linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA
@ 2018-08-25 13:50 Andi Kleen
  2018-08-25 15:07 ` Greg KH
                   ` (2 more replies)
  0 siblings, 3 replies; 10+ messages in thread
From: Andi Kleen @ 2018-08-25 13:50 UTC (permalink / raw)
  To: stable; +Cc: x86, linux-kernel, bernhard.kaindl, Andi Kleen

From: Andi Kleen <ak@linux.intel.com>

Patch for stable only to fix boot resets caused by the L1TF patches.

Stable trees reverted the following patch

Revert "x86/mm/pat: Ensure cpa->pfn only contains page frame numbers"

    This reverts commit 87e2bd898d3a79a8c609f183180adac47879a2a4 which is
    commit edc3b9129cecd0f0857112136f5b8b1bc1d45918 upstream.

but the L1TF patch backported here

   x86/mm/pat: Make set_memory_np() L1TF safe

    commit 958f79b9ee55dfaf00c8106ed1c22a2919e0028b upstream

    set_memory_np() is used to mark kernel mappings not present, but it has
    it's own open coded mechanism which does not have the L1TF protection of
    inverting the address bits.

assumed that cpa->pfn contains a PFN. With the above patch reverted
it does not, which causes the PMD to be set to an incorrect address
shifted by 12 bits, which can cause early boot reset on some
systems, like an Apollo Lake embedded system.

Convert the address to a PFN before passing it to pmd_pfn()

Thanks to Bernhard for bisecting and testing.

Cc: stable@vger.kernel.org # 4.4 and 4.9
Reported-by: Bernhard Kaindl <bernhard.kaindl@thalesgroup.com>
Tested-by: Bernhard Kaindl <bernhard.kaindl@thalesgroup.com>
Signed-off-by: Andi Kleen <ak@linux.intel.com>
---
 arch/x86/mm/pageattr.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/x86/mm/pageattr.c b/arch/x86/mm/pageattr.c
index 27610c2d1821..1007fa80f5a6 100644
--- a/arch/x86/mm/pageattr.c
+++ b/arch/x86/mm/pageattr.c
@@ -1006,7 +1006,7 @@ static int populate_pmd(struct cpa_data *cpa,
 
 		pmd = pmd_offset(pud, start);
 
-		set_pmd(pmd, pmd_mkhuge(pfn_pmd(cpa->pfn,
+		set_pmd(pmd, pmd_mkhuge(pfn_pmd(cpa->pfn >> PAGE_SHIFT,
 					canon_pgprot(pmd_pgprot))));
 
 		start	  += PMD_SIZE;
-- 
2.17.1


^ permalink raw reply related	[flat|nested] 10+ messages in thread

* Re: [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA
  2018-08-25 13:50 [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA Andi Kleen
@ 2018-08-25 15:07 ` Greg KH
  2018-08-26  4:46 ` Guenter Roeck
  2018-09-06  6:48 ` Jiri Slaby
  2 siblings, 0 replies; 10+ messages in thread
From: Greg KH @ 2018-08-25 15:07 UTC (permalink / raw)
  To: Andi Kleen; +Cc: stable, x86, linux-kernel, bernhard.kaindl, Andi Kleen

On Sat, Aug 25, 2018 at 06:50:15AM -0700, Andi Kleen wrote:
> From: Andi Kleen <ak@linux.intel.com>
> 
> Patch for stable only to fix boot resets caused by the L1TF patches.
> 
> Stable trees reverted the following patch
> 
> Revert "x86/mm/pat: Ensure cpa->pfn only contains page frame numbers"
> 
>     This reverts commit 87e2bd898d3a79a8c609f183180adac47879a2a4 which is
>     commit edc3b9129cecd0f0857112136f5b8b1bc1d45918 upstream.
> 
> but the L1TF patch backported here
> 
>    x86/mm/pat: Make set_memory_np() L1TF safe
> 
>     commit 958f79b9ee55dfaf00c8106ed1c22a2919e0028b upstream
> 
>     set_memory_np() is used to mark kernel mappings not present, but it has
>     it's own open coded mechanism which does not have the L1TF protection of
>     inverting the address bits.
> 
> assumed that cpa->pfn contains a PFN. With the above patch reverted
> it does not, which causes the PMD to be set to an incorrect address
> shifted by 12 bits, which can cause early boot reset on some
> systems, like an Apollo Lake embedded system.
> 
> Convert the address to a PFN before passing it to pmd_pfn()
> 
> Thanks to Bernhard for bisecting and testing.
> 
> Cc: stable@vger.kernel.org # 4.4 and 4.9
> Reported-by: Bernhard Kaindl <bernhard.kaindl@thalesgroup.com>
> Tested-by: Bernhard Kaindl <bernhard.kaindl@thalesgroup.com>
> Signed-off-by: Andi Kleen <ak@linux.intel.com>
> ---
>  arch/x86/mm/pageattr.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)

