Re: [PATCH v2 3/5] x86/alternative: exclude text poking against change_page_attr()

Jiri Slaby <[email protected]>
Newsgroups org.kernel.vger.stable,dev.linux.lists.iommu,org.kernel.vger.linux-kernel,org.kvack.linux-mm
Message-ID <[email protected]>
On 13. 08. 26, 11:01, Mike Rapoport wrote:
> From: Pedro Falcato <[email protected]>
> 
>  From time to time, the following BUG can be observed[0]:
> 
>> kernel BUG at arch/x86/kernel/alternative.c:2576!
>> Oops: invalid opcode: 0000 [#1] SMP NOPTI
>> CPU: 0 UID: 0 PID: 355 Comm: (udev-worker) Not tainted 7.1.3-1-default #1 PREEMPT(full) openSUSE Tumbleweed  8c1795b03ec64f997e57a8ad38b1161e3b98da64
>> Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS unknown 02/02/2022
>> RIP: 0010:__text_poke+0x2aa/0x450
>> Call Trace:
>>   <TASK>
>>   smp_text_poke_batch_finish+0x2a7/0x320
>>   __static_call_transform+0xb7/0x220
>>   arch_static_call_transform+0x5b/0xb0
>>   __static_call_init+0xe9/0x270
>>   static_call_module_notify+0x11f/0x150
>>   notifier_call_chain+0x61/0xe0
>>   blocking_notifier_call_chain_robust+0x63/0xc0
>>   load_module+0x1c92/0x20c0
>>   init_module_from_file+0xd8/0x140
>>   idempotent_init_module+0x100/0x2f0
>>   __x64_sys_finit_module+0x71/0xe0
>>   do_syscall_64+0xe1/0x610
>>   entry_SYSCALL_64_after_hwframe+0x76/0x7e
> 
> which matches the following BUG_ON in alternative.c:
> 	/*
> 	 * If something went wrong, crash and burn since recovery paths are not
> 	 * implemented.
> 	 */
> 	BUG_ON(!pages[0] || (cross_page_boundary && !pages[1]));
> 
> This can happen if vmalloc_to_page() fails, for any reason. Such can happen
> if text poking races with CPA, which can possibly result in the collapsing
> of page tables (or breaking of PMD hugepages). It is not a problem for most
> users of vmalloc_to_page() (they solely own the vmalloc'd range) but, when
> CONFIG_ARCH_HAS_EXECMEM_ROX=y, various modules own a single execmem vmalloc
> range, and can call set_memory_*() in parallel on it. This can happen to
> race against __text_poke and cause havoc in vmalloc_to_page().
> 
> Fix it by excluding against CPA using the init_mm mmap read lock.
> 
> Fixes: 64f6a4e10c05 ("x86: re-enable EXECMEM_ROX support")
> Reported-by: Jiri Slaby <[email protected]>

FWIW
Tested-by: Jiri Slaby <[email protected]>

We have not seen any BUGs since applied to the SUSE's kernel.
https://bugzilla.suse.com/show_bug.cgi?id=1271202#c26

thanks,
-- 
js
suse labs
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.