From: Rik van Riel <riel@surriel.com>
To: Dave Hansen <dave.hansen@intel.com>, linux-kernel@vger.kernel.org
Cc: kernel-team@meta.com, dave.hansen@linux.intel.com,
luto@kernel.org, peterz@infradead.org, bp@alien8.de,
x86@kernel.org, yu-cheng.yu@intel.com,
Rik van Riel <riel@meta.com>,
stable@kernel.org
Subject: Re: [PATCH 1/3] x86/mm: Fix potential overflow in user_pcid_flush_mask
Date: Tue, 03 Jun 2025 17:20:56 -0400 [thread overview]
Message-ID: <5987ac95e4011c2b71d1c3cce13872571cff3ac7.camel@surriel.com> (raw)
In-Reply-To: <83a671ed-4862-4a0f-b91d-d4598b4a82d7@intel.com>
On Mon, 2025-06-02 at 09:55 -0700, Dave Hansen wrote:
> On 6/2/25 06:30, Rik van Riel wrote:
> >
> > @@ -149,6 +166,15 @@ struct tlb_state {
> > * context 0.
> > */
> > struct tlb_context ctxs[TLB_NR_DYN_ASIDS];
> > +
> > +#ifdef CONFIG_MITIGATION_PAGE_TABLE_ISOLATION
> > + /*
> > + * Mask that contains TLB_NR_DYN_ASIDS+1 bits to indicate
> > + * the corresponding user PCID needs a flush next time we
> > + * switch to it; see SWITCH_TO_USER_CR3.
> > + */
> > + unsigned long user_pcid_flush_mask[CR3_AVAIL_PCID_LONGS];
> > +#endif
> > };
> > DECLARE_PER_CPU_ALIGNED(struct tlb_state, cpu_tlbstate);
>
> This adds an #ifdef. I guess it makes sense to do it for the now
> larger
> user_pcid_flush_mask[] while it didn't for a single long. But that's
> another logically separate bit that adds complexity to reading this
> whole mess.
>
> Honestly, I'd just leave this out for the bug fix. If someone really
> cares, we can come back and fix it up in mainline.
I added the #ifdef at Ingo's request.
I am happy to do the code in any way you two can
agree on, but we should probably avoid the back
and forth over many versions thing :)
>
> > diff --git a/arch/x86/kernel/asm-offsets.c b/arch/x86/kernel/asm-
> > offsets.c
> > index 6259b474073b..8c41a2e5a53e 100644
> > --- a/arch/x86/kernel/asm-offsets.c
> > +++ b/arch/x86/kernel/asm-offsets.c
> > @@ -103,8 +103,10 @@ static void __used common(void)
> > BLANK();
> > DEFINE(PTREGS_SIZE, sizeof(struct pt_regs));
> >
> > +#ifdef CONFIG_MITIGATION_PAGE_TABLE_ISOLATION
> > /* TLB state for the entry code */
> > OFFSET(TLB_STATE_user_pcid_flush_mask, tlb_state,
> > user_pcid_flush_mask);
> > +#endif
>
> Because it necessitates this hunk too...
I agree this isn't the prettiest, but then again
asm-offsets.c isn't code people will be reading
a lot?
--
All Rights Reversed.
next prev parent reply other threads:[~2025-06-03 21:20 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-06-02 13:30 [PATCH 0/3] TLB flush fixes Rik van Riel
2025-06-02 13:30 ` [PATCH 1/3] x86/mm: Fix potential overflow in user_pcid_flush_mask Rik van Riel
2025-06-02 16:55 ` Dave Hansen
2025-06-03 21:20 ` Rik van Riel [this message]
2025-06-03 21:33 ` Dave Hansen
2025-06-02 13:30 ` [PATCH 2/3] x86/mm: Fix early boot use of INVPLGB Rik van Riel
2025-06-02 17:21 ` Dave Hansen
2025-06-02 13:30 ` [PATCH 3/3] x86/mm: Change cpa_flush() to call flush_kernel_range() directly Rik van Riel
2025-06-02 17:22 ` Dave Hansen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5987ac95e4011c2b71d1c3cce13872571cff3ac7.camel@surriel.com \
--to=riel@surriel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=kernel-team@meta.com \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@kernel.org \
--cc=peterz@infradead.org \
--cc=riel@meta.com \
--cc=stable@kernel.org \
--cc=x86@kernel.org \
--cc=yu-cheng.yu@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®