Re: [PATCH] x86/mm/pat: fix effective RW computation in lookup_address_in_pgd_attr()

From: Juergen Gross

Date: Thu Jul 16 2026 - 04:48:05 EST


On 16.07.26 10:37, Jürgen Groß wrote:
On 16.07.26 10:10, Mike Rapoport (Microsoft) wrote:
lookup_address_in_pgd_attr() accumulates the effective NX and RW bits of
the walked page table levels so that verify_rwx() can detect mappings that
are both writable and executable.

The RW bits are folded into a bool with

    *rw &= pXd_flags(*pXd) & _PAGE_RW;

but _PAGE_RW is bit 1 while *rw only ever holds 0 or 1, so the AND is
always 0.  *rw becomes false at the first level walked, regardless of the
actual permissions, and verify_rwx() treats every mapping as non-writable
and never reports a W^X violation.

Accumulate NX and RW in unsigned long locals in their native bit positions
and store the result into the bool outputs once.

Fixes: ceb647b4b529 ("x86/pat: Introduce lookup_address_in_pgd_attr()")
Assisted-by: Copilot:claude-opus-4.8
Signed-off-by: Mike Rapoport (Microsoft) <rppt@xxxxxxxxxx>

Thanks for catching this.

Reviewed-by: Juergen Gross <jgross@xxxxxxxx>

Just one remark: instead of using additional local variables the fix could
just look like:

    *rw |= !!(pXd_flags(*pXd) & _PAGE_RW);

&=, of course.


Juergen

Attachment: OpenPGP_0xB0DE9DD628BF132F.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature