mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v3] x86/mm/pat: use pr_warn() for early W^X warnings
@ 2026-09-13  7:37 Mike Rapoport (Microsoft)
  2026-09-21 10:54 ` Mike Rapoport
  2026-09-21 19:26 ` [tip: x86/mm] x86/mm/pat: Use " tip-bot2 for Mike Rapoport (Microsoft)
  0 siblings, 2 replies; 3+ messages in thread
From: Mike Rapoport (Microsoft) @ 2026-09-13  7:37 UTC (permalink / raw)
  To: Dave Hansen
  Cc: Andy Lutomirski, Borislav Petkov, Ihor Solodrai, Ingo Molnar,
	Mike Rapoport, Nathan Chancellor, H. Peter Anvin, Peter Zijlstra,
	Thomas Gleixner, x86, linux-kernel, linux-mm

Nathan Chancellor reports the following warning:

  CPA detected W^X violation: 8000000000000123 -> 0000000000000123 range: 0xffffffffc0400000 - 0xffffffffc0400fff PFN 100e00
  WARNING: arch/x86/mm/pat/set_memory.c:722 at __change_page_attr_set_clr+0xde7/0x1290, CPU#0: swapper/0/0
  Modules linked in:
  CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.3.0-rc1-debug-00006-g453e78594434 #1 PREEMPT(full)  2950d432dd3910251071a66f3134fe0875432786
  Hardware name: ASUS System Product Name/PRIME Z590M-PLUS, BIOS 1801 12/26/2022
  RIP: 0010:__change_page_attr_set_clr+0xdff/0x1290
  Code: 80 7c 24 42 00 0f 85 3a 04 00 00 48 8d 3d 19 8d 79 02 49 89 d9 4c 89 e1 4c 89 d2 4c 89 f6 4d 8d 84 24 ff 0f 00 00 4c 89 14 24 <67> 48 0f b9 3a 4c 8b 14 24 48 8b 0d 81 44 bf 01 41 f6 c2 01
  RSP: 0000:ffffffff87003c60 EFLAGS: 00010246
  RAX: 0000000000000002 RBX: 0000000000100e00 RCX: ffffffffc0400000
  RDX: 0000000000000123 RSI: 8000000000000123 RDI: ffffffff872e50c0
  RBP: 8000000100e00123 R08: ffffffffc0400fff R09: 0000000000100e00
  R10: 0000000000000123 R11: 0000000000000001 R12: ffffffffc0400000
  R13: 0000000100e00123 R14: 8000000000000123 R15: ffffffff87003d58
  FS:  0000000000000000(0000) GS:ffff8ad1777a7000(0000) knlGS:0000000000000000
  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
  CR2: ffff8ad0a4201000 CR3: 00000007e3022001 CR4: 0000000000770ef0
  PKRU: 55555554
  Call Trace:
   <TASK>
   ? _vm_unmap_aliases+0x219/0x280
   change_page_attr_set_clr+0x161/0x250
   ? events_sysfs_show+0x5d/0x80
   set_memory_x+0x39/0x50
   apply_retpolines+0x656/0x6d0
   ? events_sysfs_show+0x5d/0x80
   ? events_sysfs_show+0x6c/0x80
   ? events_sysfs_show+0x62/0x80
   alternative_instructions+0x3c/0xd0
   arch_cpu_finalize_init+0x130/0x190
   start_kernel+0x97d/0xa10
   x86_64_start_reservations+0x24/0x30
   x86_64_start_kernel+0xda/0xe0
   common_startup_64+0x13e/0x151
   </TASK>
  ---[ end trace 0000000000000000 ]---

The warning appears because commit 038176c21617f ("x86/mm/pat: fix
effective RW computation in lookup_address_in_pgd_attr()") fixed the
effective RW checked by verify_rwx() and it exposed that pages used for ITS
trampolines temporarily have RWX permissions.

The permissions are updated in its_fini_core() after all the ITS
trampolines are generated, but since verify_rwx() detects invalid
transitions, it warns when its_alloc() makes RW memory executable.

At the time of alternatives patching the entire kernel text is mapped
RWX, so the warning is bogus anyway.

Since the verification of the entire page table with debug_checkwx() has to
be enabled explicitly in the kernel configuration, retain the warning even
if it's bogus, but make it scream less loudly: use pr_warn_once() rather
than WARN_ONCE().

The warning can be removed once debug_checkwx() becomes unconditional for
configurations with CONFIG_STRICT_KERNEL_RWX set.

