[tip: x86/urgent] x86/mm/pat: Fix effective RW computation in lookup_address_in_pgd_attr()
From: tip-bot2 for Mike Rapoport (Microsoft)
Date: Mon Aug 31 2026 - 19:27:30 EST
The following commit has been merged into the x86/urgent branch of tip:
Commit-ID: 34cd1c931a365a6b81e00e743f9f260050104ff6
Gitweb: https://git.kernel.org/tip/34cd1c931a365a6b81e00e743f9f260050104ff6
Author: Mike Rapoport (Microsoft) <rppt@xxxxxxxxxx>
AuthorDate: Thu, 13 Aug 2026 12:01:28 +03:00
Committer: Dave Hansen <dave.hansen@xxxxxxxxxxxxxxx>
CommitterDate: Mon, 31 Aug 2026 15:20:52 -07:00
x86/mm/pat: Fix effective RW computation in lookup_address_in_pgd_attr()
lookup_address_in_pgd_attr() accumulates the effective NX and RW bits of
the walked page table levels so that verify_rwx() can detect mappings that
are both writable and executable.
The RW bits are folded into a bool with
rw &= pXd_flags(*pXd) & _PAGE_RW;
but _PAGE_RW is 0x2. So consider the accumulation line:
rw &= pXd_flags(*pXd) & _PAGE_RW;
where rw=0x1 and the right side evaluates down to 0x2. It'll end up doing:
rw = 0x1 & 0x2
and rw always ends up 0.
This way rw becomes false at the first level walked, regardless of the
actual permissions, and verify_rwx() treats every mapping as non-writable
and never reports a W^X violation.
Add double negation to the right side to normalize the _PAGE_RW flag to
0 or 1.
Assisted-by: Copilot:claude-opus-4.8
Fixes: ceb647b4b529 ("x86/pat: Introduce lookup_address_in_pgd_attr()")
Signed-off-by: Mike Rapoport (Microsoft) <rppt@xxxxxxxxxx>
Signed-off-by: Dave Hansen <dave.hansen@xxxxxxxxxxxxxxx>
Reviewed-by: Juergen Gross <jgross@xxxxxxxx>
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@xxxxxxxxxx>
Tested-by: syzbot@xxxxxxxxxxxxxxxxxxxxxxxxx
Tested-by: Atish Patra <atishp@xxxxxxxx>
Tested-by: Nikunj A Dadhania <nikunj@xxxxxxx>
Cc: stable@xxxxxxxxxxxxxxx
Link: https://patch.msgid.link/20260813-cpa-fixes-v2-5-39b4ff90f91d@xxxxxxxxxx
---
arch/x86/mm/pat/set_memory.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c
index 4652487..2266609 100644
--- a/arch/x86/mm/pat/set_memory.c
+++ b/arch/x86/mm/pat/set_memory.c
@@ -754,7 +754,7 @@ pte_t *lookup_address_in_pgd_attr(pgd_t *pgd, unsigned long address,
*level = PG_LEVEL_512G;
*nx |= pgd_flags(*pgd) & _PAGE_NX;
- *rw &= pgd_flags(*pgd) & _PAGE_RW;
+ *rw &= !!(pgd_flags(*pgd) & _PAGE_RW);
p4d = p4d_offset(pgd, address);
if (p4d_none(*p4d))
@@ -765,7 +765,7 @@ pte_t *lookup_address_in_pgd_attr(pgd_t *pgd, unsigned long address,
*level = PG_LEVEL_1G;
*nx |= p4d_flags(*p4d) & _PAGE_NX;
- *rw &= p4d_flags(*p4d) & _PAGE_RW;
+ *rw &= !!(p4d_flags(*p4d) & _PAGE_RW);
pud = pud_offset(p4d, address);
if (pud_none(*pud))
@@ -776,7 +776,7 @@ pte_t *lookup_address_in_pgd_attr(pgd_t *pgd, unsigned long address,
*level = PG_LEVEL_2M;
*nx |= pud_flags(*pud) & _PAGE_NX;
- *rw &= pud_flags(*pud) & _PAGE_RW;
+ *rw &= !!(pud_flags(*pud) & _PAGE_RW);
pmd = pmd_offset(pud, address);
if (pmd_none(*pmd))
@@ -787,7 +787,7 @@ pte_t *lookup_address_in_pgd_attr(pgd_t *pgd, unsigned long address,
*level = PG_LEVEL_4K;
*nx |= pmd_flags(*pmd) & _PAGE_NX;
- *rw &= pmd_flags(*pmd) & _PAGE_RW;
+ *rw &= !!(pmd_flags(*pmd) & _PAGE_RW);
return pte_offset_kernel(pmd, address);
}