From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f98.google.com (mail-pj1-f98.google.com [209.85.216.98]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E260F32C942 for ; Thu, 12 Feb 2026 22:28:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.98 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770935339; cv=none; b=EoWEtPj0qoQM5yWpWSyfxxh2GU4LI9xZo2WldJbR83m7rMmFB39asVqt8TBDFUvsDRYBEY5+drdGN2LEWZiqVLclmX+MNVviyuTsokguWtzva7HhBsd8oNzKWukbrHx8EI6h3edp2hQUsSxtsq/W4WHo0STqvxVLJLyZY6FGdwo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770935339; c=relaxed/simple; bh=wOVWziKkJEQncBaxoTB8kqiuxvbopPX6VhoVI+3WBcc=; h=From:Cc:Subject:To:Date:Message-Id; b=twhHdgxJmAi+e2lKqrxsKmT/uGCzRsTEjMCmDGamh40J3DBJ3osd5/kC9plfG5hfvlCBm4kM+JY2bJ2Bp3qXUlX1jr+yEZHTJFg2BhN2gnaU1amq+NBiGwCuD5k16SPBgkhdXsyDDlHzW+yCZHRK8+7JDJPpt8zHCpPdP0ODkIo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=windowsforum.com; arc=none smtp.client-ip=209.85.216.98 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=windowsforum.com Received: by mail-pj1-f98.google.com with SMTP id 98e67ed59e1d1-35640ad94d3so230496a91.1 for ; Thu, 12 Feb 2026 14:28:57 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770935337; x=1771540137; h=message-id:date:user-agent:to:subject:cc:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=xr7O80uLyFjBbm9kcSOWOXWgNr+cEIPrOL32vN3cCXE=; b=Rz+h8jv1S/2fCoMhWugpgR/bHJrDVlvosyz7gGaAiWXRpZT/RdxqL4j/hV3iu2j18p CDTC6Ep9mGNfpHvDaux/0Deu1GztMNZV8F4yhlc/ABmmGP5czHONA4d/nEpGVJC8hScv kDkyEQwKvvW6oTKgbHMkK1JxaPGV+9eZcMl69GdGC8hiRyUUNjaJWkNfSnBlCpWYG4Sx XrXy30o8u3VRHz4dhIeogcftdaHL7yg9sgompBFoGJqSVNlIuhpmGZ3YUno1KrMFfJtQ WIXz7fyTJ3azo9m77fkFt5gcb221nWQeKXqPOjvTaoN1uQSB77paUh49XSkDGpaVt0Ho AETA== X-Forwarded-Encrypted: i=1; AJvYcCXQUKejjzD5jblnn8tW9M82f/Gvl2XtrPdtmduBuz5dSX7nziaNfz6EQOGtTeFTncVMd+rqboM5Xj3nbz8=@vger.kernel.org X-Gm-Message-State: AOJu0Yz4ucugwTB9oJMs6dxxSlWV0DJndjW1gi6I5sof49+eEJKZ0uSn vnhw3E4zCWu2+rMcJRQNyXWRRnWMrbERqM1hm0ygLcUbZZKBaT1Fz/ITlH0SVR4KIZVQNvSHJ+q mJpxaYk4a4jL92aNb3WaNzyDEBESJk8yBWdL4 X-Gm-Gg: AZuq6aL1vdVQrkvTQqFpKuyAi42/vuzDyG6SRYyZxMMujD+xmePuatnDz3SZbViW/8G LsR59k8ObQH4YhbCHi9D4b9AN1YfQy7zd7lzpMSkzx5bAEkF9aw7cmLNq1hPXAurXlXy2AAEOPU LC+cGxi2qvwhFoVIJPHIHzuA1pVduzb24H2SHfYQaLZdJW312dnrQ3J67h/o7PZMgdRKVji/X2u KJ1zfN70RjMe3BL2vYduULDYLqIb5PQh79SDixSVIw/dmO1WtBeSbOTUDMd7Shb+PYGR1qRMUBy 4/vqqGipknCLpRptz1FWcwOFMnvwSqhY2+nbgS8FvgPHYLL0zWxhLf+TD0z2BD3p5IeC9JbQ59V IYbzDUQH/64UAS11Mri9AaX9unTnLt433eTPkb1QsBJLNMMwvEg== X-Received: by 2002:a17:90b:3511:b0:356:3032:1d5e with SMTP id 98e67ed59e1d1-356a7a3f896mr445237a91.22.1770935337243; Thu, 12 Feb 2026 14:28:57 -0800 (PST) Received: from windowsforum.com (116.9.196.104.bc.googleusercontent.com. [104.196.9.116]) by smtp-relay.gmail.com with ESMTPS id 98e67ed59e1d1-35662f4d736sm1311648a91.5.2026.02.12.14.28.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 12 Feb 2026 14:28:57 -0800 (PST) X-Relaying-Domain: windowsforum.com Received: by windowsforum.com (Postfix, from userid 0) id 2C9B92A1C1D; Thu, 12 Feb 2026 22:28:55 +0000 (UTC) From: Mike Fara Cc: ,,, Subject: Re: [BUG] sched_mm_cid_exit+0xe2: page fault on CID bitmap write with nopti on 6.19.0 To: User-Agent: mail (GNU Mailutils 3.20) Date: Thu, 12 Feb 2026 22:28:55 +0000 Message-Id: <20260212222855.2C9B92A1C1D@windowsforum.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: To: mathieu.desnoyers@efficios.com Cc: peterz@infradead.org, mingo@redhat.com, linux-kernel@vger.kernel.org, mjfara@gmail.com Subject: Re: [BUG] sched_mm_cid_exit+0xe2: page fault on CID bitmap write with nopti on 6.19.0 Hi Mathieu, Confirmed. Rebuilt 6.19.0 with commit 1e83ccd5921a cherry-picked, CONFIG_SCHED_MM_CID=y, and nopti still on the cmdline. Clean boot, no oopses. Verified the fix is compiled in by disassembling sched_mm_cid_exit from the running kernel. The inlined mm_drop_cid_on_cpu() now has the cid_on_cpu() guard before the lock btr: mm_drop_cid_on_cpu (inlined at sched_mm_cid_exit+0xc4): mov (%rcx),%eax # Load pcp->cid test $0x40000000,%eax # Test ONCPU bit (bit 30) je # Not CPU-owned? Skip drop entirely and $0xbfffffff,%eax # Clear ONCPU: cpu_cid_to_cid() mov %eax,(%rcx) # Store back ... lock btr %rax,(%rcx) # mm_drop_cid (bitmap clear) : ... # Continue safely Without the fix, the code would fall through to lock btr with a garbage bit number derived from the TRANSIT flag (bit 29), causing the out-of-bounds write we reported. System info: # uname -a 6.19.0-gce #2 SMP PREEMPT_DYNAMIC Thu Feb 12 21:42:52 UTC 2026 x86_64 # grep SCHED_MM_CID /boot/config-$(uname -r) CONFIG_SCHED_MM_CID=y # Boot cmdline includes: nopti mitigations=off # dmesg | grep -i 'BUG\|oops\|sched_mm\|page.fault' (clean - no errors) Will continue soak testing and report back if anything surfaces. Tested-by: Mike Fara Thanks, Mike Fara mjfara@gmail.com