From: "Mike Rapoport (Microsoft)" <rppt@kernel.org>
To: Dave Hansen <dave.hansen@linux.intel.com>
Cc: Andrew Morton <akpm@linux-foundation.org>,
Andy Lutomirski <luto@kernel.org>,
Borislav Petkov <bp@alien8.de>,
David CARLIER <devnexen@gmail.com>,
David Hildenbrand <david@kernel.org>,
Ingo Molnar <mingo@redhat.com>, Jason Gunthorpe <jgg@ziepe.ca>,
Juergen Gross <jgross@suse.com>,
Kevin Tian <kevin.tian@intel.com>,
Kiryl Shutsemau <kas@kernel.org>,
"Liam R. Howlett" <liam@infradead.org>,
Lorenzo Stoakes <ljs@kernel.org>,
Lu Baolu <baolu.lu@linux.intel.com>,
Mike Rapoport <rppt@kernel.org>,
"H. Peter Anvin" <hpa@zytor.com>,
Peter Zijlstra <peterz@infradead.org>,
Shakeel Butt <shakeel.butt@linux.dev>,
Suren Baghdasaryan <surenb@google.com>,
Thomas Gleixner <tglx@kernel.org>,
Toshi Kani <toshi.kani@hpe.com>,
Vishal Moola <vishal.moola@gmail.com>,
Vlastimil Babka <vbabka@kernel.org>,
Will Deacon <will@kernel.org>,
iommu@lists.linux.dev, linux-kernel@vger.kernel.org,
linux-mm@kvack.org, stable@vger.kernel.org, x86@kernel.org,
syzbot@syzkaller.appspotmail.com
Subject: [PATCH 0/5] x86/mm/pat: CPA fixes
Date: Tue, 28 Jul 2026 16:07:43 +0300 [thread overview]
Message-ID: <20260728-cpa-fixes-v1-0-2ed2352300b3@kernel.org> (raw)
There are a couple of CPA fixes floating around:
Denis Lunev fixed races between split and collapse of the large mappings:
https://lore.kernel.org/all/20260715183453.2381141-1-den@openvz.org
Lorenzo Stoakes fixed UAF caused by races between CPA and ptdump:
https://lore.kernel.org/all/20260723-series-vmap-race-fix-v6-0-8cc77dcc0018@kernel.org
and an issue with stale page tables in IOMMU:
https://lore.kernel.org/all/20260721-fix-cpa-kernel-pagetables-v2-1-2b255deed710@kernel.org
Mike Rapoport fixed a check of RW attribute in lookup_address_in_pgd_attr()
used for the verification of RWX:
https://lore.kernel.org/all/20260715144519.934289-1-rppt@kernel.org
Some of the fixes got merged into x86 tree, some of them got merged into mm
tree and some are still hanging in the air.
Beside the fixes there was a supposed simplification of cpa_lock locking
that looked like removal of an optimization for DEBUG_PAGEALLOC, but it
turned out that it was not an optimization but rather a correctness
guard because with DEBUG_PAGEALLOC the locks could be taken in an atomic
context and couldn't use plain spin_lock()/spin_unlock().
The changes here are collected from all these fixes into a sinlge coherent
set on top of tip/x86/mm:
* update to cpa_lock handling with DEBUG_PAGEALLOC
* fix for races between CPA and ptdumpi causing UAF
* fix for stale page tables in IOMMU
* update to the fix of the race between split and collapse of large
mappings
* fix for effective RW computation in lookup_address_in_pgd_attr()
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
---
Lorenzo Stoakes (ARM) (3):
x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF
x86/mm/pat: acquire init_mm read lock on attribute change to avoid UAF
x86/mm/pat: allocate split page tables as kernel page tables
Mike Rapoport (Microsoft) (2):
x86/mm/pat: introcude cpa_lock() and cpa_unlock()
x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr()
arch/x86/mm/pat/set_memory.c | 95 +++++++++++++++++++++++++++++++-------------
include/linux/mmap_lock.h | 2 +
2 files changed, 70 insertions(+), 27 deletions(-)
---
base-commit: a5a162fe1ae130e3d2ceefef3f43afe3773c1d56
change-id: 20260727-cpa-fixes-d3c73c075672
--
Sincerely yours,
Mike.
