mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 1/1] x86/mm: fix incomplete page-table invalidation with TCE
@ 2026-10-05  5:23 Lance Yang
  2026-10-05  5:47 ` Andrew Morton
                   ` (3 more replies)
  0 siblings, 4 replies; 20+ messages in thread
From: Lance Yang @ 2026-10-05  5:23 UTC (permalink / raw)
  To: dave.hansen
  Cc: luto, peterz, tglx, mingo, bp, x86, hpa, riel, linux-kernel,
	qi.zheng, nadav.amit, thomas.lendacky, kernel-team, linux-mm,
	akpm, brendan.jackman, jannh, mhklinux, andrew.cooper3,
	Manali.Shukla, mingo, stable, toshi.kani, david,
	mikhail.v.gavrilov, pfalcato, Lance Yang

pud_free_pmd_page() uses a single-address invalidation to flush the
paging-structure caches before freeing the page tables. With AMD TCE
enabled, this only invalidates upper-level entries associated with the
target address. Cached PMD entries for other addresses in the PUD range can
still reference the PTE pages being freed.

The AMD manual quoted in the commit enabling TCE says these instructions
remove

  "only those upper-level entries that lead to the target PTE in the page
  table hierarchy, leaving unrelated upper-level entries intact."

Even with all PTEs cleared, speculative page walks can cache present PMD
entries after the earlier TLB purge.

Use a full TLB flush before freeing the page tables on CPUs with TCE. Keep
the single-address invalidation otherwise.

Fixes: 440a65b7d25f ("x86/mm: Enable AMD translation cache extensions")
Cc: stable@vger.kernel.org
Signed-off-by: Lance Yang <lance.yang@linux.dev>
---
 arch/x86/mm/pgtable.c | 11 ++++++++++-
 1 file changed, 10 insertions(+), 1 deletion(-)

diff --git a/arch/x86/mm/pgtable.c b/arch/x86/mm/pgtable.c
index 4a105f283cfb..6b7fa44f1bf6 100644
--- a/arch/x86/mm/pgtable.c
+++ b/arch/x86/mm/pgtable.c
@@ -727,7 +727,16 @@ int pud_free_pmd_page(pud_t *pud, unsigned long addr)
 	 * via normal page walks. Make them unreachable
 	 * in cached mid-level walks too:
 	 */
-	flush_tlb_kernel_range(addr, addr + PAGE_SIZE-1);
+	if (boot_cpu_has(X86_FEATURE_TCE)) {
+		/*
+		 * With TCE enabled, a single-address flush does not invalidate
+		 * cached PMD entries for the rest of the PUD range.
+		 */
+		flush_tlb_all();
+	} else {
+		/* INVLPG to clear all paging-structure caches */
+		flush_tlb_kernel_range(addr, addr + PAGE_SIZE-1);
+	}
 
 	for (i = 0; i < PTRS_PER_PMD; i++) {
 		if (!pmd_none(pmd[i])) {
-- 
2.49.0


^ permalink raw reply	[flat|nested] 20+ messages in thread

end of thread, other threads:[~2026-10-05 15:36 UTC | newest]

Thread overview: 20+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05  5:23 [PATCH 1/1] x86/mm: fix incomplete page-table invalidation with TCE Lance Yang
2026-10-05  5:47 ` Andrew Morton
2026-10-05  6:09 ` Pedro Falcato
2026-10-05  7:29   ` Lance Yang
2026-10-05  8:19     ` Andrew Cooper
2026-10-05  8:32       ` Lance Yang
2026-10-05  9:57         ` Andrew Cooper
2026-10-05 10:12           ` Lance Yang
2026-10-05 14:22             ` Borislav Petkov
2026-10-05 14:36               ` Lance Yang
2026-10-05 14:53                 ` Borislav Petkov
2026-10-05 14:58                   ` Lance Yang
2026-10-05 15:22             ` Andrew Cooper
2026-10-05 15:36               ` Lance Yang
2026-10-05 10:24     ` Pedro Falcato
2026-10-05 12:10       ` Lance Yang
2026-10-05  6:38 ` Nadav Amit
2026-10-05  7:23   ` Lance Yang
2026-10-05 15:15 ` Rik van Riel
2026-10-05 15:30   ` Lance Yang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®