From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 02EDF3859D6 for ; Mon, 20 Apr 2026 08:48:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776674928; cv=none; b=qUluLdxxZIEc9g+8RiVGiLGLKnwK1Z68N/AXvhVCblLNTjHgBiQjgHejzKE0vOk/aKGeniTnFH+VA4fPKAtaqELGQok88kWwVF8s8vN5itUe1YUGmtTSw7pa77tY4ZNccKy1BQBGQNb2FNgfPx3zT/J+tLn2tOfiSC8pMmyLSpo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776674928; c=relaxed/simple; bh=qLFgeQwJCkpSSOG98sxSdZSktT3hEJUY9FwxAEoEYcs=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=XyXncUTSbxNwiuSdhJftJFhWnEDj3xQXOtII47/khpndMyZ/HYw5pzCsEHEjkbj9DidP5FPBWuSV0iKpH17sFAqoFqS5mWKAswOsG/H0q8Es9Mz76wDNtqWBVCpsyx1HovbMKdpJ408W8701aHAxC/qthQAxLl/taE7BnW6/Hgk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=T9vRxeYx; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="T9vRxeYx" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 53FBCC19425; Mon, 20 Apr 2026 08:48:39 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1776674927; bh=qLFgeQwJCkpSSOG98sxSdZSktT3hEJUY9FwxAEoEYcs=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=T9vRxeYxFL9cfHlFph+p4HZ7WoGh85kwA61pnA64hopb3JqkEUHIbig41QikVB0o8 prK8HkTDt/Ffs9L9+yWgpZ8m4vNtm2NtKgvqFrHGKZ0kSrCIaIWiX8XFRWTp4AuE0n 5rRHIYxhoMQxEg92Bznbq5kvvr9NtLFa1+jC88YbV/vcS5Nf256U/iPi/x0/kQMUif dXVbGPzd1qJz/5dHW5nJNtqHKhuEzPHYOIDMMJ/zgr26bjAhEbAWxN1H9vUvNYGDeQ R5c4ehGomLkv+Eu4Uh3VAGGXsphT6EG7QRTvQj3L+E424MFl6JzHADE8L5FH6Bs8l9 HaSyWBlFLIDsQ== Date: Mon, 20 Apr 2026 09:48:35 +0100 From: Will Deacon To: Yin Tirui Cc: linux-kernel@vger.kernel.org, linux-mm@kvack.org, x86@kernel.org, linux-arm-kernel@lists.infradead.org, willy@infradead.org, david@kernel.org, catalin.marinas@arm.com, tglx@kernel.org, mingo@redhat.com, bp@alien8.de, dave.hansen@linux.intel.com, hpa@zytor.com, luto@kernel.org, peterz@infradead.org, akpm@linux-foundation.org, lorenzo.stoakes@oracle.com, ziy@nvidia.com, baolin.wang@linux.alibaba.com, Liam.Howlett@oracle.com, npache@redhat.com, ryan.roberts@arm.com, dev.jain@arm.com, baohua@kernel.org, lance.yang@linux.dev, vbabka@suse.cz, rppt@kernel.org, surenb@google.com, mhocko@suse.com, anshuman.khandual@arm.com, rmclure@linux.ibm.com, kevin.brodsky@arm.com, apopple@nvidia.com, ajd@linux.ibm.com, pasha.tatashin@soleen.com, bhe@redhat.com, thuth@redhat.com, coxu@redhat.com, dan.j.williams@intel.com, yu-cheng.yu@intel.com, yangyicong@hisilicon.com, baolu.lu@linux.intel.com, jgross@suse.com, conor.dooley@microchip.com, Jonathan.Cameron@huawei.com, riel@surriel.com, wangkefeng.wang@huawei.com, chenjun102@huawei.com Subject: Re: [PATCH RFC v3 2/4] mm/pgtable: Make pfn_pte() filter out huge page attributes Message-ID: References: <20260228070906.1418911-1-yintirui@huawei.com> <20260228070906.1418911-3-yintirui@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260228070906.1418911-3-yintirui@huawei.com> On Sat, Feb 28, 2026 at 03:09:04PM +0800, Yin Tirui wrote: > A fundamental principle of page table type safety is that `pte_t` represents > the lowest level page table entry and should never carry huge page attributes. > > Currently, passing a pgprot with huge page bits (e.g., extracted via > pmd_pgprot()) into pfn_pte() creates a malformed PTE that retains the huge > attribute, leading to the necessity of the ugly `pte_clrhuge()` anti-pattern. > > Enforce type safety by making `pfn_pte()` inherently filter out huge page > attributes: > - On x86: Strip the `_PAGE_PSE` bit. > - On ARM64: Mask out the block descriptor bits in `PTE_TYPE_MASK` and > enforce the `PTE_TYPE_PAGE` format. > - On RISC-V: No changes required, as RISC-V leaf PMDs and PTEs share the > exact same hardware format and do not use a distinct huge bit. > > Signed-off-by: Yin Tirui > --- > arch/arm64/include/asm/pgtable.h | 4 +++- > arch/x86/include/asm/pgtable.h | 4 ++++ > 2 files changed, 7 insertions(+), 1 deletion(-) > > diff --git a/arch/arm64/include/asm/pgtable.h b/arch/arm64/include/asm/pgtable.h > index b3e58735c49b..f2a7a40106d2 100644 > --- a/arch/arm64/include/asm/pgtable.h > +++ b/arch/arm64/include/asm/pgtable.h > @@ -141,7 +141,9 @@ static inline pteval_t __phys_to_pte_val(phys_addr_t phys) > > #define pte_pfn(pte) (__pte_to_phys(pte) >> PAGE_SHIFT) > #define pfn_pte(pfn,prot) \ > - __pte(__phys_to_pte_val((phys_addr_t)(pfn) << PAGE_SHIFT) | pgprot_val(prot)) > + __pte(__phys_to_pte_val((phys_addr_t)(pfn) << PAGE_SHIFT) | \ > + ((pgprot_val(prot) & ~(PTE_TYPE_MASK & ~PTE_VALID)) | \ > + (PTE_TYPE_PAGE & ~PTE_VALID))) Why are you touching arch/arm64? We don't implement pte_clrhuge() afaict. What does this actually fix? Will