From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by smtp.subspace.kernel.org (Postfix) with ESMTP id A7D3857266F; Tue, 22 Sep 2026 17:13:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=217.140.110.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790097185; cv=none; b=Z+GFalIscU2J+MM8rNsFazxSEgK0IUng6WvgvLC1CS1nXcjcObJMVvwKtjpkTFWeytuzwFg63teSpEtddUh7NNRyf5ZLNXN/ZfInXArdpKfMY/pzmEy8ZzdDmBY49EuKQL95sBHh42EeJ8nDNnxgPxt1KLbZbp6nvcXEWcmYurY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790097185; c=relaxed/simple; bh=6fGlC+l7ZOTUAPb0qf6/jbMAeDqXx74X21kDAUYsIyk=; h=From:Subject:Date:Message-Id:MIME-Version:Content-Type:To:Cc; b=a+vD8smW1VOp8XrBm1Kt7ObpeGknCU7JnjjI9S+ZwRIX0sqCGbLPRHg0uWZ+OTLzwU3RgoOHtlA2W5IAY/R91muj2V5mq8Tlq6YcCedwJgKh6EQmbsK2Md5s4z/m4MIdLGlAwj+lSHDIQ/ks4UaSYXuBljclNtpGEOTv6b+z7yM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com; spf=pass smtp.mailfrom=arm.com; dkim=pass (1024-bit key) header.d=arm.com header.i=@arm.com header.b=HIIxexSc; arc=none smtp.client-ip=217.140.110.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=arm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=arm.com header.i=@arm.com header.b="HIIxexSc" Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 7BA4D1595; Tue, 22 Sep 2026 10:12:58 -0700 (PDT) Received: from [127.0.1.1] (e142334-100.cambridge.arm.com [10.2.198.93]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id 153903F86C; Tue, 22 Sep 2026 10:12:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1790097182; bh=6fGlC+l7ZOTUAPb0qf6/jbMAeDqXx74X21kDAUYsIyk=; h=From:Subject:Date:To:Cc:From; b=HIIxexScPs77FEWrL1zKfh489AcYGH+eosy1rJu4q8Qx0Y5qygcZGRibDPK9zayy2 bMswKnuZyeg7Xdl5EiA/OMueeXhZkIg42q52ZYMsGuSW+3VibDu/Td+mjExBEv2p1H 6o6egoaJbq6J6Irg6+9TyJTuwzBdadX5XN/qqY9E= From: Muhammad Usama Anjum Subject: [PATCH v3 0/9] mm: distinguish HW PTE pointers from SW PTE value pointers Date: Tue, 22 Sep 2026 18:12:28 +0100 Message-Id: <20260922-pte0-v3-0-5670b8cb9059@arm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit X-B4-Tracking: v=1; b=H4sIAPy2smoC/y2NwQ6DIBAFf8XsuZgFqxVP/Y/GA8W1YoIaENPG+ O8F2+Mk8+bt4MkZ8tBkOzjajDfzFKG4ZKAHNb2ImS4yCBQVSn5ly0rIKl3XfVlK0d0kRHVx1Jv 3mXm0P/bhOZJe0zYZg/Hr7D7nzyaS909iwbFAFDmP+bqUjLPglVW5msZg78rZXM8W2uM4vgCpy qqtAAAA X-Change-ID: 20260914-pte0-6c88f5592d79 To: Andrew Morton , David Hildenbrand , Lorenzo Stoakes , "Liam R. Howlett" , Vlastimil Babka , Mike Rapoport , Suren Baghdasaryan , Michal Hocko , Xu Xin , Chengming Zhou , Jann Horn , Muchun Song , Oscar Salvador , Pedro Falcato , Arnd Bergmann , Will Deacon , "Aneesh Kumar K.V" , Nick Piggin , Peter Zijlstra , Pasha Tatashin , Rik van Riel , Harry Yoo , Lance Yang , Chris Li , Kairui Song , Kemeng Shi , Nhat Pham , Baoquan He , Barry Song , Youngjun Park , Uladzislau Rezki , Steven Rostedt , Masami Hiramatsu , Mathieu Desnoyers , Alexei Starovoitov , Daniel Borkmann , Andrii Nakryiko , Eduard Zingerman , Kumar Kartikeya Dwivedi , Martin KaFai Lau , Song Liu , Yonghong Song , Jiri Olsa , Emil Tsalapatis , Ihor Solodrai , Ingo Molnar , Arnaldo Carvalho de Melo , Namhyung Kim , Mark Rutland , Alexander Shishkin , Ian Rogers , Adrian Hunter , James Clark , SJ Park , "Matthew Wilcox (Oracle)" , Jan Kara , Jason Gunthorpe , John Hubbard , Peter Xu , Leon Romanovsky , Zi Yan , Baolin Wang , Nico Pache , Ryan Roberts , Dev Jain , Usama Arif , Kiryl Shutsemau , Andrey Ryabinin , Alexander Potapenko , Andrey Konovalov , Dmitry Vyukov , Vincenzo Frascino , Miaohe Lin , Naoya Horiguchi , Matthew Brost , Joshua Hahn , Rakie Kim , Byungchul Park , Gregory Price , Ying Huang , Alistair Popple , Dennis Zhou , Tejun Heo , Christoph Lameter , Johannes Weiner , Qi Zheng , Shakeel Butt , Axel Rasmussen , Yuanchu Xie , Wei Xu , Jani Nikula , Joonas Lahtinen , Rodrigo Vivi , Tvrtko Ursulin , David Airlie , Simona Vetter , Juergen Gross , Stefano Stabellini , Oleksandr Tyshchenko Cc: linux-kernel@vger.kernel.org, linux-mm@kvack.org, linux-fsdevel@vger.kernel.org, linux-arch@vger.kernel.org, linux-trace-kernel@vger.kernel.org, bpf@vger.kernel.org, linux-perf-users@vger.kernel.org, damon@lists.linux.dev, kasan-dev@googlegroups.com, intel-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, xen-devel@lists.xenproject.org, Muhammad Usama Anjum X-Mailer: b4 0.16.0 Hi, pte_t currently describes both a software PTE value and an element stored in a PTE table. Consequently, pte_t * can point either to a software PTE value, often a stack copy, or to a PTE-table slot. The compiler cannot distinguish these cases. A value pointer can therefore be passed to an interface that expects table storage, while table storage can be read by direct dereference instead of the architecture accessor. This series begins a staged conversion at the PTE level. It introduces hw_pte_t as the element type for PTE-table storage and converts generic MM to use hw_pte_t *. Software PTE values remain pte_t. Interfaces that intentionally return a value through pte_t *, such as install_pte, remain value interfaces; the relevant parameters are named ptentp to make that distinction explicit. The generic definition aliases hw_pte_t to pte_t unless an architecture selects ARCH_HAS_HW_PTE_T, which enables a distinct generic wrapper named __hw_pte_t. Some architectures define pgtable_t in headers parsed before the generic hw_pte_t typedef is visible. The structure tag allows those headers to define pgtable_t as struct __hw_pte_t * without creating an include-order dependency. This is required when converting s390, m68k, powerpc and sparc. No architecture selects ARCH_HAS_HW_PTE_T in this series, so the representation and behavior of every architecture are preserved. ptep_get() keeps its existing READ_ONCE() semantics and converts the stored element through __pte_from_hw(). An architecture can later select the option and convert its PTE interfaces to make the distinction compiler-enforced. Architecture PTE implementations and most architecture code are deliberately left for those later opt-in conversions. Here, hw_pte_t identifies PTE-table storage rather than table lifetime: complete PTE tables use hw_pte_t whether or not they are currently linked into a page-table hierarchy, while software PTE values use pte_t. The distinction between complete but unlinked tables and hardware-reachable tables was raised during discussion and remains an important point for review. PMD, PUD, P4D and PGD storage are deliberately out of scope. They can be converted in later series after the PTE boundary is agreed, avoiding the PMD-specific cases that made an all-level conversion difficult to review. Most mechanical pointer conversions were generated with the Coccinelle script included below, then audited and fixed by hand. This series does not add a second ptep_get_once() accessor and does not remove or replace STRICT_MM_TYPECHECKS. The design discussion is available at [1]; while the original idea came from [2]. I've the patches here [3] for arm64 conversion which I used to find usages in generic code which I missed during development. [1] https://lore.kernel.org/all/6110202c-057b-4701-8c04-1a76ee7bb9ab@arm.com/ [2] https://lore.kernel.org/all/a063f6c5-2785-4a9f-8079-25edb3e54cef@arm.com [3] https://lore.kernel.org/all/20260914-pte0_arm-v1-0-bb53b663e396@arm.com Testing: Testing was performed with and without the series on both x86_64 and arm64. KUnit and the MM kselftests produced matching before-and-after results problems or regressions. Fastpath performance testing was also completed on arm64. No regression was found. Thanks, Usama --- Changes in v3: - Retitle the series - Moved hw_pte_val() adding helper to generic series - Link to v2: https://patch.msgid.link/20260903103002.1091859-1-usama.anjum@arm.com Changes in v2: - Name the generic wrapper structure __hw_pte_t so architectures can forward-declare it before the generic typedef is visible. - Use software PTE value terminology consistently - Fold the prerequisite header includes into the generic storage conversion - Explain why the NOMMU stub converts the stored entry without ptep_get(). - Rebase onto mm-new and rerun the Coccinelle conversion. - Link to v1: https://lore.kernel.org/all/20260806083926.1807279-1-usama.anjum@arm.com Changes in v1: - Add ARCH_HAS_HW_PTE_T so architectures can opt in to a distinct PTE-table storage type. - Define the distinct hw_pte_t wrapper and its conversion helpers in generic code instead of requiring each architecture to define them. - Read hw_pte_t through READ_ONCE() before converting it to pte_t. - Drop the previous mremap patch in favour of [a]. Apply [a] first if it is not already present. - Drop the previous two dead-code conversion patches; the affected code was cleaned up separately in [b] and [c]. - Link to RFC: https://lore.kernel.org/all/20260727164715.2866609-1-usama.anjum@arm.com [a] https://lore.kernel.org/linux-mm/20260720141633.501799-1-agordeev@linux.ibm.com/ [b] https://lore.kernel.org/all/20260730111316.3672672-1-usama.anjum@arm.com [c] https://lore.kernel.org/all/20260730094501.3002718-1-usama.anjum@arm.com --- // SPDX-License-Identifier: GPL-2.0-only /// /// Rename raw PTE pointer types to hardware PTE pointer types. /// /// This is a mechanical type rename. It converts common declarations, /// function parameters, prototypes, return types and casts from "pte_t *" /// to "hw_pte_t *". Plain "pte_t" objects are intentionally left unchanged. /// Pointers named "ptentp" refer to temporary software PTE values and are /// intentionally ignored in all modes. /// Re-run in context mode afterwards to audit remaining raw pte_t pointers /// and cases that need hand conversion, such as trace macros and mixed /// declarations. /// /// Confidence: Moderate // Options: --no-includes --include-headers virtual patch virtual report virtual context @local_decl depends on patch@ identifier x != ptentp; @@ - pte_t *x; + hw_pte_t *x; @local_decl_init depends on patch@ identifier x != ptentp; expression e; @@ - pte_t *x = e; + hw_pte_t *x = e; @param_proto depends on patch@ identifier f; identifier x != ptentp; type R; @@ R f(..., - pte_t *x + hw_pte_t *x ,...); @param_proto_unnamed depends on patch@ identifier f; type R; @@ R f(..., - pte_t * + hw_pte_t * ,...); @param_def depends on patch@ identifier f; identifier x != ptentp; type R; @@ R f(..., - pte_t *x + hw_pte_t *x ,...) { ... } @ret_proto depends on patch@ identifier f; parameter list ps; @@ - pte_t * + hw_pte_t * f(ps); @ret_def depends on patch@ identifier f; parameter list ps; @@ - pte_t * + hw_pte_t * f(ps) { ... } @struct_member depends on patch@ identifier S; identifier x != ptentp; @@ struct S { ... - pte_t *x; + hw_pte_t *x; ... }; @union_member depends on patch@ identifier x != ptentp; @@ union { ... - pte_t *x; + hw_pte_t *x; ... }; @union_member_in_struct depends on patch@ identifier S; identifier x != ptentp; @@ struct S { ... union { ... - pte_t *x; + hw_pte_t *x; ... }; ... }; @fnptr_struct_member depends on patch@ identifier S,f; identifier x != ptentp; type R; @@ struct S { ... R (*f)(..., - pte_t *x + hw_pte_t *x ,...); ... }; @fnptr_typedef_pte_fn_t depends on patch@ identifier x != ptentp; @@ typedef int (*pte_fn_t)(..., - pte_t *x + hw_pte_t *x ,...); @cast depends on patch@ expression e; @@ - (pte_t *)e + (hw_pte_t *)e @remaining_decl depends on context || report@ identifier x != ptentp; position p; @@ * pte_t *x@p; @remaining_decl_init depends on context || report@ identifier x != ptentp; expression e; position p; @@ * pte_t *x@p = e; @remaining_param_proto depends on context || report@ identifier f; identifier x != ptentp; type R; position p; @@ R f(..., * pte_t *x@p ,...); @remaining_param_proto_unnamed depends on context || report@ identifier f; type R; position p; @@ R f(..., * pte_t *@p ,...); @remaining_param_def depends on context || report@ identifier f; identifier x != ptentp; type R; position p; @@ R f(..., * pte_t *x@p ,...) { ... } @remaining_ret_proto depends on context || report@ identifier f; parameter list ps; position p; @@ * pte_t *f@p(ps); @remaining_ret_def depends on context || report@ identifier f; parameter list ps; position p; @@ * pte_t *f@p(ps) { ... } @remaining_struct_member depends on context || report@ identifier S; identifier x != ptentp; position p; @@ struct S { ... * pte_t *x@p; ... }; @remaining_union_member depends on context || report@ identifier x != ptentp; position p; @@ union { ... * pte_t *x@p; ... }; @remaining_union_member_in_struct depends on context || report@ identifier S; identifier x != ptentp; position p; @@ struct S { ... union { ... * pte_t *x@p; ... }; ... }; @remaining_fnptr_struct_member depends on context || report@ identifier S,f; identifier x != ptentp; type R; position p; @@ struct S { ... R (*f)(..., * pte_t *x@p ,...); ... }; @remaining_fnptr_typedef_pte_fn_t depends on context || report@ identifier x != ptentp; position p; @@ typedef int (*pte_fn_t)(..., * pte_t *x@p ,...); --- To: Andrew Morton To: David Hildenbrand To: Lorenzo Stoakes To: "Liam R. Howlett" To: Vlastimil Babka To: Mike Rapoport To: Suren Baghdasaryan To: Michal Hocko To: Xu Xin To: Chengming Zhou To: Jann Horn To: Muchun Song To: Oscar Salvador To: Pedro Falcato To: Arnd Bergmann To: Will Deacon To: "Aneesh Kumar K.V" To: Nick Piggin To: Peter Zijlstra To: Pasha Tatashin To: Rik van Riel To: Harry Yoo To: Lance Yang To: Chris Li To: Kairui Song To: Kemeng Shi To: Nhat Pham To: Baoquan He To: Barry Song To: Youngjun Park To: Uladzislau Rezki To: Steven Rostedt To: Masami Hiramatsu To: Mathieu Desnoyers To: Alexei Starovoitov To: Daniel Borkmann To: Andrii Nakryiko To: Eduard Zingerman To: Kumar Kartikeya Dwivedi To: Martin KaFai Lau To: Song Liu To: Yonghong Song To: Jiri Olsa To: Emil Tsalapatis To: Ihor Solodrai To: Ingo Molnar To: Arnaldo Carvalho de Melo To: Namhyung Kim To: Mark Rutland To: Alexander Shishkin To: Ian Rogers To: Adrian Hunter To: James Clark To: SJ Park To: "Matthew Wilcox (Oracle)" To: Jan Kara To: Jason Gunthorpe To: John Hubbard To: Peter Xu To: Leon Romanovsky To: Zi Yan To: Baolin Wang To: Nico Pache To: Ryan Roberts To: Dev Jain To: Usama Arif To: Kiryl Shutsemau To: Andrey Ryabinin To: Alexander Potapenko To: Andrey Konovalov To: Dmitry Vyukov To: Vincenzo Frascino To: Miaohe Lin To: Naoya Horiguchi To: Matthew Brost To: Joshua