Thanks for this, now queued up.

greg k-h

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA
  2018-08-25 13:50 [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA Andi Kleen
  2018-08-25 15:07 ` Greg KH
@ 2018-08-26  4:46 ` Guenter Roeck
  2018-08-26  5:06   ` Andi Kleen
  2018-09-06  6:48 ` Jiri Slaby
  2 siblings, 1 reply; 10+ messages in thread
From: Guenter Roeck @ 2018-08-26  4:46 UTC (permalink / raw)
  To: Andi Kleen; +Cc: stable, x86, linux-kernel, bernhard.kaindl, Andi Kleen

On Sat, Aug 25, 2018 at 06:50:15AM -0700, Andi Kleen wrote:
> From: Andi Kleen <ak@linux.intel.com>
> 
> Patch for stable only to fix boot resets caused by the L1TF patches.
> 
> Stable trees reverted the following patch
> 
> Revert "x86/mm/pat: Ensure cpa->pfn only contains page frame numbers"
> 
>     This reverts commit 87e2bd898d3a79a8c609f183180adac47879a2a4 which is
>     commit edc3b9129cecd0f0857112136f5b8b1bc1d45918 upstream.
> 
> but the L1TF patch backported here
> 
>    x86/mm/pat: Make set_memory_np() L1TF safe
> 
>     commit 958f79b9ee55dfaf00c8106ed1c22a2919e0028b upstream
> 
>     set_memory_np() is used to mark kernel mappings not present, but it has
>     it's own open coded mechanism which does not have the L1TF protection of
>     inverting the address bits.
> 
> assumed that cpa->pfn contains a PFN. With the above patch reverted
> it does not, which causes the PMD to be set to an incorrect address
> shifted by 12 bits, which can cause early boot reset on some
> systems, like an Apollo Lake embedded system.
> 
> Convert the address to a PFN before passing it to pmd_pfn()
> 
> Thanks to Bernhard for bisecting and testing.
> 

Thanks a lot to you for tracking it down, and sorry for messing it up.

> Cc: stable@vger.kernel.org # 4.4 and 4.9

LGTM for v4.4.y but ... are you sure that this patch applies to v4.9.y ?
Commit edc3b9129cec is 'native' in v4.9.y and has not been reverted there.

$ git log --oneline v4.4..linux-4.9.y | grep "x86/mm/pat: Ensure cpa->pfn only contains page frame numbers"
edc3b9129cec x86/mm/pat: Ensure cpa->pfn only contains page frame numbers

Guenter

> Reported-by: Bernhard Kaindl <bernhard.kaindl@thalesgroup.com>
> Tested-by: Bernhard Kaindl <bernhard.kaindl@thalesgroup.com>
> Signed-off-by: Andi Kleen <ak@linux.intel.com>
> ---
>  arch/x86/mm/pageattr.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/arch/x86/mm/pageattr.c b/arch/x86/mm/pageattr.c
> index 27610c2d1821..1007fa80f5a6 100644
> --- a/arch/x86/mm/pageattr.c
> +++ b/arch/x86/mm/pageattr.c
> @@ -1006,7 +1006,7 @@ static int populate_pmd(struct cpa_data *cpa,
>  
>  		pmd = pmd_offset(pud, start);
>  
> -		set_pmd(pmd, pmd_mkhuge(pfn_pmd(cpa->pfn,
> +		set_pmd(pmd, pmd_mkhuge(pfn_pmd(cpa->pfn >> PAGE_SHIFT,
>  					canon_pgprot(pmd_pgprot))));
>  
>  		start	  += PMD_SIZE;

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA
  2018-08-26  4:46 ` Guenter Roeck
@ 2018-08-26  5:06   ` Andi Kleen
  2018-08-26  5:55     ` Greg KH
  0 siblings, 1 reply; 10+ messages in thread
From: Andi Kleen @ 2018-08-26  5:06 UTC (permalink / raw)
  To: Guenter Roeck
  Cc: Andi Kleen, stable, x86, linux-kernel, bernhard.kaindl, greg

> > Cc: stable@vger.kernel.org # 4.4 and 4.9
> 
> LGTM for v4.4.y but ... are you sure that this patch applies to v4.9.y ?
> Commit edc3b9129cec is 'native' in v4.9.y and has not been reverted there.

You're right. I thought it was needed for 4.9 too, but yes it has the CPA pfn
patch. So for 4.9 the patch is not needed and in fact incorrect.

The original report was for 4.4.

Greg can you please revert/remove it again for 4.9?

