Re: [PATCH 1/1] x86/mm: fix incomplete page-table invalidation with TCE

From: Andrew Morton

Date: Mon Oct 05 2026 - 01:47:50 EST


On Mon, 5 Oct 2026 13:23:02 +0800 Lance Yang <lance.yang@xxxxxxxxx> wrote:

> pud_free_pmd_page() uses a single-address invalidation to flush the
> paging-structure caches before freeing the page tables. With AMD TCE
> enabled, this only invalidates upper-level entries associated with the
> target address. Cached PMD entries for other addresses in the PUD range can
> still reference the PTE pages being freed.
>
> The AMD manual quoted in the commit enabling TCE says these instructions
> remove
>
> "only those upper-level entries that lead to the target PTE in the page
> table hierarchy, leaving unrelated upper-level entries intact."
>
> Even with all PTEs cleared, speculative page walks can cache present PMD
> entries after the earlier TLB purge.
>
> Use a full TLB flush before freeing the page tables on CPUs with TCE. Keep
> the single-address invalidation otherwise.
>
> Fixes: 440a65b7d25f ("x86/mm: Enable AMD translation cache extensions")
> Cc: stable@xxxxxxxxxxxxxxx

Sorry, but my usual complaint applies.

Check the first 32 lines of
Documentation/process/stable-kernel-rules.rst. They're very simple,

I'm sure x86 people can immediately grasp the importance of this
change, but nobody else can. This includes -stable maintainers as well
as a large number of other downstream users of our work who are
wondering "why should I apply this to my kernel". Let's tell them!


iow, and not for the first time: when fixing a bug please fully
describe the userspace-visible runtime effects of that bug.

Thanks.