large
> pages:
> 
> https://lore.kernel.org/all/anCK3eWFMwZqq5ka@pedro-suse
> 
> Some of the fixes got merged into x86 tree, some of them got merged into mm
> tree and some are still hanging in the air.
> 
> The changes here are collected from all these fixes into a single coherent
> set on top of tip/x86/mm:
> 
> * fix for races between CPA and ptdump causing UAF
> * update to the fix of the race between split and collapse of large
>   mappings
> * fix for races between CPA and vmalloc_to_page() in text poking
> * fix for stale page tables in IOMMU
> * fix for effective RW computation in lookup_address_in_pgd_attr()
> 
> ---
> v2 changes:
> * rebased on the current tip/x86/mm that includes peterz's changes for
>   DEBUG_PAGEALLOC
> * added fix for CPA vs text poking race

Tested v2 on a 512-guest concurrent boot harness across 200 iterations
with no splats. Both crash signatures reported in [1] are no longer seen.

Tested-by: Nikunj A Dadhania <nikunj@amd.com>

Regards,
Nikunj

[1] https://lore.kernel.org/all/20260812063316.21371-1-nikunj@amd.com/
 
> v1: https://patch.msgid.link/20260728-cpa-fixes-v1-0-2ed2352300b3@kernel.org
> 
> ---
> Lorenzo Stoakes (ARM) (3):
>       x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF
>       x86/mm/pat: acquire init_mm read lock on attribute change to avoid UAF
>       x86/mm/pat: allocate split page tables as kernel page tables
> 
> Mike Rapoport (Microsoft) (1):
>       x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr()
> 
> Pedro Falcato (1):
>       x86/alternative: exclude text poking against change_page_attr()
> 
>  arch/x86/kernel/alternative.c | 39 ++++++++++++++++++++++++---
>  arch/x86/mm/pat/set_memory.c  | 61 +++++++++++++++++++++++++++++++------------
>  include/linux/mmap_lock.h     |  2 ++
>  3 files changed, 83 insertions(+), 19 deletions(-)
> ---
> base-commit: 7da514d819a0afb148634aac92b3d190f34947c3
> change-id: 20260727-cpa-fixes-d3c73c075672
> 
> --
> Sincerely yours,
> Mike.
>
Re: [PATCH v2 0/5] x86/mm/pat: CPA fixes
Posted by Lorenzo Stoakes (ARM) 1 month, 2 weeks ago
On Thu, Aug 13, 2026 at 08:35:21PM +0530, Nikunj A. Dadhania wrote:
>
> Tested v2 on a 512-guest concurrent boot harness across 200 iterations
> with no splats. Both crash signatures reported in [1] are no longer seen.
>
> Tested-by: Nikunj A Dadhania <nikunj@amd.com>

Thanks so much for the testing!

And all credit to Pedro for reporting and contributing the key commit that
resolves this issue :)

>
> Regards,
> Nikunj
>
> [1] https://lore.kernel.org/all/20260812063316.21371-1-nikunj@amd.com/
>
> > v1: https://patch.msgid.link/20260728-cpa-fixes-v1-0-2ed2352300b3@kernel.org
> >
> > ---
> > Lorenzo Stoakes (ARM) (3):
> >       x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF
> >       x86/mm/pat: acquire init_mm read lock on attribute change to avoid UAF
> >       x86/mm/pat: allocate split page tables as kernel page tables
> >
> > Mike Rapoport (Microsoft) (1):
> >       x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr()
> >
> > Pedro Falcato (1):
> >       x86/alternative: exclude text poking against change_page_attr()
> >
> >  arch/x86/kernel/alternative.c | 39 ++++++++++++++++++++++++---
> >  arch/x86/mm/pat/set_memory.c  | 61 +++++++++++++++++++++++++++++++------------
> >  include/linux/mmap_lock.h     |  2 ++
> >  3 files changed, 83 insertions(+), 19 deletions(-)
> > ---
> > base-commit: 7da514d819a0afb148634aac92b3d190f34947c3
> > change-id: 20260727-cpa-fixes-d3c73c075672
> >
> > --
> > Sincerely yours,
> > Mike.
> >
>

--
Cheers, Lorenzo
Re: [PATCH v2 0/5] x86/mm/pat: CPA fixes
Posted by Pedro Falcato 1 month, 2 weeks ago
On Thu, Aug 13, 2026 at 04:07:38PM +0100, Lorenzo Stoakes (ARM) wrote:
> On Thu, Aug 13, 2026 at 08:35:21PM +0530, Nikunj A. Dadhania wrote:
> >
> > Tested v2 on a 512-guest concurrent boot harness across 200 iterations
> > with no splats. Both crash signatures reported in [1] are no longer seen.
> >
> > Tested-by: Nikunj A Dadhania <nikunj@amd.com>

Nice!

> 
> Thanks so much for the testing!
> 
> And all credit to Pedro for reporting and contributing the key commit that
> resolves this issue :)

And all credit to you for starting this flurry of fixes and patches that
solve Critical Kernel Issues(tm)! My fix would be nothing without yours!

-- 
Pedro