mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Shrikanth Hegde <sshegde@linux.ibm.com>
To: Venkat Rao Bagalkote <venkat88@linux.ibm.com>,
	linuxppc-dev@lists.ozlabs.org
Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com,
	chleroy@kernel.org, mkchauras@linux.ibm.com, mkchauras@gmail.com,
	ruanjinjie@huawei.com, ritesh.list@gmail.com,
	riteshh@linux.ibm.com, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v3] powerpc/interrupt: Use early_radix_enabled() in NMI real-mode guard
Date: Wed, 9 Sep 2026 23:19:56 +0530	[thread overview]
Message-ID: <8d45cfd1-55d0-4e8f-aac1-fae5c9c4d91c@linux.ibm.com> (raw)
In-Reply-To: <20260909123240.58786-1-venkat88@linux.ibm.com>



On 9/9/26 6:02 PM, Venkat Rao Bagalkote wrote:
> radix_enabled() uses a jump label which is only valid after
> setup_feature_keys() is called. Before that point, on a pSeries
> hash guest, early_check_vec5() clears MMU_FTR_TYPE_RADIX in
> cur_cpu_spec->mmu_features, but the jump label has not yet been patched,
> so radix_enabled() incorrectly returns true.
> 
> The dangerous usage window where it goes wrong in early_setup():
> 
>      early_setup:
>          configure_exceptions();
>          <exceptions can happen now, and handler enter/exit can be invoked>
>          <those could use radix_enabled(), which returns stale true>
>          setup_feature_keys();
>          <jump labels set up; post this it is safe to use radix_enabled()>
> 
> If an NMI occurs in this window, !radix_enabled() evaluates to false in
> DEFINE_INTERRUPT_HANDLER_NMI. The handler fails to skip NMI entry in real
> mode and attempts to access memory outside the Real Mode Area (RMA),
> hanging the boot.
> 
> Since common interrupt wrappers do not have the context of early or late,
> using early_radix_enabled() is the safer option. It does a plain bitmask
> check against cur_cpu_spec->mmu_features and is correct at all times.
> 
> Console logs from a pSeries HASH guest showing values across boot stages:
> 
> [    0.000000] DEBUG: after early_init_devtree: early_radix_enabled=0 radix_enabled=1 (mismatch means NMI real-mode check is unsafe!)
> [    0.000000] DEBUG: after configure_exceptions (DANGEROUS WINDOW): early_radix_enabled=0 radix_enabled=1
> [    0.000000] DEBUG: after setup_feature_keys (jump labels initialized): early_radix_enabled=0 radix_enabled=0 (should now match!)
> [    0.057124] DEBUG: post secondary CPU bringup: early_radix_enabled=0 radix_enabled=0 (should match!)
> 
> Console logs from a RADIX guest showing values across boot stages:
> 
> [    0.000000] DEBUG: after early_init_devtree: early_radix_enabled=1 radix_enabled=1 (mismatch means NMI real-mode check is unsafe!)
> [    0.000000] DEBUG: after configure_exceptions (DANGEROUS WINDOW): early_radix_enabled=1 radix_enabled=1
> [    0.000000] DEBUG: after setup_feature_keys (jump labels initialized): early_radix_enabled=1 radix_enabled=1 (should now match!)
> [    0.057016] DEBUG: post secondary CPU bringup: early_radix_enabled=1 radix_enabled=1 (should match!)
> 
> Add the missing #include <asm/mmu.h> in alphabetical order since
> early_radix_enabled() is declared there.
> 

Reviewed-by: Shrikanth Hegde <sshegde@linux.ibm.com>

> Fixes: 8d0e21012743 ("powerpc/mce: Avoid nmi_enter/exit in real mode on pseries hash")
> Signed-off-by: Venkat Rao Bagalkote <venkat88@linux.ibm.com>
> Reviewed-by: Mukesh Kumar Chaurasiya <mkchauras@gmail.com>

Nit: I prefer to see Signed-off-by at the end.
But i guess b4 or patchwork tools take care of ordering. So i think
we are fine.

> ---
> v3:
>   - Clarified early_setup execution flow and race window in changelog.
>   - Explained why early_radix_enabled() is required for context-agnostic wrappers.
>   - Added console logs for both HASH and RADIX guests in changelog.
> v2:
>   - Added Fixes: tag referencing commit 8d0e21012743.
>   - Included <asm/mmu.h> in alphabetical order.
>   - Added Reviewed-by tag from Mukesh.
> 
>   arch/powerpc/include/asm/interrupt.h | 5 +++--
>   1 file changed, 3 insertions(+), 2 deletions(-)
> 
> diff --git a/arch/powerpc/include/asm/interrupt.h b/arch/powerpc/include/asm/interrupt.h
> index 1b45a49e9bed..355f6bbf9894 100644
> --- a/arch/powerpc/include/asm/interrupt.h
> +++ b/arch/powerpc/include/asm/interrupt.h
> @@ -70,6 +70,7 @@
>   #include <linux/irq-entry-common.h>
>   
>   #include <asm/kprobes.h>
> +#include <asm/mmu.h>
>   #include <asm/runlatch.h>
>   
>   #ifdef CONFIG_PPC_IRQ_SOFT_MASK_DEBUG
> @@ -290,7 +291,7 @@ interrupt_handler long func(struct pt_regs *regs)			\
>   		state = irqentry_nmi_enter(regs);			\
>   	} else if (IS_ENABLED(CONFIG_PPC_BOOK3S_64) &&			\
>   		   firmware_has_feature(FW_FEATURE_LPAR) &&		\
> -		   !radix_enabled()) {					\
> +		   !early_radix_enabled()) {				\
>   		/* no nmi_entry for a pseries hash guest		\
>   		 * taking a real mode exception */			\
>   	} else if (IS_ENABLED(CONFIG_KASAN)) {				\
> @@ -307,7 +308,7 @@ interrupt_handler long func(struct pt_regs *regs)			\
>   		irqentry_nmi_exit(regs, state);				\
>   	} else if (IS_ENABLED(CONFIG_PPC_BOOK3S_64) &&			\
>   		   firmware_has_feature(FW_FEATURE_LPAR) &&		\
> -		   !radix_enabled()) {					\
> +		   !early_radix_enabled()) {				\
>   		/* no nmi_exit for a pseries hash guest			\
>   		 * taking a real mode exception */			\
>   	} else if (IS_ENABLED(CONFIG_KASAN)) {				\


      reply	other threads:[~2026-09-09 17:50 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09 12:32 Venkat Rao Bagalkote
2026-09-09 17:49 ` Shrikanth Hegde [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8d45cfd1-55d0-4e8f-aac1-fae5c9c4d91c@linux.ibm.com \
    --to=sshegde@linux.ibm.com \
    --cc=chleroy@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=maddy@linux.ibm.com \
    --cc=mkchauras@gmail.com \
    --cc=mkchauras@linux.ibm.com \
    --cc=mpe@ellerman.id.au \
    --cc=npiggin@gmail.com \
    --cc=ritesh.list@gmail.com \
    --cc=riteshh@linux.ibm.com \
    --cc=ruanjinjie@huawei.com \
    --cc=venkat88@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®