From: Shrikanth Hegde <sshegde@linux.ibm.com>
To: Venkat Rao Bagalkote <venkat88@linux.ibm.com>,
linuxppc-dev@lists.ozlabs.org
Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com,
chleroy@kernel.org, mkchauras@linux.ibm.com, mkchauras@gmail.com,
ruanjinjie@huawei.com, ritesh.list@gmail.com,
riteshh@linux.ibm.com, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v3] powerpc/interrupt: Use early_radix_enabled() in NMI real-mode guard
Date: Wed, 9 Sep 2026 23:19:56 +0530 [thread overview]
Message-ID: <8d45cfd1-55d0-4e8f-aac1-fae5c9c4d91c@linux.ibm.com> (raw)
In-Reply-To: <20260909123240.58786-1-venkat88@linux.ibm.com>
On 9/9/26 6:02 PM, Venkat Rao Bagalkote wrote:
> radix_enabled() uses a jump label which is only valid after
> setup_feature_keys() is called. Before that point, on a pSeries
> hash guest, early_check_vec5() clears MMU_FTR_TYPE_RADIX in
> cur_cpu_spec->mmu_features, but the jump label has not yet been patched,
> so radix_enabled() incorrectly returns true.
>
> The dangerous usage window where it goes wrong in early_setup():
>
> early_setup:
> configure_exceptions();
> <exceptions can happen now, and handler enter/exit can be invoked>
> <those could use radix_enabled(), which returns stale true>
> setup_feature_keys();
> <jump labels set up; post this it is safe to use radix_enabled()>
>
> If an NMI occurs in this window, !radix_enabled() evaluates to false in
> DEFINE_INTERRUPT_HANDLER_NMI. The handler fails to skip NMI entry in real
> mode and attempts to access memory outside the Real Mode Area (RMA),
> hanging the boot.
>
> Since common interrupt wrappers do not have the context of early or late,
> using early_radix_enabled() is the safer option. It does a plain bitmask
> check against cur_cpu_spec->mmu_features and is correct at all times.
>
> Console logs from a pSeries HASH guest showing values across boot stages:
>
> [ 0.000000] DEBUG: after early_init_devtree: early_radix_enabled=0 radix_enabled=1 (mismatch means NMI real-mode check is unsafe!)
> [ 0.000000] DEBUG: after configure_exceptions (DANGEROUS WINDOW): early_radix_enabled=0 radix_enabled=1
> [ 0.000000] DEBUG: after setup_feature_keys (jump labels initialized): early_radix_enabled=0 radix_enabled=0 (should now match!)
> [ 0.057124] DEBUG: post secondary CPU bringup: early_radix_enabled=0 radix_enabled=0 (should match!)
>
> Console logs from a RADIX guest showing values across boot stages:
>
> [ 0.000000] DEBUG: after early_init_devtree: early_radix_enabled=1 radix_enabled=1 (mismatch means NMI real-mode check is unsafe!)
> [ 0.000000] DEBUG: after configure_exceptions (DANGEROUS WINDOW): early_radix_enabled=1 radix_enabled=1
> [ 0.000000] DEBUG: after setup_feature_keys (jump labels initialized): early_radix_enabled=1 radix_enabled=1 (should now match!)
> [ 0.057016] DEBUG: post secondary CPU bringup: early_radix_enabled=1 radix_enabled=1 (should match!)
>
> Add the missing #include <asm/mmu.h> in alphabetical order since
> early_radix_enabled() is declared there.
>
Reviewed-by: Shrikanth Hegde <sshegde@linux.ibm.com>
> Fixes: 8d0e21012743 ("powerpc/mce: Avoid nmi_enter/exit in real mode on pseries hash")
> Signed-off-by: Venkat Rao Bagalkote <venkat88@linux.ibm.com>
> Reviewed-by: Mukesh Kumar Chaurasiya <mkchauras@gmail.com>
Nit: I prefer to see Signed-off-by at the end.
But i guess b4 or patchwork tools take care of ordering. So i think
we are fine.
> ---
> v3:
> - Clarified early_setup execution flow and race window in changelog.
> - Explained why early_radix_enabled() is required for context-agnostic wrappers.
> - Added console logs for both HASH and RADIX guests in changelog.
> v2:
> - Added Fixes: tag referencing commit 8d0e21012743.
> - Included <asm/mmu.h> in alphabetical order.
> - Added Reviewed-by tag from Mukesh.
>
> arch/powerpc/include/asm/interrupt.h | 5 +++--
> 1 file changed, 3 insertions(+), 2 deletions(-)
>
> diff --git a/arch/powerpc/include/asm/interrupt.h b/arch/powerpc/include/asm/interrupt.h
> index 1b45a49e9bed..355f6bbf9894 100644
> --- a/arch/powerpc/include/asm/interrupt.h
> +++ b/arch/powerpc/include/asm/interrupt.h
> @@ -70,6 +70,7 @@
> #include <linux/irq-entry-common.h>
>
> #include <asm/kprobes.h>
> +#include <asm/mmu.h>
> #include <asm/runlatch.h>
>
> #ifdef CONFIG_PPC_IRQ_SOFT_MASK_DEBUG
> @@ -290,7 +291,7 @@ interrupt_handler long func(struct pt_regs *regs) \
> state = irqentry_nmi_enter(regs); \
> } else if (IS_ENABLED(CONFIG_PPC_BOOK3S_64) && \
> firmware_has_feature(FW_FEATURE_LPAR) && \
> - !radix_enabled()) { \
> + !early_radix_enabled()) { \
> /* no nmi_entry for a pseries hash guest \
> * taking a real mode exception */ \
> } else if (IS_ENABLED(CONFIG_KASAN)) { \
> @@ -307,7 +308,7 @@ interrupt_handler long func(struct pt_regs *regs) \
> irqentry_nmi_exit(regs, state); \
> } else if (IS_ENABLED(CONFIG_PPC_BOOK3S_64) && \
> firmware_has_feature(FW_FEATURE_LPAR) && \
> - !radix_enabled()) { \
> + !early_radix_enabled()) { \
> /* no nmi_exit for a pseries hash guest \
> * taking a real mode exception */ \
> } else if (IS_ENABLED(CONFIG_KASAN)) { \
prev parent reply other threads:[~2026-09-09 17:50 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 12:32 Venkat Rao Bagalkote
2026-09-09 17:49 ` Shrikanth Hegde [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8d45cfd1-55d0-4e8f-aac1-fae5c9c4d91c@linux.ibm.com \
--to=sshegde@linux.ibm.com \
--cc=chleroy@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=maddy@linux.ibm.com \
--cc=mkchauras@gmail.com \
--cc=mkchauras@linux.ibm.com \
--cc=mpe@ellerman.id.au \
--cc=npiggin@gmail.com \
--cc=ritesh.list@gmail.com \
--cc=riteshh@linux.ibm.com \
--cc=ruanjinjie@huawei.com \
--cc=venkat88@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®