next reply other threads:[~2026-07-28 13:08 UTC|newest]
Thread overview: 39+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-28 13:07 Mike Rapoport (Microsoft) [this message]
2026-07-28 13:07 ` [PATCH 1/5] x86/mm/pat: introcude cpa_lock() and cpa_unlock() Mike Rapoport (Microsoft)
2026-07-28 13:13 ` Lorenzo Stoakes (ARM)
2026-07-28 14:21 ` Peter Zijlstra
2026-07-28 14:30 ` Dave Hansen
2026-07-28 14:31 ` Peter Zijlstra
2026-07-28 14:46 ` Mike Rapoport
2026-07-28 14:50 ` Lorenzo Stoakes (ARM)
2026-07-28 14:55 ` Peter Zijlstra
2026-07-28 15:01 ` Peter Zijlstra
2026-07-28 15:20 ` Lorenzo Stoakes (ARM)
2026-07-28 15:33 ` Peter Zijlstra
2026-07-28 15:54 ` Mike Rapoport
2026-07-28 15:02 ` Lorenzo Stoakes (ARM)
2026-07-28 15:30 ` Peter Zijlstra
2026-07-28 15:16 ` Peter Zijlstra
2026-07-28 16:01 ` Mike Rapoport
2026-07-28 13:07 ` [PATCH 2/5] x86/mm/pat: acquire init_mm write lock on collapse to avoid UAF Mike Rapoport
2026-07-28 13:07 ` [PATCH 3/5] x86/mm/pat: acquire init_mm read lock on attribute change " Mike Rapoport
2026-07-28 13:14 ` Lorenzo Stoakes (ARM)
2026-07-28 13:07 ` [PATCH 4/5] x86/mm/pat: allocate split page tables as kernel page tables Mike Rapoport
2026-07-28 13:07 ` [PATCH 5/5] x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr() Mike Rapoport (Microsoft)
2026-07-28 13:11 ` [PATCH 0/5] x86/mm/pat: CPA fixes Lorenzo Stoakes (ARM)
2026-07-30 15:53 ` Steffen Dirkwinkel
2026-08-03 12:41 ` Pedro Falcato
2026-08-07 15:36 ` Lorenzo Stoakes (ARM)
2026-08-12 11:46 ` Pedro Falcato
2026-08-12 15:15 ` Mike Rapoport
2026-08-12 15:42 ` Lorenzo Stoakes (ARM)
2026-08-13 5:55 ` Nikunj A Dadhania
2026-08-13 8:51 ` Mike Rapoport
2026-08-13 9:23 ` Lorenzo Stoakes (ARM)
2026-08-13 9:24 ` Nikunj A. Dadhania
2026-08-03 15:14 ` Mike Rapoport
2026-08-07 14:34 ` Lorenzo Stoakes (ARM)
2026-08-07 15:00 ` Lorenzo Stoakes (ARM)
2026-08-12 22:20 ` Dave Hansen
2026-08-13 8:57 ` Lorenzo Stoakes (ARM)
2026-08-13 9:06 ` Lorenzo Stoakes (ARM)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260728-cpa-fixes-v1-0-2ed2352300b3@kernel.org \
--to=rppt@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=baolu.lu@linux.intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=david@kernel.org \
--cc=devnexen@gmail.com \
--cc=hpa@zytor.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@ziepe.ca \
--cc=jgross@suse.com \
--cc=kas@kernel.org \
--cc=kevin.tian@intel.com \
--cc=liam@infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=ljs@kernel.org \
--cc=luto@kernel.org \
--cc=mingo@redhat.com \
--cc=peterz@infradead.org \
--cc=shakeel.butt@linux.dev \
--cc=stable@vger.kernel.org \
--cc=surenb@google.com \
--cc=syzbot@syzkaller.appspotmail.com \
--cc=tglx@kernel.org \
--cc=toshi.kani@hpe.com \
--cc=vbabka@kernel.org \
--cc=vishal.moola@gmail.com \
--cc=will@kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®