From: Dave Hansen <dave.hansen@intel.com>
To: hitesh.murali@imperva.com,
Dave Hansen <dave.hansen@linux.intel.com>,
Andy Lutomirski <luto@kernel.org>,
Peter Zijlstra <peterz@infradead.org>,
Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>,
x86@kernel.org, "H. Peter Anvin" <hpa@zytor.com>,
Rick Edgecombe <rick.p.edgecombe@intel.com>,
Yu-cheng Yu <yu-cheng.yu@intel.com>,
"Mike Rapoport (IBM)" <rppt@kernel.org>
Cc: linux-kernel@vger.kernel.org
Subject: Re: [PATCH] x86/mm/fault: Test _PAGE_RW, not pte_write(), in spurious_kernel_fault_check()
Date: Thu, 1 Oct 2026 09:24:57 -0700 [thread overview]
Message-ID: <6ccb518d-2b66-4a0d-9747-3aae91227e03@intel.com> (raw)
In-Reply-To: <20261001-x86-fault-spurious-rw-v1-1-7fe1189b5efd@imperva.com>
On 10/1/26 09:12, Hitesh Murali via B4 Relay wrote:
> Kernel read-only mappings are created without Dirty since commit
> f788b71768ff ("x86/mm: Remove _PAGE_DIRTY from kernel RO pages"), but a
> store made while _PAGE_RW is temporarily set leaves Dirty behind, and the
> kernel does not clear it again. A later normal store to such an entry
> raises a protection fault, which is then classified as spurious. The
> store is restarted, faults again, and the CPU makes no progress.
I'm having a really hard time parsing through this changelog. Was this
all from the LLM?
Can this issue actually be triggered in a normal kernel? The root of
this problem is that PTE-modifying kernel code is leaving _PAGE_DIRTY
behind during a RW=>RO transition. We have code to prevent that from
happening.
So are the out-of-tree modules just being naughty and directly
manipulating page tables? Care to post your "small GPL test modules"?
Yeah, there still might be a buglet in spurious fault detection that
would surface in the face of _other_ kernel bugs, but it'd be extra low
priority.
next prev parent reply other threads:[~2026-10-01 16:25 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 16:12 Hitesh Murali via B4 Relay
2026-10-01 16:24 ` Dave Hansen [this message]
[not found] ` <MR0P264MB69837D7B9DF99BBA6333DB60E68A2@MR0P264MB6983.FRAP264.PROD.OUTLOOK.COM>
2026-10-01 20:37 ` Dave Hansen
2026-10-01 16:34 ` Edgecombe, Rick P
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6ccb518d-2b66-4a0d-9747-3aae91227e03@intel.com \
--to=dave.hansen@intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=hitesh.murali@imperva.com \
--cc=hpa@zytor.com \
--cc=linux-kernel@vger.kernel.org \
--cc=luto@kernel.org \
--cc=mingo@redhat.com \
--cc=peterz@infradead.org \
--cc=rick.p.edgecombe@intel.com \
--cc=rppt@kernel.org \
--cc=tglx@kernel.org \
--cc=x86@kernel.org \
--cc=yu-cheng.yu@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®