Reported-by: Nathan Chancellor <nathan@kernel.org>
Closes: https://lore.kernel.org/all/20260905044253.GA3816371@ax162
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Tested-by: Nathan Chancellor <nathan@kernel.org>
Tested-by: Ihor Solodrai <ihor.solodrai@linux.dev>
---
v3 changes:
* fix stupid copy-paste error

v2: https://patch.msgid.link/20260911-fixes-verify-rwx-v2-1-e2cde39b6693@kernel.org
* Use pr_warn_once() for early violations instad if skipping them entirely

v1: https://lore.kernel.org/all/20260908092730.4002628-1-rppt@kernel.org/
---
 arch/x86/mm/pat/set_memory.c | 15 +++++++++++++++
 1 file changed, 15 insertions(+)

diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c
index b3060000da8d1..a799f539287e2 100644
--- a/arch/x86/mm/pat/set_memory.c
+++ b/arch/x86/mm/pat/set_memory.c
@@ -697,6 +697,21 @@ static inline pgprot_t verify_rwx(pgprot_t old, pgprot_t new, unsigned long star
 		return new;
 
 	end = start + npg * PAGE_SIZE - 1;
+
+	/*
+	 * If the kernel text is still RWX, gently complain, this could be a
+	 * false positive.
+	 * Once debug_checkwx() becomes mandatory for CONFIG_STRICT_KERNEL_RWX,
+	 * the warning can be removed completely.
+	 */
+	if (!kernel_set_to_readonly) {
+		pr_warn_once("CPA detected W^X violation: %016llx -> %016llx range: 0x%016lx - 0x%016lx PFN %lx\n",
+		  (unsigned long long)pgprot_val(old),
+		  (unsigned long long)pgprot_val(new),
+		  start, end, pfn);
+		return new;
+	}
+
 	WARN_ONCE(1, "CPA detected W^X violation: %016llx -> %016llx range: 0x%016lx - 0x%016lx PFN %lx\n",
 		  (unsigned long long)pgprot_val(old),
 		  (unsigned long long)pgprot_val(new),

---
base-commit: ebaf7c9bbb1e16523d7036e7e1225ad2dfcc6482
change-id: 20260910-fixes-verify-rwx-044841b76a38

--
Sincerely yours,
Mike.


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH v3] x86/mm/pat: use pr_warn() for early W^X warnings
  2026-09-13  7:37 [PATCH v3] x86/mm/pat: use pr_warn() for early W^X warnings Mike Rapoport (Microsoft)
@ 2026-09-21 10:54 ` Mike Rapoport
  2026-09-21 19:26 ` [tip: x86/mm] x86/mm/pat: Use " tip-bot2 for Mike Rapoport (Microsoft)
  1 sibling, 0 replies; 3+ messages in thread
From: Mike Rapoport @ 2026-09-21 10:54 UTC (permalink / raw)
  To: Dave Hansen
  Cc: Andy Lutomirski, Borislav Petkov, Ihor Solodrai, Ingo Molnar,
	Nathan Chancellor, H. Peter Anvin, Peter Zijlstra,
	Thomas Gleixner, x86, linux-kernel, linux-mm

Gentle ping.

