mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Matt Fleming <matt@console-pimps.org>
To: linux-efi@vger.kernel.org
Cc: linux-kernel@vger.kernel.org, Alan Cox <alan@lxorguk.ukuu.org.uk>,
	Matt Fleming <matt.fleming@intel.com>,
	Matthew Garrett <mjg59@srcf.ucam.org>,
	Dave Hansen <dave.hansen@intel.com>, Borislav Petkov <bp@suse.de>
Subject: [PATCH] x86/efi: Only pass mapped RAM regions to free_bootmem_late()
Date: Thu,  5 Jun 2014 14:27:34 +0100	[thread overview]
Message-ID: <1401974854-7716-1-git-send-email-matt@console-pimps.org> (raw)

From: Matt Fleming <matt.fleming@intel.com>

free_bootmem_late() expects to only be passed RAM regions that the
kernel can access, and that have a corresponding 'struct page'. It's
possible for regions in the EFI memory map to reside in address ranges
for which pfn_to_page() doesn't work, for instance when running on an
i386 system with CONFIG_HIGHMEM=n.

This is in fact the case for one of Alan's machines where some of the
EFI boot services pages live in highmem, and running a kernel without
CONFIG_HIGHMEM enabled results in the following oops,

 BUG: unable to handle kernel paging request at f7f1f080
 IP: [<c17fba96>] __free_pages_bootmem+0x5a/0xb8
 *pdpt = 0000000001887001 *pde = 0000000001984067 *pte = 000000000 0000000
 Oops: 0002 [#1] SMP

[...]

 Call Trace:
  [<c17feacc>] free_bootmem_late+0x2d/0x3d
  [<c17f1013>] efi_free_boot_services+0x48/0x5b
  [<c17ddc12>] start_kernel+0x3ad/0x3cf
  [<c17dd654>] ? set_init_arg+0x49/0x49
  [<c17dd380>] i386_start_kernel+0x12e/0x131

Reported-by: Alan Cox <alan@lxorguk.ukuu.org.uk>
Cc: Matthew Garrett <mjg59@srcf.ucam.org>
Cc: Dave Hansen <dave.hansen@intel.com>
Cc: Borislav Petkov <bp@suse.de>
Signed-off-by: Matt Fleming <matt.fleming@intel.com>
---

Alan, could you double check that this patch also fixes the oops on your
CONFIG_HIGHMEM=n machine?

 arch/x86/platform/efi/efi.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/arch/x86/platform/efi/efi.c b/arch/x86/platform/efi/efi.c
index 3781dd39e8bd..893d183ee98f 100644
--- a/arch/x86/platform/efi/efi.c
+++ b/arch/x86/platform/efi/efi.c
@@ -451,6 +451,9 @@ void __init efi_free_boot_services(void)
 		if (!size)
 			continue;
 
+		if (!e820_all_mapped(start, start + size, E820_RAM))
+			continue;
+
 		free_bootmem_late(start, size);
 	}
 
-- 
1.9.0


             reply	other threads:[~2014-06-05 13:27 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-06-05 13:27 Matt Fleming [this message]
2014-06-05 14:43 ` Dave Hansen
2014-06-05 15:01 ` Alan Cox
2014-06-05 18:07   ` Matt Fleming

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1401974854-7716-1-git-send-email-matt@console-pimps.org \
    --to=matt@console-pimps.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=bp@suse.de \
    --cc=dave.hansen@intel.com \
    --cc=linux-efi@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=matt.fleming@intel.com \
    --cc=mjg59@srcf.ucam.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®