-Andi

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA
  2018-08-26  5:06   ` Andi Kleen
@ 2018-08-26  5:55     ` Greg KH
  0 siblings, 0 replies; 10+ messages in thread
From: Greg KH @ 2018-08-26  5:55 UTC (permalink / raw)
  To: Andi Kleen
  Cc: Guenter Roeck, Andi Kleen, stable, x86, linux-kernel, bernhard.kaindl

On Sat, Aug 25, 2018 at 10:06:41PM -0700, Andi Kleen wrote:
> > > Cc: stable@vger.kernel.org # 4.4 and 4.9
> > 
> > LGTM for v4.4.y but ... are you sure that this patch applies to v4.9.y ?
> > Commit edc3b9129cec is 'native' in v4.9.y and has not been reverted there.
> 
> You're right. I thought it was needed for 4.9 too, but yes it has the CPA pfn
> patch. So for 4.9 the patch is not needed and in fact incorrect.
> 
> The original report was for 4.4.
> 
> Greg can you please revert/remove it again for 4.9?

Now dropped, thanks.

greg k-h

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA
  2018-08-25 13:50 [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA Andi Kleen
  2018-08-25 15:07 ` Greg KH
  2018-08-26  4:46 ` Guenter Roeck
@ 2018-09-06  6:48 ` Jiri Slaby
  2018-09-06 20:27   ` Andi Kleen
  2 siblings, 1 reply; 10+ messages in thread
From: Jiri Slaby @ 2018-09-06  6:48 UTC (permalink / raw)
  To: Andi Kleen, stable; +Cc: x86, linux-kernel, bernhard.kaindl, Andi Kleen

On 08/25/2018, 03:50 PM, Andi Kleen wrote:
> From: Andi Kleen <ak@linux.intel.com>
> 
> Patch for stable only to fix boot resets caused by the L1TF patches.
> 
> Stable trees reverted the following patch
> 
> Revert "x86/mm/pat: Ensure cpa->pfn only contains page frame numbers"
> 
>     This reverts commit 87e2bd898d3a79a8c609f183180adac47879a2a4 which is
>     commit edc3b9129cecd0f0857112136f5b8b1bc1d45918 upstream.
> 
> but the L1TF patch backported here
> 
>    x86/mm/pat: Make set_memory_np() L1TF safe
> 
>     commit 958f79b9ee55dfaf00c8106ed1c22a2919e0028b upstream
> 
>     set_memory_np() is used to mark kernel mappings not present, but it has
>     it's own open coded mechanism which does not have the L1TF protection of
>     inverting the address bits.
> 
> assumed that cpa->pfn contains a PFN. With the above patch reverted
> it does not, which causes the PMD to be set to an incorrect address
> shifted by 12 bits, which can cause early boot reset on some
> systems, like an Apollo Lake embedded system.
> 
> Convert the address to a PFN before passing it to pmd_pfn()
> 
> Thanks to Bernhard for bisecting and testing.
> 
> Cc: stable@vger.kernel.org # 4.4 and 4.9
> Reported-by: Bernhard Kaindl <bernhard.kaindl@thalesgroup.com>
> Tested-by: Bernhard Kaindl <bernhard.kaindl@thalesgroup.com>
> Signed-off-by: Andi Kleen <ak@linux.intel.com>
> ---
>  arch/x86/mm/pageattr.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/arch/x86/mm/pageattr.c b/arch/x86/mm/pageattr.c
> index 27610c2d1821..1007fa80f5a6 100644
> --- a/arch/x86/mm/pageattr.c
> +++ b/arch/x86/mm/pageattr.c
> @@ -1006,7 +1006,7 @@ static int populate_pmd(struct cpa_data *cpa,
>  
>  		pmd = pmd_offset(pud, start);
>  
> -		set_pmd(pmd, pmd_mkhuge(pfn_pmd(cpa->pfn,
> +		set_pmd(pmd, pmd_mkhuge(pfn_pmd(cpa->pfn >> PAGE_SHIFT,
>  					canon_pgprot(pmd_pgprot))));

And what about populate_pud?
                set_pud(pud, pud_mkhuge(pfn_pud(cpa->pfn,
                                   canon_pgprot(pud_pgprot))));

                start     += PUD_SIZE;
                cpa->pfn  += PUD_SIZE;

thanks,
-- 
js
suse labs

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA
  2018-09-06  6:48 ` Jiri Slaby
@ 2018-09-06 20:27   ` Andi Kleen
  2018-09-17 11:51     ` Greg KH
  0 siblings, 1 reply; 10+ messages in thread
From: Andi Kleen @ 2018-09-06 20:27 UTC (permalink / raw)
  To: Jiri Slaby
  Cc: Andi Kleen, stable, x86, linux-kernel, bernhard.kaindl, Andi Kleen

> And what about populate_pud?
>                 set_pud(pud, pud_mkhuge(pfn_pud(cpa->pfn,
>                                    canon_pgprot(pud_pgprot))));
> 
>                 start     += PUD_SIZE;
>                 cpa->pfn  += PUD_SIZE;

Yes you're right. That case needs to be fixed too.

