Re: [PATCH v2 4/5] hibernation, KFENCE: explicitly map/unmap KFENCE pages

From: David Hildenbrand (Arm)

Date: Mon Sep 28 2026 - 05:15:33 EST


On 9/26/26 11:26, Mike Rapoport (Microsoft) wrote:
> The pages protected by KFENCE are removed from the direct map.
>
> safe_copy_page() temporarily maps and unmaps them using set_direct_map
> APIs, or, when the stars align, even using debug_pagealloc_map_pages().
>
> Neither of these APIs cares whether it is a KFENCE page and both blindly
> perform the update of the kernel page table for any non-present page.
>
> Ability to use debug_pagealloc_map_pages() to remap KFENCE pages when both
> KFENCE and debug_pagealloc are enabled is an amusing coincidence.
>
> But with increasing appetite for using set_direct_map for hardening
> purposes, it becomes too big of a hammer to enable saving any non-present
> page in the hibernation image.
>
> Another gotcha is that loongarch that does not have a direct map at all
> advertises ARCH_HAS_SET_DIRECT_MAP to allow coexistence of KFENCE and
> hibernation.
>
> Extend KFENCE with a bitmap that tracks which pages are protected and
> provide kfence_force_mapping() and kfence_reset_mapping() APIs that allow
> forced mapping and unmapping of KFENCE pages.
>
> Use these APIs in hibernate_{map,unmap}_pages() for KFENCE pages.
>
> Signed-off-by: Mike Rapoport (Microsoft) <rppt@xxxxxxxxxx>
> ---

Reviewed-by: David Hildenbrand (Arm) <david@xxxxxxxxxx>




--
Cheers,

David