[tip: x86/cpu] x86/cpu: Don't transiently clear the boot CPU's capabilities

From: tip-bot2 for Ihor Solodrai

Date: Wed Sep 16 2026 - 22:04:35 EST


The following commit has been merged into the x86/cpu branch of tip:

Commit-ID: 2711d67bc3a776abcfc651ad87be5d29ada19166
Gitweb: https://git.kernel.org/tip/2711d67bc3a776abcfc651ad87be5d29ada19166
Author: Ihor Solodrai <ihor.solodrai@xxxxxxxxx>
AuthorDate: Wed, 16 Sep 2026 12:52:03 -07:00
Committer: Borislav Petkov (AMD) <bp@xxxxxxxxx>
CommitterDate: Thu, 17 Sep 2026 02:05:39 +02:00

x86/cpu: Don't transiently clear the boot CPU's capabilities

On the boot CPU, identify_cpu() runs from arch_cpu_finalize_init(), with
interrupts enabled and before alternatives are patched. So
cpu_feature_enabled() still evaluates against boot_cpu_data.

identify_cpu() rebuilds c->x86_capability from scratch: the reset zeroes the
array and the CPUID rescan fills it in again. An interrupt delivered in that
window finds X86_FEATURE_LA57 clear in boot_cpu_data, so pgtable_l5_enabled()
is false and KASAN checks a 5-level address against the 4-level addressability
limit. The result is a bogus "wild-memory-access" report, and under
kasan_multi_shot a report storm that wedges the boot.

The boot CPU has already been scanned by early_identify_cpu(), with interrupts
disabled, and its capabilities cannot have changed since. Reset only the CPUs
which have not been scanned yet.

The window is as old as identify_cpu() rebuilding the capabilities. Commit

39b9552281ab ("x86/mm: Optimize boot-time paging mode switching cost")

merely let KASAN notice it by making pgtable_l5_enabled() read the feature
bit. So no Fixes: tag.

Closes: https://lore.kernel.org/bpf/20260610175651.647515-1-ihor.solodrai@xxxxxxxxx/
Signed-off-by: Ihor Solodrai <ihor.solodrai@xxxxxxxxx>
Signed-off-by: Borislav Petkov (AMD) <bp@xxxxxxxxx>
Link: https://patch.msgid.link/20260916195203.1099646-6-ihor.solodrai@xxxxxxxxx
---
arch/x86/kernel/cpu/common.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/arch/x86/kernel/cpu/common.c b/arch/x86/kernel/cpu/common.c
index 156a7b8..7d4ff29 100644
--- a/arch/x86/kernel/cpu/common.c
+++ b/arch/x86/kernel/cpu/common.c
@@ -2000,8 +2000,6 @@ static void identify_cpu(struct cpuinfo_x86 *c)

c->loops_per_jiffy = loops_per_jiffy;

- init_cpu_info(c);
-
if (!cpuid_feature())
identify_cpu_without_cpuid(c);

@@ -2186,6 +2184,7 @@ void identify_secondary_cpu(unsigned int cpu)
*c = boot_cpu_data;
c->cpu_index = cpu;

+ init_cpu_info(c);
identify_cpu(c);
x86_spec_ctrl_setup_ap();
update_srbds_msr();