Are you sending a patch, or should I?

-Andi

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA
  2018-09-06 20:27   ` Andi Kleen
@ 2018-09-17 11:51     ` Greg KH
  2018-09-17 12:16       ` Jiri Slaby
  0 siblings, 1 reply; 10+ messages in thread
From: Greg KH @ 2018-09-17 11:51 UTC (permalink / raw)
  To: Andi Kleen
  Cc: Jiri Slaby, stable, x86, linux-kernel, bernhard.kaindl, Andi Kleen

On Thu, Sep 06, 2018 at 01:27:49PM -0700, Andi Kleen wrote:
> > And what about populate_pud?
> >                 set_pud(pud, pud_mkhuge(pfn_pud(cpa->pfn,
> >                                    canon_pgprot(pud_pgprot))));
> > 
> >                 start     += PUD_SIZE;
> >                 cpa->pfn  += PUD_SIZE;
> 
> Yes you're right. That case needs to be fixed too.
> 
> Are you sending a patch, or should I?

Someone needs to.  Please?

greg k-h

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA
  2018-09-17 11:51     ` Greg KH
@ 2018-09-17 12:16       ` Jiri Slaby
  2018-09-17 12:20         ` Greg KH
  0 siblings, 1 reply; 10+ messages in thread
From: Jiri Slaby @ 2018-09-17 12:16 UTC (permalink / raw)
  To: Greg KH, Andi Kleen
  Cc: stable, x86, linux-kernel, bernhard.kaindl, Andi Kleen

On 09/17/2018, 01:51 PM, Greg KH wrote:
> On Thu, Sep 06, 2018 at 01:27:49PM -0700, Andi Kleen wrote:
>>> And what about populate_pud?
>>>                 set_pud(pud, pud_mkhuge(pfn_pud(cpa->pfn,
>>>                                    canon_pgprot(pud_pgprot))));
>>>
>>>                 start     += PUD_SIZE;
>>>                 cpa->pfn  += PUD_SIZE;
>>
>> Yes you're right. That case needs to be fixed too.
>>
>> Are you sending a patch, or should I?
> 
> Someone needs to.  Please?

You already released 4.4.x with the patch :):

commit 15898df477269c981dc1ae5afa39e1bb65e1db0a
Author: Jiri Slaby <jslaby@suse.cz>
Date:   Fri Sep 7 11:13:07 2018 +0200

    x86/mm/pat: Fix L1TF stable backport for CPA, 2nd call

thanks,
-- 
js
suse labs

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA
  2018-09-17 12:16       ` Jiri Slaby
@ 2018-09-17 12:20         ` Greg KH
  0 siblings, 0 replies; 10+ messages in thread
From: Greg KH @ 2018-09-17 12:20 UTC (permalink / raw)
  To: Jiri Slaby
  Cc: Andi Kleen, stable, x86, linux-kernel, bernhard.kaindl, Andi Kleen

On Mon, Sep 17, 2018 at 02:16:33PM +0200, Jiri Slaby wrote:
> On 09/17/2018, 01:51 PM, Greg KH wrote:
> > On Thu, Sep 06, 2018 at 01:27:49PM -0700, Andi Kleen wrote:
> >>> And what about populate_pud?
> >>>                 set_pud(pud, pud_mkhuge(pfn_pud(cpa->pfn,
> >>>                                    canon_pgprot(pud_pgprot))));
> >>>
> >>>                 start     += PUD_SIZE;
> >>>                 cpa->pfn  += PUD_SIZE;
> >>
> >> Yes you're right. That case needs to be fixed too.
> >>
> >> Are you sending a patch, or should I?
> > 
> > Someone needs to.  Please?
> 
> You already released 4.4.x with the patch :):
> 
> commit 15898df477269c981dc1ae5afa39e1bb65e1db0a
> Author: Jiri Slaby <jslaby@suse.cz>
> Date:   Fri Sep 7 11:13:07 2018 +0200
> 
>     x86/mm/pat: Fix L1TF stable backport for CPA, 2nd call
> 

Ugh, nevermind, sorry for the noise :)

greg k-h

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2018-09-17 12:20 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-08-25 13:50 [PATCH] x86/mm/pat: Fix L1TF stable backport for CPA Andi Kleen
2018-08-25 15:07 ` Greg KH
2018-08-26  4:46 ` Guenter Roeck
2018-08-26  5:06   ` Andi Kleen
2018-08-26  5:55     ` Greg KH
2018-09-06  6:48 ` Jiri Slaby
2018-09-06 20:27   ` Andi Kleen
2018-09-17 11:51     ` Greg KH
2018-09-17 12:16       ` Jiri Slaby
2018-09-17 12:20         ` Greg KH

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).