Hahn To: Rakie Kim To: Byungchul Park To: Gregory Price To: Ying Huang To: Alistair Popple To: Dennis Zhou To: Tejun Heo To: Christoph Lameter To: Johannes Weiner To: Qi Zheng To: Shakeel Butt To: Axel Rasmussen To: Yuanchu Xie To: Wei Xu To: Jani Nikula To: Joonas Lahtinen To: Rodrigo Vivi To: Tvrtko Ursulin To: David Airlie To: Simona Vetter To: Juergen Gross To: Stefano Stabellini To: Oleksandr Tyshchenko Cc: linux-kernel@vger.kernel.org Cc: linux-mm@kvack.org Cc: linux-fsdevel@vger.kernel.org Cc: linux-arch@vger.kernel.org Cc: linux-trace-kernel@vger.kernel.org Cc: bpf@vger.kernel.org Cc: linux-perf-users@vger.kernel.org Cc: damon@lists.linux.dev Cc: kasan-dev@googlegroups.com Cc: intel-gfx@lists.freedesktop.org Cc: dri-devel@lists.freedesktop.org Cc: xen-devel@lists.xenproject.org Signed-off-by: Muhammad Usama Anjum --- Muhammad Usama Anjum (9): mm: introduce hw_pte_t for PTE table storage mm: rename pointers to software PTE values as ptentp mm: use hw_pte_t for generic PTE table storage mm: convert PTE table entries in ptep_get() mm: convert PTE table entry to pte mm: add hw_pte_val for HW PTE storage mm/kasan: use hw_pte_t for the early shadow PTE table drm/i915: use hw_pte_t for PTE range callbacks xen: use hw_pte_t for PTE range callbacks MAINTAINERS | 1 + drivers/gpu/drm/i915/gem/selftests/i915_gem_mman.c | 4 +-- drivers/gpu/drm/i915/i915_mm.c | 4 +-- drivers/xen/gntdev.c | 2 +- drivers/xen/privcmd.c | 2 +- drivers/xen/xenbus/xenbus_client.c | 2 +- drivers/xen/xlate_mmu.c | 4 +-- fs/hugetlbfs/inode.c | 3 +- fs/proc/task_mmu.c | 33 ++++++++++---------- include/asm-generic/hugetlb.h | 15 ++++----- include/asm-generic/pgalloc.h | 6 ++-- include/asm-generic/tlb.h | 5 +-- include/linux/hugetlb.h | 53 +++++++++++++++++-------------- include/linux/kasan.h | 2 +- include/linux/mm.h | 26 ++++++++-------- include/linux/page_table_check.h | 10 ++++-- include/linux/pagewalk.h | 10 +++--- include/linux/pgtable.h | 81 +++++++++++++++++++++++++----------------------- include/linux/pgtable_types.h | 23 ++++++++++++++ include/linux/rmap.h | 2 +- include/linux/swapops.h | 6 ++-- include/linux/vmalloc.h | 4 +-- include/trace/events/xen.h | 10 +++--- kernel/bpf/arena.c | 9 +++--- kernel/events/core.c | 3 +- mm/Kconfig | 3 ++ mm/damon/ops-common.c | 2 +- mm/damon/ops-common.h | 2 +- mm/damon/vaddr.c | 20 ++++++------ mm/debug_vm_pgtable.c | 2 +- mm/filemap.c | 4 +-- mm/gup.c | 9 +++--- mm/highmem.c | 15 ++++----- mm/hmm.c | 6 ++-- mm/huge_memory.c | 4 +-- mm/hugetlb.c | 60 ++++++++++++++++++----------------- mm/hugetlb_vmemmap.c | 13 ++++---- mm/internal.h | 16 +++++----- mm/kasan/init.c | 14 ++++----- mm/kasan/shadow.c | 6 ++-- mm/khugepaged.c | 50 ++++++++++++++++++------------ mm/ksm.c | 11 ++++--- mm/madvise.c | 18 ++++++----- mm/mapping_dirty_helpers.c | 4 +-- mm/memory-failure.c | 6 ++-- mm/memory.c | 78 +++++++++++++++++++++++----------------------- mm/mempolicy.c | 4 +-- mm/migrate.c | 4 +-- mm/migrate_device.c | 4 +-- mm/mincore.c | 4 +-- mm/mlock.c | 4 +-- mm/mprotect.c | 19 ++++++------ mm/mremap.c | 4 +-- mm/page_table_check.c | 4 +-- mm/pagewalk.c | 9 +++--- mm/percpu.c | 2 +- mm/pgtable-generic.c | 20 ++++++------ mm/ptdump.c | 4 +-- mm/rmap.c | 6 ++-- mm/sparse-vmemmap.c | 22 ++++++------- mm/swap_state.c | 3 +- mm/swapfile.c | 5 +-- mm/userfaultfd.c | 32 ++++++++++--------- mm/util.c | 2 +- mm/vmalloc.c | 11 ++++--- mm/vmscan.c | 6 ++-- 66 files changed, 457 insertions(+), 375 deletions(-) --- base-commit: ead700ca770c82167af32622cf8b68c9f87c3c7c change-id: 20260914-pte0-6c88f5592d79 Best regards, -- Usama