On Sun, Sep 13, 2026 at 10:37:27AM +0300, Mike Rapoport (Microsoft) wrote:
> Nathan Chancellor reports the following warning:
> 
>   CPA detected W^X violation: 8000000000000123 -> 0000000000000123 range: 0xffffffffc0400000 - 0xffffffffc0400fff PFN 100e00
>   WARNING: arch/x86/mm/pat/set_memory.c:722 at __change_page_attr_set_clr+0xde7/0x1290, CPU#0: swapper/0/0
>   Modules linked in:
>   CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.3.0-rc1-debug-00006-g453e78594434 #1 PREEMPT(full)  2950d432dd3910251071a66f3134fe0875432786
>   Hardware name: ASUS System Product Name/PRIME Z590M-PLUS, BIOS 1801 12/26/2022
>   RIP: 0010:__change_page_attr_set_clr+0xdff/0x1290
>   Code: 80 7c 24 42 00 0f 85 3a 04 00 00 48 8d 3d 19 8d 79 02 49 89 d9 4c 89 e1 4c 89 d2 4c 89 f6 4d 8d 84 24 ff 0f 00 00 4c 89 14 24 <67> 48 0f b9 3a 4c 8b 14 24 48 8b 0d 81 44 bf 01 41 f6 c2 01
>   RSP: 0000:ffffffff87003c60 EFLAGS: 00010246
>   RAX: 0000000000000002 RBX: 0000000000100e00 RCX: ffffffffc0400000
>   RDX: 0000000000000123 RSI: 8000000000000123 RDI: ffffffff872e50c0
>   RBP: 8000000100e00123 R08: ffffffffc0400fff R09: 0000000000100e00
>   R10: 0000000000000123 R11: 0000000000000001 R12: ffffffffc0400000
>   R13: 0000000100e00123 R14: 8000000000000123 R15: ffffffff87003d58
>   FS:  0000000000000000(0000) GS:ffff8ad1777a7000(0000) knlGS:0000000000000000
>   CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
>   CR2: ffff8ad0a4201000 CR3: 00000007e3022001 CR4: 0000000000770ef0
>   PKRU: 55555554
>   Call Trace:
>    <TASK>
>    ? _vm_unmap_aliases+0x219/0x280
>    change_page_attr_set_clr+0x161/0x250
>    ? events_sysfs_show+0x5d/0x80
>    set_memory_x+0x39/0x50
>    apply_retpolines+0x656/0x6d0
>    ? events_sysfs_show+0x5d/0x80
>    ? events_sysfs_show+0x6c/0x80
>    ? events_sysfs_show+0x62/0x80
>    alternative_instructions+0x3c/0xd0
>    arch_cpu_finalize_init+0x130/0x190
>    start_kernel+0x97d/0xa10
>    x86_64_start_reservations+0x24/0x30
>    x86_64_start_kernel+0xda/0xe0
>    common_startup_64+0x13e/0x151
>    </TASK>
>   ---[ end trace 0000000000000000 ]---
> 
> The warning appears because commit 038176c21617f ("x86/mm/pat: fix
> effective RW computation in lookup_address_in_pgd_attr()") fixed the
> effective RW checked by verify_rwx() and it exposed that pages used for ITS
> trampolines temporarily have RWX permissions.
> 
> The permissions are updated in its_fini_core() after all the ITS
> trampolines are generated, but since verify_rwx() detects invalid
> transitions, it warns when its_alloc() makes RW memory executable.
> 
> At the time of alternatives patching the entire kernel text is mapped
> RWX, so the warning is bogus anyway.
> 
> Since the verification of the entire page table with debug_checkwx() has to
> be enabled explicitly in the kernel configuration, retain the warning even
> if it's bogus, but make it scream less loudly: use pr_warn_once() rather
> than WARN_ONCE().
> 
> The warning can be removed once debug_checkwx() becomes unconditional for
> configurations with CONFIG_STRICT_KERNEL_RWX set.
> 
> Reported-by: Nathan Chancellor <nathan@kernel.org>
> Closes: https://lore.kernel.org/all/20260905044253.GA3816371@ax162
> Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
> Tested-by: Nathan Chancellor <nathan@kernel.org>
> Tested-by: Ihor Solodrai <ihor.solodrai@linux.dev>
> ---
> v3 changes:
> * fix stupid copy-paste error
> 
> v2: https://patch.msgid.link/20260911-fixes-verify-rwx-v2-1-e2cde39b6693@kernel.org
> * Use pr_warn_once() for early violations instad if skipping them entirely
> 
> v1: https://lore.kernel.org/all/20260908092730.4002628-1-rppt@kernel.org/
> ---
>  arch/x86/mm/pat/set_memory.c | 15 +++++++++++++++
>  1 file changed, 15 insertions(+)
> 
> diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c
> index b3060000da8d1..a799f539287e2 100644
> --- a/arch/x86/mm/pat/set_memory.c
> +++ b/arch/x86/mm/pat/set_memory.c
> @@ -697,6 +697,21 @@ static inline pgprot_t verify_rwx(pgprot_t old, pgprot_t new, unsigned long star
>  		return new;
>  
>  	end = start + npg * PAGE_SIZE - 1;
> +
> +	/*
> +	 * If the kernel text is still RWX, gently complain, this could be a
> +	 * false positive.
> +	 * Once debug_checkwx() becomes mandatory for CONFIG_STRICT_KERNEL_RWX,
> +	 * the warning can be removed completely.
> +	 */
> +	if (!kernel_set_to_readonly) {
> +		pr_warn_once("CPA detected W^X violation: %016llx -> %016llx range: 0x%016lx - 0x%016lx PFN %lx\n",
> +		  (unsigned long long)pgprot_val(old),
> +		  (unsigned long long)pgprot_val(new),
> +		  start, end, pfn);
> +		return new;
> +	}
> +
>  	WARN_ONCE(1, "CPA detected W^X violation: %016llx -> %016llx range: 0x%016lx - 0x%016lx PFN %lx\n",
>  		  (unsigned long long)pgprot_val(old),
>  		  (unsigned long long)pgprot_val(new),
> 
> ---
> base-commit: ebaf7c9bbb1e16523d7036e7e1225ad2dfcc6482
> change-id: 20260910-fixes-verify-rwx-044841b76a38
> 
> --
> Sincerely yours,
> Mike.
> 

-- 
Sincerely yours,
Mike.

^ permalink raw reply	[flat|nested] 3+ messages in thread

* [tip: x86/mm] x86/mm/pat: Use pr_warn() for early W^X warnings
  2026-09-13  7:37 [PATCH v3] x86/mm/pat: use pr_warn() for early W^X warnings Mike Rapoport (Microsoft)
  2026-09-21 10:54 ` Mike Rapoport
@ 2026-09-21 19:26 ` tip-bot2 for Mike Rapoport (Microsoft)
  1 sibling, 0 replies; 3+ messages in thread
From: tip-bot2 for Mike Rapoport (Microsoft) @ 2026-09-21 19:26 UTC (permalink / raw)
  To: linux-tip-commits
  Cc: Nathan Chancellor, Mike Rapoport (Microsoft),
	Dave Hansen, Ihor Solodrai, x86, linux-kernel

The following commit has been merged into the x86/mm branch of tip:

Commit-ID:     ea6fd393cb9e6811a748c7551de0dd3090f9dcde
Gitweb:        https://git.kernel.org/tip/ea6fd393cb9e6811a748c7551de0dd3090f9dcde
Author:        Mike Rapoport (Microsoft) <rppt@kernel.org>
AuthorDate:    Sun, 13 Sep 2026 10:37:27 +03:00
Committer:     Dave Hansen <dave.hansen@linux.intel.com>
CommitterDate: Mon, 21 Sep 2026 12:23:22 -07:00

x86/mm/pat: Use pr_warn() for early W^X warnings

Nathan Chancellor reports the following warning:

  CPA detected W^X violation: 8000000000000123 -> 0000000000000123 range: 0xffffffffc0400000 - 0xffffffffc0400fff PFN 100e00

from its_alloc() doing set_memory_x() during early retpoline setup.

The warning is not factually wrong but it is unproductive. First, the RWX
permission is temporary and fixed up by execmem_restore_rox(). Second,
at the time of the warning, all kernel text is mapped RWX. So there is not
even a transient actual security issue.

The right way to fix this up is to relax RWX detection during boot but
make a final verification pass over all kernel page tables before running
userspace.  There is code to do that today (debug_checkwx()) but it
must be enabled explicitly in Kconfig.

For now, retain the warning even if it's unproductive, but make it
scream less loudly: use pr_warn_once() rather than WARN_ONCE().

Remove the warning once debug_checkwx() behavior becomes unconditional.

Closes: https://lore.kernel.org/all/20260905044253.GA3816371@ax162
Reported-by: Nathan Chancellor <nathan@kernel.org>
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Dave Hansen <dave.hansen@linux.intel.com>
Tested-by: Nathan Chancellor <nathan@kernel.org>
Tested-by: Ihor Solodrai <ihor.solodrai@linux.dev>
Link: https://patch.msgid.link/20260913-fixes-verify-rwx-v3-1-5e1d6a08bd02@kernel.org
---
 arch/x86/mm/pat/set_memory.c | 15 +++++++++++++++
 1 file changed, 15 insertions(+)

diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c
index b306000..a799f53 100644
--- a/arch/x86/mm/pat/set_memory.c
+++ b/arch/x86/mm/pat/set_memory.c
@@ -697,6 +697,21 @@ static inline pgprot_t verify_rwx(pgprot_t old, pgprot_t new, unsigned long star
 		return new;
 
 	end = start + npg * PAGE_SIZE - 1;
+
+	/*
+	 * If the kernel text is still RWX, gently complain, this could be a
+	 * false positive.
+	 * Once debug_checkwx() becomes mandatory for CONFIG_STRICT_KERNEL_RWX,
+	 * the warning can be removed completely.
+	 */
+	if (!kernel_set_to_readonly) {
+		pr_warn_once("CPA detected W^X violation: %016llx -> %016llx range: 0x%016lx - 0x%016lx PFN %lx\n",
+		  (unsigned long long)pgprot_val(old),
+		  (unsigned long long)pgprot_val(new),
+		  start, end, pfn);
+		return new;
+	}
+
 	WARN_ONCE(1, "CPA detected W^X violation: %016llx -> %016llx range: 0x%016lx - 0x%016lx PFN %lx\n",
 		  (unsigned long long)pgprot_val(old),
 		  (unsigned long long)pgprot_val(new),

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-21 19:26 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-13  7:37 [PATCH v3] x86/mm/pat: use pr_warn() for early W^X warnings Mike Rapoport (Microsoft)
2026-09-21 10:54 ` Mike Rapoport
2026-09-21 19:26 ` [tip: x86/mm] x86/mm/pat: Use " tip-bot2 for Mike Rapoport (Microsoft)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®